Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-22150 | DTBI780 | SV-40711r1_rule | ECSC-1 | Medium |
Description |
---|
InPrivate Browsing lets the user control whether or not Internet Explorer saves the browsing history, cookies, and other data. User control of settings is not the preferred control method. The InPrivate Browsing feature in Internet Explorer makes browser privacy easy by not storing history, cookies, temporary Internet files, or other data. If you enable this policy setting, InPrivate Browsing will be disabled. If you disable this policy setting, InPrivate Browsing will be available for use. If you do not configure this setting, InPrivate Browsing can be turned on or off through the registry. |
STIG | Date |
---|---|
Internet Explorer 9 Security Technical Implementation Guide | 2015-03-26 |
Check Text ( C-39439r2_chk ) |
---|
The policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer -> Privacy -> “Turn off InPrivate Browsing” must be “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Internet Explorer\Privacy Criteria: If the value EnableInPrivateBrowsing is REG_DWORD = 0, this is not a finding. |
Fix Text (F-34567r1_fix) |
---|
Set the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer -> Privacy -> “Turn off InPrivate Browsing” to “Enabled”. |