Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-57681 | DTBF-0032 | SV-72091r1_rule | Medium |
Description |
---|
This AutoComplete feature suggests possible matches when users are filling in forms and searches. It is possible that this feature will cache sensitive data and store it in the user's profile, where it might not be protected as rigorously as required by organizational policy. If you enable this setting or do not set a value, Auto-complete will remain under the control of the user. This will allow them to configure this setting, and switch Auto-complete on or off at their own discretion. |
STIG | Date |
---|---|
Mozilla Firefox | 2017-03-22 |
Check Text ( C-58503r1_chk ) |
---|
Procedure: In about:config, verify that the setting for the following Preference Name’s are set and locked. "browser.urlbar.autocomplete.enabled”, set to “false”. Criteria: If the parameter is set incorrectly, then this is a finding. If the setting is not locked, then this is a finding. |
Fix Text (F-62883r1_fix) |
---|
Set and lock the following preferences using the “Mozilla.cfg” file: "browser.urlbar.autocomplete.enabled”, set to “false”. |