9.13 Set 'Disable AutoComplete for forms' to 'Enabled'

Information



This policy setting controls automatic completion of fields in forms on Web pages. If you
enable this policy setting, the AutoComplete feature will not suggest possible choices for
completing a form. This can help protect sensitive data in certain environments. The
recommended state for this setting is- Enabled.

*Rationale*

It is possible that this feature will cache sensitive data and store it in the user's profile
where it might not be protected as rigorously as required by organizational policy.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.User Configuration\Administrative Templates\Windows Components\Internet
Explorer\Disable AutoComplete for forms

Impact-If you enable this policy setting, the AutoComplete feature will not suggest possible choices
for completing a form.

Default Value-Disabled

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CSCv6|3.1

Plugin: Windows

Control ID: a232b26a7addba5455cd6a1df1ca5c3be2c8e4fb847dc0b0c3acdcb12c9fc818