9.9 Set 'Disable AutoComplete for forms' to 'Enabled'

Information

*Description*

This policy setting controls automatic completion of fields in forms on Web pages. If you
enable this policy setting, the AutoComplete feature will not suggest possible choices for
completing a form. This can help protect sensitive data in certain environments. The
recommended state for this setting is- Enabled.

*Rationale*

It is possible that this feature will cache sensitive data and store it in the user's profile
where it might not be protected as rigorously as required by organizational policy.

Solution

To implement the recommended configuration state, set the following Group Policy setting
to Enabled.

User Configuration\Administrative Templates\Windows Components\Internet
Explorer\Disable AutoComplete for forms

Impact-If you enable this policy setting, the AutoComplete feature will not suggest possible choices
for completing a form.

See Also

https://workbench.cisecurity.org/files/1516

Item Details

Audit Name: CIS IE 9 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CSCv6|3.1

Plugin: Windows

Control ID: ab14b234ff3a9c436cba495ea8026b10638591af831e7380fe9df2d37fba7299