10.1 (L1) Ensure 'Show full website address' is 'Enabled'

Information

This setting controls how the URL is displayed. With it enabled, the full path will be shown. With it disabled, only the high-level domain will be displayed.

Rationale:

By displaying the full URL, the user is better informed as to where they are browsing on a given site and may even see sensitive parameters that are being passed via URL.

Solution

Follow the below steps to set Show full website address to Enabled:

1. Click Safari.
2. Click Preferences.
3. Click Advanced.
4. Check Show full website address checkbox.

To configure the plist follow the below steps:

1. Open the com.apple.Safari.plist.
2. Find the token <key>ShowFullURLInSmartSearchField</key>
3. Ensure this token is immediately followed by <true/>

Default Value:
Disabled. (Shortens URL)

See Also

https://workbench.cisecurity.org/files/1822

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv6|7

Plugin: Unix

Control ID: d3a4c4ea1293407cbefad41edd76379dbec692158873d5ceb9cd7e3c047e64d3