1.1.30 (L1) Ensure 'Disable Forget Button' is set to 'Enabled'

Information

This policy setting determines whether the Forget button is available. This feature is also known as eCleaner and allows a user to quickly delete browser data from a selected time frame without affecting the rest of the data.

The recommended state for this setting is: Enabled

Deleting browser data will delete information that may be important for a computer investigation. Investigators such as Computer Forensics Analysts may not be able to retrieve pertinent information to the investigation.

Solution

To establish the recommended configuration via GP, set the following UI path to `Enabled:

Computer Configuration\Policies\Administrative Templates\Mozilla\Firefox\Disable Forget Button

Note: This Group Policy path does not exist by default. An additional Group Policy template ( firefox.admx/adml ) is required - it is available to download at this

link

.

Impact:

The Forget button will not be available to users.

See Also

https://workbench.cisecurity.org/benchmarks/18454

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-14(2)

Plugin: Windows

Control ID: 3fab6f891b0ec69caafc71e3e1fdbe8666f9a30733b35e4806d3a60ce82fe5a4