1.2.6 - MobileIron - Delete Saved Password Information

Information

The Safari configuration provides a repository to store information, including website username and password details, that can be to support Safari Auto Fill capability. Saved password information is stored in the device keychain and/or iCloud keychain. The Safari configuration interface requires the input of the device passcode prior to granting access to stored website password details; website and user name details can be viewed without the additional passcode prompt.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

From the MobileIron console, open the Policies and Configs -> iOS and OSX view. Under the Restrictions Policy verify that Enable autofill is not checked.
NOTE: This item will only be configurable if Allow use of Safari is enabled.

See Also

https://workbench.cisecurity.org/files/1678

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-19

Plugin: MDM

Control ID: 0564503628c7154d663e7426d7215380b8ba083622ba26198777be36a0b8a1ba