4.9 Ensure 'Enable AutoFill for addresses' is set to 'Disabled'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Chrome allows users to auto-complete web forms with saved information such as address or phone number. Disabling this feature will prompt a user to enter all information manually.

The recommended state for this setting is: Disabled (0)

Rationale:

If an attacker gains access to a user's machine where the user has stored address AutoFill data, information could be harvested.

Impact:

If this setting is disabled, AutoFill will be inaccessible to users.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled:

Computer Configuration\Administrative Templates\Google\Google Chrome\Enable AutoFill for addresses

Default Value:

Unset (Same as Enabled, but user can change)

See Also

https://workbench.cisecurity.org/files/3653

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv7|13

Plugin: Windows

Control ID: 5ef9d570249e36c32bb1221e33a6e410e1346dc6d889ecad844423f91fbd1a95