3.2 (L2) Ensure 'AutoFill web forms: Credit cards' is 'Disabled'

Information

Safari can store and retrieve payment card information in the user-level keychain. The information is collected during an online purchase, following the user's permission. It is recommended that Safari be configured to not store payment card information in cases where security is paramount.

Rationale:

If a user's console session is compromised, credit card information may be auto-filled into a website for a malicious purpose.

Solution

Follow the below steps to set AutoFill web forms: Credit cards to Disabled:

1. Click Safari.
2. Click Preferences.
3. Click AutoFill.
4. Uncheck AutoFill web forms: Credit cards.

To configure the plist follow the below steps:

1. Open the com.apple.Safari.plist.
2. Find the token <key>AutoFillCreditCardData</key>
3. Ensure this token is immediately followed by <false/>

Default Value:
Enabled.

See Also

https://workbench.cisecurity.org/files/1822

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv6|13

Plugin: Unix

Control ID: f12b75710a46b290e01d3bbd013fbd01f6cb3929595e90bca596899652887aad