3.3 (L2) Ensure 'AutoFill web forms: Other forms' is 'Disabled'

Information

Safari can store the information typed in forms for later use on other websites. It is recommended that Safari be configured such that it does not store and auto-fill form contents.

Rationale:

If Safari or other applications executing at equal or higher security contexts is compromised, potentially sensitive, persisted, form data is at increased risk.

Solution

Follow the below steps to set AutoFill web forms: Other forms to Disabled:

1. Click Safari.
2. Click Preferences.
3. Click AutoFill.
4. Uncheck AutoFill web forms: Other forms.

To configure the plist follow the below steps:

1. Open the com.apple.Safari.plist.
2. Find the token <key>AutoFillMiscellaneousForms</key>
3. Ensure this token is immediately followed by <false/>

Default Value:
Enabled.

See Also

https://workbench.cisecurity.org/files/1822

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv6|13

Plugin: Unix

Control ID: 6c63f804f51f64a6acd7408084597926c55e52207b2d664f2cac3560794e3f3d