6.20 Ensure that User Credential Submission uses the action of block or continue on the URL categories

Information

Ideally user names and passwords user within an organization are not used with third party site. Some sanctioned SAS applications may have connections to the corporate domain, in which case they will need to be exempt from the user credential submission policy through a custom URL category.
Rationale:
Preventing users from having the ability to submit their corporate credentials to the Internet could stop credential phishing attacks and the potential that a breach at a site where a user reused credentials could lead to a credential stuffing attack.

Solution

Navigate to Objects > Security Profiles > URL Filtering.
Set the user credential submitting action on all URL categories listed to Block.
Under the "User Credential Detection" tab set user credential detection to Use IP User Mapping. This requires User-ID to be configured and decryption to be effective.
Impact:
Not preventing users from submitting their corporate credentials to the Internet can leave them open to phishing attacks or allow for credential reuse on unauthorized sites.
Default Value:
Not Configured

See Also

https://workbench.cisecurity.org/files/2104

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv7|7

Plugin: Palo_Alto

Control ID: b033e4e92f917efc1bcbbaffcb8bbd39a3540c94683dacc04320a0b1884bd675