DTBC-0070 - AutoFill for credit cards must be disabled.

Information

Enabling Google Chrome's AutoFill feature allows users to auto complete credit card information in web forms using previously stored information.
If this setting is disabled, Autofill will never suggest or fill credit card information, nor will it save additional credit card information that the user might submit while browsing the web.

If this setting is enabled or has no value, the user will be able to control Autofill for credit cards in the UI.

Solution

Windows group policy:
1. Open the 'group policy editor' tool with gpedit.msc
2. Navigate to Policy Path: Computer Configuration\Administrative Templates\Google\Google Chrome\
Policy Name: Enable AutoFill for credit cards
Policy State: Disabled

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Google_Chrome_V2R9_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(1), CAT|II, CCI|CCI-001166, Rule-ID|SV-226402r879627_rule, STIG-ID|DTBC-0070, STIG-Legacy|SV-111831, STIG-Legacy|V-102869, Vuln-ID|V-226402

Plugin: Windows

Control ID: 1353afd1aa5da139e29eb432d3dd3c120c1ab13822a00ba1a587b5dd21c134fc