WINCC-000147 - The touch keyboard or input panel must not highlight keys as passwords are entered. - PasswordSecurity

Information

The touch keyboard or input panel may highlight keys as passwords are entered, providing visibility to nearby persons, and compromising them.

Solution

If the system does not have a touch screen, this is NA.
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Tablet PC -> Input Panel -> 'Turn off password security in Input Panel' to at least 'Enabled- Medium High'.

See Also

http://iasecontent.disa.mil/stigs/zip/Oct2016/U_Windows_Vista_V6R41_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-6, CAT|III, CCI|CCI-000206, Rule-ID|SV-70675r1_rule, STIG-ID|WINCC-000147, Vuln-ID|V-56421

Plugin: Windows

Control ID: 568f8ed98e563a41424834a9704cbefbbc9dc6780240e3af29fd8837e57e7e4e