Skip to content
ATO Pathways
Log In
Overview
Search
Catalogs
SCAP
OSCAL
Catalogs
Profiles
Documents
References
Knowledge Base
Platform Documentation
Compliance Dictionary
Platform Changelog
About
Catalogs
XCCDF
Microsoft Outlook 2010 STIG
DTOO237-Disable "remember password" on eMail Accts
The "remember password" for internet e-mail accounts must be disabled.
The "remember password" for internet e-mail accounts must be disabled.
An XCCDF Rule
Details
Profiles
Prose
The "remember password" for internet e-mail accounts must be disabled.
Medium Severity
<VulnDiscussion>As a security precaution, password caching for eMail Internet protocols such as POP3 or IMAP may lead to password discovery and eventually to data loss. An attacker that is able to access the users' profile may be able to acquire these cached passwords, they could then use this information to compromise the users' email accounts and other systems that use the same credentials. </VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility>System Administrator</Responsibility><Responsibility>Information Assurance Officer</Responsibility><IAControls></IAControls>