2.12.1 (L1) Ensure 'Enable Related Website Sets' Is Disabled

Information

This policy controls access to the Related Website Sets. First-party Sets are a way for sites to declare relationships with each other and enable limited cross-site cookie access for specific, user-facing purposes. It can configured to either:

- Disabled (0): Disable Related Website Sets for all affected users
- Enabled (1): Enable Related Website Sets for all affected users

Note: This replaces the previous recommendation of Ensure 'Enable First-Party Sets' Is Disabled.

Setting this policy will not allow sites to declare the relationships that allow them to access the cross-site cookies.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Content settings\Enable Related Website Sets

Impact:

This may cause unexpected behavior as a user moves between affiliated sites.

See Also

https://workbench.cisecurity.org/benchmarks/16430

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4

Plugin: Windows

Control ID: 5545ee037117b97d789c1bdb7935a6fc4816bf71c543b4612f4b8cebcd08f990