3.2 (L1) Ensure 'Update policy override' is set to 'Enabled' with 'Always allow updates (recommended)' or 'Automatic silent updates only' specified

Information

Google Update manages installation of available Google Chrome updates from Google. This setting allows users to define whether updates are to be applied automatically. Depending on the business scenario, updates shall be applied periodically or also if the user seeks for updates.

- (0): Updates disabled
- (1): Always allow updates (recommended)
- (2): Manual updates only
- (3): Automatic silent updates only

Disabled (0): Google Update handles available updates as specified by 'Update policy override default'.

The recommended state for this setting is: Enabled with a value of Always allow updates (recommended) (1) or Automatic silent updates only (3)

NOTE: This policy is available only on Windows instances that are joined to a Microsoft(R) Active Directory(R) domain.

Software updates shall be applied as soon as they are available since they may include latest security patches.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Always allow updates (recommended) :

Computer Configuration\Policies\Administrative Templates\Google\Google Update\Applications\Google Chrome\Update policy override

Impact:

Latest updates are automatically applied at least periodically.

See Also

https://workbench.cisecurity.org/benchmarks/16430

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.5

Plugin: Windows

Control ID: daf22bc119ca9c089db865a92f7092f07d97ed7f23d06380513d7a874a21a04b