2.33 (L1) Ensure 'Clear Browsing Data on Exit' is set to 'Disabled'

Information

This policy controls whether web browser data, such as forms, passwords and visited sites is deleted each time Google Chrome is closed.

Note: If this policy is enabled, do not enable the AllowDeletingBrowserHistory policy, because it will take precedence over the ClearBrowsingDataOnExit policy and all data will be deleted when Google Chrome closes, regardless of how AllowDeletingBrowserHistory is configured.

Deleting browser data on close will delete information that may be important for a computer investigation and investigators such as Computer Forensics Analysts may not be able to retrieve pertinent information to the investigation.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Clear Browsing Data on Exit

Impact:

Browsing data will not be deleted on closing and the user will not be able to change this setting.

Note: This setting will preserve browsing history that could contain a user's personal browsing history. Ensure this setting is in compliance with organizational policies.

See Also

https://workbench.cisecurity.org/benchmarks/16430

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Windows

Control ID: 48e939d95fde182eaa151156bb33b910e427ba327c2c9f1f64c3981ea1f6fd66