2.2.10 (L2) Ensure 'Default Sensors Setting' is set to 'Enabled: Do not allow any site to access sensors'

Information

This setting controls website access and use of system sensors such as motion and light.

- Allow sites to access sensors (1)
- Do not allow any site to access sensors (2)

The recommended state for this setting is: Do not allow any site to access sensors (2)

The recommended state for this setting is: Enabled with a value of Do not allow any site to access sensors

NOTE: If more granular control is needed (per website) then this setting can be used in combination with the SensorsAllowedForUrls and SensorsBlockedForUrls settings. For example, SensorsAllowedForUrls can be used to allow sensor access to specific sites. Please see the references below for more information.

Preventing access to system sensors may prevent malicious sites from using these sensors for user profiling (OpSec).

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Do not allow any site to access sensors :

Computer Configuration\Administrative Templates\Google\Google Chrome\Content settings\Default sensors setting

Impact:

This setting would also prevent legitimate sites from accessing it as well.

See Also

https://workbench.cisecurity.org/benchmarks/16430

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 3832fa8c81892874fb124e22f37d994fdf470a235da7a2e39482614cd2d2ce4d