2.15.1 (L1) Ensure 'Configure the list of domains on which Safe Browsing will not trigger warnings' is set to 'Disabled'

Information

The setting determines the functionality of Safe Browsing.

- Disabled (0): Safe Browsing protection applies to all resources
- Enabled (1), with a list of 1 or more sites: Means Safe Browsing will trust the domains you designate. It won't check them for dangerous resources such as phishing, malware, or unwanted software.

The recommended state for this setting is: Disabled (0)

NOTE: Safe Browsing's download protection service won't check downloads hosted on these domains, and its password protection service won't check for password reuse.

Google Safe Browsing will help protect users from a variety of malicious and fraudulent sites, or from downloading dangerous files.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Safe Browsing settings\Configure the list of domains on which Safe Browsing will not trigger warnings.

Impact:

None - This is the default behavior.

NOTE: The only real impact is possible user annoyance if they are going to a legitimate site that is falsely considered fraudulent (a rare occurrence). This can be handled by adding the site to the allowlist and/or notifying Google of the false finding.

See Also

https://workbench.cisecurity.org/benchmarks/23110

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(3), 800-53|SC-7(4), CSCv7|7.4

Plugin: Windows

Control ID: 5ff49dd9bc00fa1b9de2c89c56c6c47b0f4a2147ab56e99964c4ef04259c5c7f