2.3.21 (L2) Ensure 'Control use of the File System API for writing' is set to 'Enabled: Do not allow any site to request write access to files and directories via the File System API'

Information

This policy setting determines whether websites can ask for write access to the host operating system's file system using the File System API.

Policy options mapping:

BlockFileSystemWrite (2) = Do not allow any site to request write access to files and directories via the File System API

AskFileSystemWrite (3) = Allow sites to ask the user to grant write access to files and directories via the File System API

The recommended state for this setting is: Enabled: Don't allow any site to request write access to files and directories.

This API allows web apps to write or save changes directly to files and folders on user devices. It also allows for the writing files.

Allowing web apps the ability to save changes directly to files and folders opens the organization to the possibility of malicious content being saved directly to user devices.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Do not allow any site to request write access to files and directories via the File System API :

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Content settings\Control use of the File System API for writing

Impact:

Users with creative roles that require write access to files and directories via the File System API may need additional permissions granted for said roles.

See Also

https://workbench.cisecurity.org/benchmarks/23110

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 63355bc6195fff51eab09519c89174e45cdcfb04445a969950a58c5165b40df4