1.15 Ensure 'Enable component updates in Google Chrome' is set to 'Enabled'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Google Chrome's Component Updater updates several components of Google Chrome on a regular basis (applies only to Chrome browser components).

The recommended state for this setting is: Enabled (1)

NOTE: Updates to any component that does not contain executable code, does not significantly alter the behavior of the browser, or is critical for its security will not be disabled (E.g. certificate revocation lists and Safe Browsing data is updated regardless of this setting). FYI chrome://components lists all components, but not if they are are affected by this settings.

NOTE: Google provided the following list of 'some of the components' controlled by this settings:

Recovery component

Pnacl

Floc

Optimization hints

SSL error assistant

CRL set

Origin trials

SW reporter

PKI metadata

Rationale:

Google Chrome Updater shall be used to keep the components bundled to Chrome up-to-date.

Impact:

None - This is the default behavior.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Enable component updates in Google Chrome

Default Value:

Unset (Same as Enabled, but user can change)

See Also

https://workbench.cisecurity.org/files/3653

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-2(5), CSCv6|4.5, CSCv7|3.5

Plugin: Windows

Control ID: faa80c22b4ac87004577eae96b8d567928ddfc85c3f7f7948607f0f39f228b7f