2.9 Ensure 'Allow download restrictions' is set to 'Enabled: Block dangerous downloads'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Google Chrome can block certain types of downloads, and won't let users bypass the security warnings, depending on the classification of Safe Browsing.

No special restrictions (0, Disabled)

Block dangerous downloads (1)

Block potentially dangerous downloads (2)

Block all downloads (3)

Block malicious downloads (4)

The recommended state for this setting is: Enabled with a value of Block dangerous downloads (1)

NOTE: These restrictions apply to downloads triggered from webpage content, as well as the Download link... menu option. They don't apply to the download of the currently displayed page or to saving as PDF from the printing options.

Rationale:

Users shall be prevented from downloading certain types of files, and shall not be able to bypass security warnings.

Impact:

If this setting is enabled, all downloads are allowed, except for those that carry Safe Browsing warnings. These are downloads that have been identified as risky or from a risky source by the Google Safe Browsing Global intelligence engine.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Block dangerous downloads:

Computer Configuration\Polices\Administrative Templates\Google\Google Chrome\Allow download restrictions

Default Value:

Unset (Same as Disabled, but user can change)

See Also

https://workbench.cisecurity.org/files/3653

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(2), CSCv7|8

Plugin: Windows

Control ID: ac78d827776d23a5ab0da23406f8ceefcff4d0857e8f1f8356ee9e0dcc3aec24