2.12 Ensure 'Enable Chrome Cleanup on Windows' is Configured

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Chrome provides a Cleanup-feature to detect unwanted software. This feature periodically scans the system for unwanted software and will ask the user if they wish to remove it, if any has been found.

The recommended state for this setting is: Explicitly set to Enabled (1) or Disabled (0) based on the organization's needs.

Rationale:

The Google Chrome Cleanup is Enabled by default and each organization should review and determine if they want to use this solutions for malware detection. If another solution is used instead of the built in Chrome option then an organization should configure the setting to Disabled.

Impact:

Organizational Specific.

NOTE: If Disabled, Chrome Cleanup will no longer be able to scan the system. If users do not have a centrally managed anti-malware solution then leaving this setting Enabled can help protect a system.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

To establish the recommended configuration via Group Policy, configure the following setting to meet organizational requirements:

Computer Configuration\Polices\Administrative Templates\Google\Google Chrome\Enable Chrome Cleanup on Windows

Default Value:

Unset (Same as Enabled, and users can change)

See Also

https://workbench.cisecurity.org/files/3653

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv7|8.1

Plugin: Windows

Control ID: dfcf285131023e570c2b66ee73c7fb3a89a1ef1fa49f5b68a080edfe857810df