3.4 Ensure 'Block third party cookies' is set to 'Enabled'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Chrome allows cookies to be set by web page elements that are not from the domain in the user's address bar. Enabling this feature prevents third party cookies from being set.

The recommended state for this setting is: Enabled (1)

Rationale:

Blocking third party cookies can help protect a user's privacy by eliminating a number of website tracking cookies.

Impact:

Enabling this setting prevents cookies from being set by web page elements that are not from the domain that is in the browser's address bar.

NOTE: Third Party Cookies and Tracking Protection are required for many business critical websites, including Microsoft 365 web apps (Office 365), SalesForce, and SAP Analytics Cloud. If these, or similar services, are needed by the organization then this setting can be Disabled.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled:

Computer Configuration\Administrative Templates\Google\Google Chrome\Block third party cookies




Default Value:

Unset (Same as Disabled, but user can change)

See Also

https://workbench.cisecurity.org/files/3653

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-10, CSCv6|13

Plugin: Windows

Control ID: e3239ba311f52bd3a7b8c0483452e5864e3b6317b0eb5812cc12d84766cf9821