3.13 Ensure 'Enable Safe Browsing for trusted sources' is set to 'Disabled'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Google Chrome can be adjusted to allow download without Safe Browsing checks when the requested files is from a trusted source. Trusted sources can be defined using recommendation 'Configure the list of domains on which Safe Browsing will not trigger warnings'.

The recommended state for this setting is: Disabled (0)

NOTE: On Microsoft Windows, this functionality is only available on instances that are joined to a Microsoft Active Directory domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management.

Rationale:

Information requested from trusted sources shall not be sent to Google's safe browsing servers.

Impact:

If this setting is disabled files downloaded from intranet resources will not be checked by Google Services.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled:

Computer Configuration\Administrative Templates\Google\Google Chrome\Enable Safe Browsing for trusted sources

Default Value:

Unset (Same as Enabled, but user can change)

See Also

https://workbench.cisecurity.org/files/3653

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv7|13

Plugin: Windows

Control ID: c55fdb02ade3149ae0a0a65f94cb6387ee844cd9a5932abbbf119bb845aaa329