1.27 Ensure 'Origins or hostname patterns for which restrictions on insecure origins should not apply' is set to 'Disabled'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Google Chrome can use a list of origins (URLs) or hostname patterns (such as '*.example.com') for which security restrictions on insecure origins will not apply and are prevented from being labeled as 'Not Secure' in the omnibox.

The recommended state for this setting is: Disabled (0)

Rationale:

Insecure contexts shall always be labeled as insecure.

Impact:

None - This is the default behavior.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Origins or hostname patterns for which restrictions on insecure origins should not apply

Default Value:

Unset (Same as Disabled, but user can change)

See Also

https://workbench.cisecurity.org/files/3653

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv7|7

Plugin: Windows

Control ID: 9602738cd4783fb6356f9ba42d3978b1b715d27971bb5256919028516b3e4cf4