2.11 Ensure 'Allow download restrictions' is set to 'Enabled: Block malicious downloads'

Information

Google Chrome can block certain types of downloads, and won't let users bypass the security warnings, depending on the classification of Safe Browsing.

No special restrictions. Default. (0, Disabled) (Default)

Block malicious downloads and dangerous file types. (1)

Block malicious downloads, uncommon or unwanted downloads and dangerous file types. (2)

Block all downloads. (3)

Block malicious downloads. Recommended. (4)

The recommended state for this setting is: Enabled with a value of Block malicious downloads. Recommended. (4)

NOTE: These restrictions apply to downloads triggered from webpage content, as well as the Download link... menu option. They don't apply to the download of the currently displayed page or to saving as PDF from the printing options.

Rationale:

Users shall be prevented from downloading malicious file types, and shall not be able to bypass security warnings.

Impact:

If this setting is enabled, all downloads are allowed, except for those that carry Safe Browsing warnings. These are downloads that have been identified as risky or from a risky source by the Google Safe Browsing Global intelligence engine.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Block malicious downloads. Recommended.:

Computer Configuration\Polices\Administrative Templates\Google\Google Chrome\Allow download restrictions

Default Value:

Unset (Same as Disabled, but user can change)

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4, CSCv7|10.5

Plugin: Windows

Control ID: 5be47a2eba69d56c098f771440d0d0b0aad3389f59a38d2f0a01e4d914c7808e