4.2.5 Ensure 'Default clipboard setting' Is 'Enabled' to 'Deny Permissions'

Information

This setting controls the defaults for clipboard permission access from sites. It can be configured to either:

Disabled (2): Does not allow access to the clipboard site permission by any site

Enabled (3): Sites ask the user to allow access to the clipboard site permission

If the value for DefaultClipboardSetting is not changed from the default, it will behave as if it is enabled. ClipboardAllowedForUrls or ClipboardBlockedForUrls will override this setting for any site that matches the configured URL patterns.

With the setting disabled, organizations will need to set ClipboardAllowedForUrls for any URLs they want to make exempt.

Rationale:

The clipboard stores data, text, and images that are shared between all applications. An organization would disable clipboard access to restrict sites from reading the contents of the clipboard when visiting.

Impact:

Not allowing sites to have access to the clipboard permission can cause issues with formatting or access to needed images on the clipboard.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Do not allow any site to use the clipboard site permission:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Content settings\Default clipboard setting




Default Value:

Allow clipboard permission access

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-8, CSCv7|4.8

Plugin: Windows

Control ID: e36c684bc4b3b8733c56e6b19f1a4aa002bbeb6c956ebc2a6f1ddfd53ebfe2d6