1.15 Ensure 'Enable component updates in Google Chrome' is set to 'Enabled'

Information

Google Chrome's Component Updater updates several components of Google Chrome on a regular basis (applies only to Chrome browser components).

The recommended state for this setting is: Enabled (1)

NOTE: Updates to any component that does not contain executable code, does not significantly alter the behavior of the browser, or is critical for its security will not be disabled (E.g. certificate revocation lists and Safe Browsing data is updated regardless of this setting). FYI chrome://components lists all components, but not if they are affected by this setting.

NOTE: Google provided the following list of 'some of the components' controlled by this setting:

Recovery component

Pnacl

Floc

Optimization hints

SSL error assistant

CRL set

Origin trials

SW reporter

PKI metadata

Rationale:

Google Chrome Updater shall be used to keep the components bundled to Chrome up-to-date.

Impact:

None - This is the default behavior.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Enable component updates in Google Chrome

Default Value:

Unset (Same as Enabled, but user can change)

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.5

Plugin: Windows

Control ID: 631e1018e6c350bed0b7af82f975ff6a51129db933bea5e5f63cd5da2c9c034d