2.3.5 Ensure 'Block third-party storage partitioning for these origins' Is Configured

Information

This setting will block specific sites your organization selects from accessing the storage session from any other site. This will allow an organization to block third party trackers that are embedded on multiple sites from tracking a user across the sites they visit. It will also allow blocking third party access to the user agent and to infer data about the user from the data from another site.

Setting the Level 2 recommendation DefaultThirdPartyStoragePartitioningSetting will block all sites, not just this set list in ThirdPartyStoragePartitioningBlockedForOrigins

Rationale:

If your organization does not want to block all third-party sites from accessing the user agent, you can configure a curated list of sites to block.

Impact:

This might cause the user experience to vary from allowed sites to blocked sites.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled and set Show to the approved URLs:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Content settings\Block third-party storage partitioning for these origins

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-8, CSCv7|4.8

Plugin: Windows

Control ID: fc5082795e2586d83dd0ee4078287736af5fa3886966c2a99089803f5c84ee8d