1.18 Ensure 'Enable security warnings for command-line flags' is set to 'Enabled'

Information

This setting prevents Google Chrome from showing security warnings that potentially dangerous command-line flags are in use at its launch.

The recommended state of this setting is: Enabled (0)

Rationale:

If Google Chrome is being launched with potentially dangerous flags, this information should be exposed to the user as a warning. If not, the user may be unintentionally using non-secure settings and be exposed to security flaws.

Impact:

None - This is the default behavior.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Enable security warnings for command-line flags

Default Value:

Unset (Same as Enabled, but user can change)

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4, CSCv7|7.2

Plugin: Windows

Control ID: 68112f55df8fd4ec4de31dd19a52014e2bb0db8328f539c37511f319761c3901