1.2.2 Ensure 'Safe Browsing Protection Level' is set to 'Enabled: Safe Browsing is active in the standard mode.' or higher

Information

Control whether Google Chrome's Safe Browsing feature is enabled and the mode in which it operates. If you set this setting as mandatory, users cannot change or override the Safe Browsing setting in Google Chrome.

If this setting is left not set, Safe Browsing will operate in Standard Protection mode but users can change this setting.

No Protection (0): Safe Browsing is never active.

Standard Protection (1): Safe Browsing is active in the standard mode.

Enhanced Protection (2): Safe Browsing is active in the enhanced mode. This mode provides better security, but requires sharing more browsing information with Google.

The recommended state for this setting is: Safe Browsing is active in the standard mode. (1) or higher

Rationale:

Google Safe Browsing will help protect users from a variety of malicious and fraudulent sites, or from downloading dangerous files.

NOTE: Google recommends using Enhanced Safe Browsing Mode (2). Turning on Enhanced Safe Browsing will substantially increase protection from dangerous websites and downloads, but will share more data with Google.

For more details, please refer to the items in the References section below.

Impact:

None - This is the default behavior (Standard Protection).

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Safe Browsing is active in the standard mode.:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Safe Browsing settings\Safe Browsing Protection Level

Default Value:

Unset (Same as Standard Protection, but user can change)

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(3), 800-53|SC-7(4), CSCv7|7.4

Plugin: Windows

Control ID: d47427bdad8a54edfbfc8b729af91470f4836091067581ca29b530a84c98644b