3.13 Ensure 'Enable Safe Browsing for trusted sources' is set to 'Disabled'

Information

Google Chrome can be adjusted to allow downloads without Safe Browsing checks when the requested file is from a trusted source. Trusted sources can be defined using recommendation 'Configure the list of domains on which Safe Browsing will not trigger warnings'.

The recommended state for this setting is: Disabled (0)

NOTE: On Microsoft Windows, this functionality is only available on instances that are joined to a Microsoft Active Directory domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management.

Rationale:

Information requested from trusted sources shall not be sent to Google's safe browsing servers.

Impact:

If this setting is disabled, files downloaded from intranet resources will not be checked by Google Services.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled:

Computer Configuration\Administrative Templates\Google\Google Chrome\Enable Safe Browsing for trusted sources

Default Value:

Unset (Same as Enabled, but user can change)

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-8, CSCv7|4.8

Plugin: Windows

Control ID: 8d4c6cf1e8fa3dc555be17437d7e8b7000615a8ea3f98a18f2feb625fe99c05e