1.6 Ensure 'Ask where to save each file before downloading' is set to 'Enabled'

Information

Google Chrome offers to download files automatically to the default download directory without prompting.

If this setting is enabled, users are always asked where to save each file before downloading.

The recommended state for this setting is: Enabled (1)

Rationale:

Users shall be prevented from the drive-by-downloads threat.

Impact:

None - This is the default behavior.

Solution

To establish the recommended configuration via Group Policy, set the
following UI path to Enabled:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Ask where to save each file before downloading

Default Value:

Unset (Same as Enabled, but user can change)

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(2)

Plugin: Windows

Control ID: 09138f5cbc768ae3125068ef21d4f9b3595cbb88aafb3c34def547bc94b971af