1.9 Ensure 'Determine the availability of variations' is set to 'Enable all variations'

Information

Configuring this setting allows specifying which variations are allowed to be applied in Google Chrome. Variations provide a means for Google to offer modifications to Google Chrome without shipping a new version of the browser by selectively enabling or disabling already existing features.

Enable all variations (0): Allows all variations to be applied to the browser (Default value).

Enable variations concerning critical fixes only (1): Allows only variations considered critical security or stability fixes to be applied to Google Chrome.

Disable all variations (2): Prevent all variations from being applied to the browser. Please note that this mode can potentially prevent the Google Chrome developers from providing critical security fixes in a timely manner and is thus not recommended.

The recommended state for this setting is: Enable all variations (0)

NOTE: Google strongly believes there is no added security benefit for turning this to critical fixes as leaving it on increases the stability of the browser. Disabling variations can also prevent getting critical security updates in a timely manner.

Rationale:

Google strongly recommends leaving this setting at the default (0 = Enable all variations), so fixes are gradually enabled (or if necessary, rapidly disabled) via the Chrome Variations framework.

Impact:

None - This is the default behavior.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Enable all variations:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Determine the availability of variations

Default Value:

Unset (Same as Disabled, but user can change)

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.5, CSCv7|7.4

Plugin: Windows

Control ID: 5280bd4cc925891c63cae1011ad76d6b6359bf9c9fed5ab04906e96e9346ad25