3.1.1 Ensure 'Default cookies setting' is set to 'Enabled: Keep cookies for the duration of the session'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

When leaving the setting _RestoreOnStartup _unset results in the use of _DefaultCookiesSetting _for all sites, if it's set. If _DefaultCookiesSetting _is not set, the user's personal setting applies.

Disabled (0, user's personal setting applies)

Allow all sites to set local data (1)

Do not allow any site to set local data (2)

Keep cookies for the duration of the session (4)

The recommended state for this setting is: Enabled with a value of Keep cookies for the duration of the session (4)

NOTE: If the RestoreOnStartup setting is set to restore URLs from previous sessions this setting will not be respected and cookies will be stored permanently for those sites.

Rationale:

Permanently stored cookies may be used for malicious intent.

Impact:

If this setting is enabled, cookies will be cleared when the session closes.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled with Keep cookies for the duration of the session:

Computer Configuration\Administrative Templates\Google\Google Chrome\Content Settings\Default cookies setting

Default Value:

Unset (Same as Disabled, but user can change)

See Also

https://workbench.cisecurity.org/files/3653

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|13

Plugin: Windows

Control ID: 965b86819415c4da16df7820b63fbe30ac3c0b14288e04549e192c3c45d356ea