2.3.4 Ensure 'Default third-party storage partitioning setting' Is Enabled and Blocked

Information

This setting will block any site from accessing the storage session from any other site. This will block third party trackers that are embedded on multiple sites from tracking a user across the sites they visit. Blocking third party access to the user agent will not allow sites to infer data about the user from the data from another site.

It can be configured to either:

Enabled (1): Allow third-party storage partitioning to be enabled.

Disabled (2): Block third-party storage partitioning from being enabled.

Rationale:

Setting this requires that user agent state needs to be keyed by more than a single origin or site. It can also defend against timing attacks on web privacy.

Impact:

Enforcing this may cause users to experience issues with sites they regularly visit that already grant access to third-parties.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Block third-party storage partitioning from being enabled.:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Content settings\Default third-party storage partitioning setting

Default Value:

Not Configured

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2, CSCv7|3.3

Plugin: Windows

Control ID: a1c51d8c7a8c4b30a824f2d94545fbe5957d497fa21c5e17da3aa439e1651a3c