5.2 Ensure 'Incognito mode availability' is set to 'Enabled: Incognito mode disabled'

Information

Specifies whether the user may open pages in Incognito mode in Google Chrome. The possible values are:

Incognito mode available (0 - Same as Disabled))

Incognito mode disabled (1)

Incognito mode forced (2)

The recommended state for this setting is: Enabled: Incognito mode disabled (1)

Rationale:

Incognito mode in Chrome gives you the choice to browse the internet without your activity being saved to your browser or device.

Allowing users to use the browser without any information being saved can hide evidence of malicious behaviors. This information may be important for a computer investigation, and investigators such as Computer Forensics Analysts may not be able to retrieve pertinent information to the investigation.

Impact:

Users will not be able to initiate Incognito mode for Google Chrome.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Incognito mode disabled:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Incognito mode availability




Default Value:

Unset (Same as Enabled, but user can change)

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-10

Plugin: Windows

Control ID: 5701fd7f96595529234d76ccccdd6e6548a5b073fd27d8fcc15f0f1c796a3f3d