4.5 Ensure 'Allow or deny video capture' is set to 'Disabled'

Information

This setting allows administrators to set whether the end-user is prompted for access to video capture devices.

Disabled (0): Turns off prompts and video capture will only work for URLs configured in the VideoCaptureAllowedUrls list.

Enabled (1): With the exception of URLs set in the VideoCaptureAllowedUrls list, users get prompted for video capture access.

NOTE: The setting affects all video input (not just the built-in camera).

The recommended state for this setting is: Disabled (0)

Rationale:

The end-user having the ability to allow or deny video capture for websites in Google Chrome could open an organization up to a malicious site that may capture proprietary information through the browser. By limiting or disallowing video capture, it removes the end-user's discretion, leaving it up to the organization which sites are allowed to use this ability.

Impact:

If you disable this setting, users will not be prompted for video devices when using websites which may need this access, such as a web-based conferencing system. If there are sites which access will be allowed, configuration of the VideoCaptureAllowedUrls setting will be necessary.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled:

Computer Configuration\Administrative Templates\Google\Google Chrome\Allow or deny video capture

Default Value:

Unset (Same as Enabled, but user can change)

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-8, CSCv7|4.8

Plugin: Windows

Control ID: 5beb9eef73de54ed380ed81057b2d8095c01200b206d5c3bad6d9f84b7f92294