4.2.2 (L2) Ensure 'Default Sensors Setting' is set to 'Enabled: Do not allow any site to access sensors'

Information

This setting controls website access and use of system sensors such as motion and light.

- Allow sites to access sensors (1)
- Do not allow any site to access sensors (2)

The recommended state for this setting is: Do not allow any site to access sensors (2)

The recommended state for this setting is: Enabled with a value of Do not allow any site to access sensors

NOTE: If more granular control is needed (per website) then this setting can be used in combination with the

SensorsAllowedForUrls

and

SensorsBlockedForUrls

settings. For example,

SensorsAllowedForUrls

can be used to allow sensor access to specific sites. Please see the references below for more information.

Preventing access to system sensors may prevent malicious sites from using these sensors for user profiling (OpSec).

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Do not allow any site to access sensors :

Computer Configuration\Administrative Templates\Google\Google Chrome\Content settings\Default sensors setting

Impact:

This setting would also prevent legitimate sites from accessing it as well.

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: ade8bd8087cc2dc8954d3018bbafe1afd99019b68fb664f422425a81a3b460e0