1.8 Ensure 'Control SafeSites adult content filtering' is set to 'Enabled: Filter top level sites (but not embedded iframes) for adult content'

Information

Google Chrome can use the Google Safe Search API to classify URLs as pornographic or not.

The recommended state for this setting is: Enabled with a value of Filter top level sites (but not embedded iframes) for adult content (1)

Rationale:

Allowing search results to present sites that may have malicious content should be prohibited to help ensure users do not accidentally visit sites that are more prone to malicious content including spyware, adware, and viruses.

Impact:

Users' search results will be filtered and content such as adult text, videos, and images will not be shown.

NOTE: Using Googles Safe Search API may leak information which is typed/pasted by mistake into the omnibox, e.g. passwords, internal webservices, folder structures, etc.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Do not filter sites for adult content:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Control SafeSites adult content filtering.

Default Value:

Unset (Same as Enabled with 'Do not filter sites for adult content', but user can change)

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(3), 800-53|SC-7(4), CSCv7|7.4

Plugin: Windows

Control ID: b62282d384ebf9b847321aafabdbe1a4e758b33afa57fc6171270e1bc2bf5730