1.72 (L2) Ensure 'Configure Speech Recognition' is set to 'Disabled'

Information

This policy setting specifies whether websites can use the W3C Web speech API to recognize speech from the user. The Microsoft Edge implementation of the Web speech API uses Azure Cognitive Services, so voice data will leave the machine.

The recommended state for this setting is: Disabled.

Allowing speech recognition to use the Web speech API in Azure Cognitive permits voice data to leave the machine, potentially allowing sensitive data to be collected from a non-secured third-party source.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Disabled :

Microsoft Edge\Configure Speech Recognition

Impact:

Users will be unable to use speech recognition for voice typing. Users that use speech recognition for accessibility will need other tools implemented for voice typing.

Warning: Disabling this setting will turn off the Speech Recognition feature. Before disabling, make sure this feature is not required for accessibility purposes.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: c9beefdf0bce5f1435757055fe3519244cb1d75d06081cb634a2b2fe2628f9f5