1.5 Protect Firefox Binaries

Information

Ensure that Firefox is installed and owned by an administrative account in order to protect the binaries and to prevent users from circumventing security settings.
When Firefox is installed by an ordinary user, the software in installed into the user's profile / home directory. This avoids the requirement for administrative access during installation and upgrades, but also allows users to circumvent security settings defined in settings.js and mozilla.cfg files. Having the installation owned by an administrative user can also protect binary and configuration files from malware that is executed in an ordinary user's browser.

Solution

Install Firefox into a shared location that can be accessed by users but modified only by Administrators.

See Also

https://workbench.cisecurity.org/files/1158