DTBC-0055 - Download restrictions must be configured.

Information

Setting the policy means users cannot bypass download security decisions. There are many types of download warnings within Chrome, which roughly break down into these categories:
- Malicious, as flagged by the Safe Browsing server.
- Uncommon or unwanted, as flagged by the Safe Browsing server.
- A dangerous file type (e.g., all SWF downloads and many EXE downloads).

Setting the policy blocks different subsets of these, depending on its value:

0 = No special restrictions. Default.
1 = Block malicious downloads and dangerous file types.
2 = Block malicious downloads, uncommon or unwanted downloads, and dangerous file types.
3 = Block all downloads.
4 = Block malicious downloads. Recommended.

Solution

If the system is on the SIPRNet, this requirement is Not Applicable.

Windows group policy:
1. Open the group policy editor tool with gpedit.msc.
2. Navigate to Policy Path: Computer Configuration\Administrative Templates\Google\Google Chrome\
Policy Name: Allow download restrictions
Policy State: 1, 2, or 4
Policy Value: N/A

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Google_Chrome_V2R11_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12a., CAT|II, CCI|CCI-000169, Rule-ID|SV-221588r1106670_rule, STIG-ID|DTBC-0055, STIG-Legacy|SV-94635, STIG-Legacy|V-79931, Vuln-ID|V-221588

Plugin: Windows

Control ID: 657eb73318bdaa07546dd4e7d124f491c6f40e8cea41c80834d1d91a6a0de289