2.14 Ensure 'Allow download restrictions' is set to 'Enabled' with 'Block dangerous downloads' specified.

Information

Google Chrome allows to block certain types of downloads, and won't let users bypass the security warnings, depending on the classification of Safe Browsing.
Rationale:
Users shall be prevented from downloading certain types of files, and shall not be able to bypass security warnings.

Solution

To establish the recommended configuration via Group Policy, set thefollowing UI path to Enabled with value 'Block dangerous downloads' selected from drop down:
Computer Configuration\Administrative Templates\Google\Google Chrome\Allow download restrictions
Impact:
If this setting is enabled, all downloads are allowed, except for those that carry Safe Browsing warnings.
Default Value:
No special restrictions (usual security restrictions based on Safe Browsing analysis results).

See Also

https://workbench.cisecurity.org/files/2385

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(2), CSCv7|8

Plugin: Windows

Control ID: 230d180146b4b45daac4289bbda71431af65f46c4ef289e00e62fe253e235a28