1.14 Ensure 'Origins or hostname patterns for which restrictions on insecure origins should not apply' is set to 'Disabled'

Information

Google Chrome allows to specify a list of origins (URLs) or hostname patterns (such as '*.example.com') for which security restrictions on insecure origins will not apply and are prevented from being labeled as 'Not Secure' in the omnibox.
Rationale:
Insecure contexts shall always be labeled as insecure.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled:
Computer Configuration\Administrative Templates\Google\Google Chrome\Origins or hostname patterns for which restrictions on insecure origins should not apply
Impact:
Insecure contexts are labeled as insecure.
Default Value:
Disabled.

See Also

https://workbench.cisecurity.org/files/2385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv7|7

Plugin: Windows

Control ID: fca6ef835fd710cf487536e20bef0777c3b23cd09ca03f5831d330c11cdfee43