2.1 Ensure 'Default Flash Setting' is set to 'Enabled' (Click to Play)

Information

Allows you to set whether websites are allowed to automatically run plugins. Automatically running plugins can be either allowed for all websites or denied for all websites.
Rationale:
Malicious plugins can cause browser instability and erratic behavior so setting the value to 'Click to play' will allow a user to only run necessary plugins.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled with Click to play selected from the drop down.
Computer Configuration\Administrative Templates\Google\Google Chrome\Content Settings\Default Flash Setting
Impact:
If this setting is enabled, users must click plugins to allow their execution
Default Value:
If this policy is left not set, the user will be able to change this setting manually.

See Also

https://workbench.cisecurity.org/files/2385

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(2), CSCv6|7.2, CSCv7|7.2

Plugin: Windows

Control ID: d40a19c70c0d12dc1af32ab29a4a0e492d2fc2eec3bf786015984430b31b0d9e