2.13 Ensure 'Enable Site Isolation for every site' is set to 'Enabled'

Information

This policy controls is every website will load into its own process.
Rationale:
Chrome will load each website in its own process. So, even if a site bypasses the same-origin policy, the extra security will help stop the site from stealing your data from another website.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled.
Computer Configuration\Administrative Templates\Google\Google Chrome\Enable Site Isolation for every site
Impact:
If the policy is enabled, each site will run in its own process which will cause the system to use more memory. You might want to look at the IsolateOrigins policy setting to get the best of both worlds, isolation and limited impact for users, by using IsolateOrigins with a list of the sites you want to isolate.
Default Value:
If the policy is not configured, the user will be able to change this setting.

See Also

https://workbench.cisecurity.org/files/2385

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(4), CSCv6|2.4, CSCv7|2.10

Plugin: Windows

Control ID: 7e072ff100120b0473d90b649f873ebf29a2e7d0175f27dc3c542857f8e2a6c5