2.10 Ensure 'Choose how to specify proxy server settings' is not set to 'Enabled' with 'Auto detect proxy settings'

Information

Google Chrome offers the functionality to configure the proxy settings by automatic discovery using WPAD (Web Proxy Auto-Discovery Protocol).
Rationale:
Attackers may abuse the WPAD auto-config functionality to supply computers with a PAC file that specifies a rogue web proxy under their control.

Solution

To establish the recommended configuration via Group Policy, make sure the following UI path is not set to 'Enabled' with 'Auto detect proxy settings':
Computer Configuration\Administrative Templates\Google\Google Chrome\Proxy server\Choose how to specify proxy server settings
Impact:
If the policy is enabled, the proxy configuration will no longer be discovered using WPAD.
Default Value:
If the policy is not configured, the user will be able to change this setting.

See Also

https://workbench.cisecurity.org/files/2385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv7|12.9

Plugin: Windows

Control ID: 6da7c771b92d2ae7c06a1fe27f5ec8bef59562bb9be6adc048d61936d3f50689