1.16 Ensure 'Disable Certificate Transparency enforcement for a list of URLs' is set to 'Disabled'

Information

Google Chrome allows to specify URLs/hostnames for which Certificate Transparency will not be enforced.
Rationale:
Certificates that are required to be disclosed via Certificate Transparency shall be treated for all URLs as untrusted if they are not disclosed according to the Certificate Transparency policy.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled:
Computer Configuration\Administrative Templates\Google\Google Chrome\Disable Certificate Transparency enforcement for a list of URLs
Impact:
If this setting is disabled, no URLs are excluded from Certificate Transparency requirements.
Default Value:
Disabled.

See Also

https://workbench.cisecurity.org/files/2385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv7|7

Plugin: Windows

Control ID: e7b3b0667195a34498abc4106b168cb38d60c94371807f8a524d3fc60df28dd4