4.2.4 Ensure 'Block clipboard on these sites' Is Configured

Information

This setting allows administrators to list specific sites that do not have access to the clipboard site permissions.

Note: This does not include using keyboard shortcuts. Those are not gated by the clipboard site permission.

Rationale:

Specifying URLs that do not have access to the clipboard site permissions limits data for sites that have access to data on the clipboard, and allows for more sites to have access.

Setting this policy denies specified URLs to have access to the clipboard site permissions. This will limit the specified sites to access the data on the clipboard that other sites do. DefaultClipboardSetting is recommended to be set to disabled, so this list would be a backup to that policy in case it was enabled, left as the default, or removed.

Impact:

Enforcing this recommendation can cause the clipboard functionality to not work identically for every site.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled and set Show to the blocked URLs:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Content settings\Block clipboard on these sites

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-8, CSCv7|4.8

Plugin: Windows

Control ID: 609b3d876343a4bd563e75fa5f4ec05109762f4fdf60bcbea1a1a59d28c40138