4.11 Ensure 'List of types that should be excluded from synchronization' is set to 'Enabled: passwords'

Information

This setting allows you to specify data types that will be limited/excluded from uploading data to the Google Chrome synchronization service.

The recommended state for this setting is: Enabled with the following text value passwords (Case Sensitive)

NOTE: Other settings in addition to passwords can be included based on organizational needs.

Rationale:

Storing and sharing information could potentially expose sensitive information including but not limited to user passwords and login information. Allowing this synchronization could also potentially allow an end user to pull corporate data that was synchronized into the cloud to a personal machine.

Impact:

Password data will not be synchronized with the Google Chrome synchronization service.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: passwords (Case Sensitive):

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\List of types that should be excluded from synchronization

Default Value:

Unset (Same as Disabled, but user can change)

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 4cfd554c9401b29b45f71eb91de7ddd8862504a388ea89529304a018ab6798f8