3.1 Ensure 'Default cookies setting' is set to 'Enabled' (Keep cookies for the duration of the session)

Information

Allows you to set whether websites are allowed to set local data. Setting local data can be either allowed for all websites or denied for all websites.
Rationale:
Permanently stored cookies may be used for malicious intent.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled with Keep cookies for the duration of the session selected from the drop down.
Computer Configuration\Administrative Templates\Google\Google Chrome\Content Settings\Default cookies setting
Impact:
If this setting is enabled, cookies will be cleared when the session closes.
Default Value:
If this policy is left not set, AllowCookies will be used and the user will be able to change it.

See Also

https://workbench.cisecurity.org/files/2385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|13

Plugin: Windows

Control ID: f96e57a8f7813b56e62e2be7708d4f9c56560c57143d6f43692dcde2d9d16e26