1.1.9.1 (L1) Ensure 'Lock Encrypted Media Extensions' is set to 'Enabled'

Information

This policy setting configures whether encrypted media extensions (EME) are downloaded automatically without user consent. EME is a JavaScript API for playing DRMed video content in HTML.

The recommended state for this setting is: Enabled

Downloading media from the internet without user consent could lead to malicious content being downloaded and deployed to the system.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Mozilla\Firefox\Encrypted Media Extensions\Lock Encrypted Media Extensions

Note: This Group Policy path does not exist by default. An additional Group Policy template ( firefox.admx/adml ) is required - it is available to download at this

link

.

Impact:

Users will have to consent to downloading EMEs.

See Also

https://workbench.cisecurity.org/benchmarks/18454

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-11(2), 800-53|SC-7(11)

Plugin: Windows

Control ID: c2a54d9356e210f486e9069d38cd543c5996ee719acefd7836aa51b258642767