STIGQter STIGQter: STIG Summary: Google Chrome Current Windows Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 23 Apr 2021:

Download restrictions must be configured.

DISA Rule

SV-221588r615937_rule

Vulnerability Number

V-221588

Group Title

SRG-APP-000089

Rule Version

DTBC-0055

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If the system is on the SIPRNet, this requirement is NA.
Windows group policy:
1. Open the group policy editor tool with gpedit.msc
2. Navigate to Policy Path: Computer Configuration\Administrative Templates\Google\Google Chrome\
Policy Name: Allow download restrictions
Policy State: 1 or 2
Policy Value: N/A

Check Contents

If the system is on the SIPRNet, this requirement is NA.
Universal method:
1. In the omnibox (address bar) type chrome:// policy
2. If "DownloadRestrictions" is not displayed under the "Policy Name" column or it is not set to "1" or "2" under the "Policy Value" column, then this is a finding.

Windows method:
1. Start regedit
2. Navigate to HKLM\Software\Policies\Google\Chrome\
3. If the "DownloadRestrictions" value name does not exist or its value data is not set to "1" or "2", then this is a finding.

Vulnerability Number

V-221588

Documentable

False

Rule Version

DTBC-0055

Severity Override Guidance

If the system is on the SIPRNet, this requirement is NA.
Universal method:
1. In the omnibox (address bar) type chrome:// policy
2. If "DownloadRestrictions" is not displayed under the "Policy Name" column or it is not set to "1" or "2" under the "Policy Value" column, then this is a finding.

Windows method:
1. Start regedit
2. Navigate to HKLM\Software\Policies\Google\Chrome\
3. If the "DownloadRestrictions" value name does not exist or its value data is not set to "1" or "2", then this is a finding.

Check Content Reference

M

Target Key

4081

Comments