STIGQter STIGQter: STIG Summary: Microsoft Edge Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 14 Jan 2021:

WebUSB must be disabled.

DISA Rule

SV-235742r626523_rule

Vulnerability Number

V-235742

Group Title

SRG-APP-000141

Rule Version

EDGE-00-000025

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Content settings/Control use of the WebUSB API" to enabled" and select "Do not allow any site to request access to USB devices via the WebUSB API".

Check Contents

The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Content settings/Control use of the WebUSB API" must be set to "enabled" with the option value set to "Do not allow any site to request access to USB devices via the WebUSB API".

Use the Windows Registry Editor to navigate to the following key:
HKLM\SOFTWARE\Policies\Microsoft\Edge

If the value for "DefaultWebUsbGuardSetting" is not set to "REG_DWORD = 2", this is a finding.

Vulnerability Number

V-235742

Documentable

False

Rule Version

EDGE-00-000025

Severity Override Guidance

The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Content settings/Control use of the WebUSB API" must be set to "enabled" with the option value set to "Do not allow any site to request access to USB devices via the WebUSB API".

Use the Windows Registry Editor to navigate to the following key:
HKLM\SOFTWARE\Policies\Microsoft\Edge

If the value for "DefaultWebUsbGuardSetting" is not set to "REG_DWORD = 2", this is a finding.

Check Content Reference

M

Target Key

5280

Comments