Skip to content

Google Chrome Current Windows Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • Online revocation checks must be performed.

    <VulnDiscussion>By setting this policy to true, the previous behavior is restored and online OCSP/CRL checks will be performed. If the policy...
    Rule Medium Severity
  • SRG-APP-000206

    <GroupDescription></GroupDescription>
    Group
  • Web Bluetooth API must be disabled.

    &lt;VulnDiscussion&gt;Setting the policy to 3 lets websites ask for access to nearby Bluetooth devices. Setting the policy to 2 denies access to ne...
    Rule Medium Severity
  • SRG-APP-000383

    <GroupDescription></GroupDescription>
    Group
  • Use of the QUIC protocol must be disabled.

    &lt;VulnDiscussion&gt;QUIC is used by more than half of all connections from the Chrome web browser to Google's servers, and this activity is undes...
    Rule Medium Severity
  • SRG-APP-000080

    <GroupDescription></GroupDescription>
    Group
  • Session only based cookies must be enabled.

    &lt;VulnDiscussion&gt;Cookies must only be allowed per session and only for approved URLs as permanently stored cookies can be used for malicious i...
    Rule Medium Severity
  • SRG-APP-000047

    <GroupDescription></GroupDescription>
    Group
  • SRG-APP-000605

    <GroupDescription></GroupDescription>
    Group
  • URLs must be allowlisted for Autoplay use.

    &lt;VulnDiscussion&gt;Controls the allowlist of URL patterns that autoplay will always be enabled on. If the "AutoplayAllowed" policy is set to "Tr...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules