Skip to content

Upstream STIG for Google Chromium

Rules and Groups employed by this XCCDF Profile

  • Disable All Plugins by Default

    Plugins are developed internally or by third party sources and are designed to extend Google Chromium's functionality. All plugins should be blackl...
    Rule Unknown Severity
  • Disable Popups

    Chromium allows you to manage whether or not unwanted pop-up windows appear. To disable pop-ups, set <code>DefaultPopupsSetting</code> to <code>2</...
    Rule Unknown Severity
  • Disable Insecure And Obsolete Protocol Schemas

    Each access to a URL is handled by the browser according to the URL's "scheme". The "scheme" of a URL is the section before the ":". The term "prot...
    Rule Unknown Severity
  • Disable Saved Passwords

    Disable by setting ImportSavedPasswords to false in the Chromium policy file.
    Rule Unknown Severity
  • Disable Search Suggestion

    Chromium tries to guess what users are searching for when users enter search data in the search Omnibox. This should be disabled by setting <code>...
    Rule Unknown Severity
  • Disable Session Cookies

    To disable session only cookies sites, set CookiesSessionOnlyForUrls to none in the Chromium policy file.
    Rule Unknown Severity
  • Disable 3rd Party Cookies

    Third party cookies should be be enabled. To disable third party cookies, set <code>BlockThirdPartyCookies</code> to <code>true</code> in the Chrom...
    Rule Unknown Severity
  • Disable Location Tracking

    Location tracking is enabled by default and can track user's browsing habits. Location tracking should be disabled by setting <code>DefaultGeolocat...
    Rule Unknown Severity
  • Enable Only Approved Plugins

    An organization might need to use an internal or third party developed plugins. Any organizationally approved plugin should be enabled. To enable a...
    Rule Unknown Severity
  • Enable Saving the Browser History

    Users can enable or disable the saving of browser history in Chromium. Browser history should be retained by setting <code>SavingBrowserHistoryDisa...
    Rule Unknown Severity
  • Enable Encrypted Searching

    Specifies the URL of the search engine used when doing a default search. The URL should contain the string <code>{searchTerms}</code>. To set the U...
    Rule Unknown Severity
  • Enable the Safe Browsing Feature

    Chromium has the capability to check URLs for known malware and phishing associated with websites through the Safe Browsing Feature. This can be ...
    Rule Unknown Severity
  • Enable Only Approved Extensions

    An organization might need to use an internal or third party developed extension. Any organizationally approved extenstion should be enabled. To en...
    Rule Unknown Severity
  • Set Chromium's HTTP Authentication Scheme

    To set the default Chromium's HTTP Authentication Scheme, set <code>AuthSchemes</code> to <code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_...
    Rule Unknown Severity
  • Require Outdated Plugins to be Authorized

    Chromium should prompt users for authorization to run outdated plugins. This can be enabled by setting <code>AlwaysAuthorizePlugins</code> to <code...
    Rule Unknown Severity
  • Ensure the Chromium Policy Configuration File Exists

    Chromium can be configured with numerous policies and settings. These settings can be set so that a user is unable to edit or change them. To preve...
    Rule Unknown Severity
  • Set the Default Home Page

    When a browser is started the first web page displayed is the "home page". While the home page can be selected by the user, the default home page n...
    Rule Unknown Severity
  • Enable Plugins for Only Approved URLs

    In some cases, plugins utilized by organizationally approved websites may be allowed to be used by those websites, configure the approved URLs allo...
    Rule Unknown Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules