Skip to content

III - Administrative Sensitive

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000206

    Group
  • Safe Browsing Extended Reporting must be disabled.

    Enables Google Chrome's Safe Browsing Extended Reporting and prevents users from changing this setting. Extended Reporting sends some system information and page content to Google servers to help d...
    Rule Medium Severity
  • SRG-APP-000141

    Group
  • WebUSB must be disabled.

    Allows you to set whether websites are allowed to get access to connected USB devices. Access can be completely blocked, or the user can be asked every time a website wants to get access to connect...
    Rule Medium Severity
  • SRG-APP-000089

    Group
  • Chrome Cleanup must be disabled.

    If set to "False", prevents Chrome Cleanup from scanning the system for unwanted software and performing cleanups. Manually triggering Chrome Cleanup from chrome://settings/cleanup is disabled. If ...
    Rule Medium Severity
  • SRG-APP-000089

    Group
  • Chrome Cleanup reporting must be disabled.

    If unset, should Chrome Cleanup detect unwanted software, it may report metadata about the scan to Google in accordance with policy set by “SafeBrowsingExtendedReportingEnabled”. Chrome Cleanup wil...
    Rule Medium Severity
  • SRG-APP-000141

    Group
  • Google Cast must be disabled.

    If this policy is set to ”True” or is not set, Google Cast will be enabled, and users will be able to launch it from the app menu, page context menus, media controls on Cast-enabled websites, and (...
    Rule Medium Severity
  • SRG-APP-000141

    Group
  • Autoplay must be disabled.

    This allows a user to control if videos can play automatically with audio content (without user consent) in Google Chrome. If the policy is set to "True", Google Chrome is allowed to autoplay medi...
    Rule Medium Severity
  • SRG-APP-000210

    Group
  • URLs must be allowlisted for Autoplay use.

    Controls the allowlist of URL patterns that autoplay will always be enabled on. If the "AutoplayAllowed" policy is set to "True" then this policy will have no effect. If the "AutoplayAllowed" polic...
    Rule Medium Severity
  • SRG-APP-000206

    Group
  • Anonymized data collection must be disabled.

    Enable URL-keyed anonymized data collection in Google Chrome and prevent users from changing this setting. URL-keyed anonymized data collection sends URLs of pages the user visits to Google to make...
    Rule Medium Severity
  • SRG-APP-000206

    Group
  • Collection of WebRTC event logs must be disabled.

    If the policy is set to “true”, Google Chrome is allowed to collect WebRTC event logs from Google services (e.g., Google Meet), and upload those logs to Google. If the policy is set to “false”, or ...
    Rule Medium Severity
  • SRG-APP-000266

    Group
  • Chrome development tools must be disabled.

    While the risk associated with browser development tools is more related to the proper design of a web application, a risk vector remains within the browser. The developer tools allow end users and...
    Rule Low Severity
  • SRG-APP-000206

    Group
  • Guest Mode must be disabled.

    If this policy is set to true or not configured, Google Chrome will enable guest logins. Guest logins are Google Chrome profiles where all windows are in incognito mode. If this policy is set to f...
    Rule Medium Severity
  • SRG-APP-000206

    Group
  • AutoFill for credit cards must be disabled.

    Enabling Google Chrome's AutoFill feature allows users to auto complete credit card information in web forms using previously stored information. If this setting is disabled, Autofill will never su...
    Rule Medium Severity
  • SRG-APP-000206

    Group
  • AutoFill for addresses must be disabled.

    Enabling Google Chrome's AutoFill feature allows users to auto complete address information in web forms using previously stored information. If this setting is disabled, Autofill will never sugges...
    Rule Medium Severity
  • SRG-APP-000206

    Group
  • Import AutoFill form data must be disabled.

    This policy forces the autofill form data to be imported from the previous default browser if enabled. If enabled, this policy also affects the import dialog. If disabled, the autofill form data is...
    Rule Medium Severity
  • SRG-APP-000141

    Group
  • Web Bluetooth API must be disabled.

    Setting the policy to 3 lets websites ask for access to nearby Bluetooth devices. Setting the policy to 2 denies access to nearby Bluetooth devices. Leaving the policy unset lets sites ask for acc...
    Rule Medium Severity
  • SRG-APP-000383

    Group
  • Use of the QUIC protocol must be disabled.

    QUIC is used by more than half of all connections from the Chrome web browser to Google's servers, and this activity is undesirable in the DoD. Setting the policy to Enabled or leaving it unset al...
    Rule Medium Severity
  • SRG-APP-000080

    Group
  • Session only based cookies must be enabled.

    Cookies must only be allowed per session and only for approved URLs as permanently stored cookies can be used for malicious intent. Approved URLs may be allowlisted via the CookiesAllowedForUrls ...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules