Back
A practical hardening checklist for securing Google Chrome on Windows using STIG guidance. Ideal for system admins and security teams deploying enterprise policies via GPO or Intune.
Progress
0 / 19
- Update Google Chrome to the latest stable version — Ensure the browser is on the most recent security release.
- Enable automatic updates via enterprise policy — Configure auto-update to maintain timely security fixes.
- Apply GPO or Intune policies to enforce Chrome settings — Deploy the downloaded policy pack to target machines.
- Enable Safe Browsing (warn about phishing and malware) — Turn on Google's Safe Browsing protections via policy.
- Disable Chrome sync with Google accounts — Prevent data leaving the enterprise account scope.
- Disable saving passwords in the browser — Force use of enterprise-approved password managers.
- Disable Autofill for addresses and payment methods — Reduce leakage of sensitive form data.
- Enable Site Isolation — Improve process separation between sites for security.
- Enforce HTTPS-Only mode or block insecure content — Prevent loading of HTTP resources on secure pages.
- Block third-party cookies — Limit cross-site tracking and data sharing.
- Disable legacy plugins (Flash, NPAPI) and block plugin installs — Remove known insecure plugin attack surface.
- Disable insecure or deprecated protocols (TLS 1.0/1.1) — Enforce modern TLS versions via policy or enterprise controls.
- Disable pop-ups and redirects — Block unwanted content and malicious redirect chains.
- Restrict extension installation (block by default) — Prevent unauthorized extensions from installing.
- Whitelist allowed extensions — Permit only vetted extensions via an allowlist.
- Block all other extensions not on the allowlist — Enforce blocklist for any non-approved extensions.
- Configure homepage/new-tab and prevent unwanted changes — Set a controlled start page or a blank page for endpoints.
- Run a SCAP/XCCDF compliance scan and remediate findings — Use automated scan results to verify STIG compliance.
- Document exceptions and obtain authorization for deviations — Record any accepted waivers with justification and approvals.
Your Stats
🏆
0
Completed
📅
—
Last Done
⏱️
—
Last Time
Completion Rate
Items checked per run
⚡
—
Fastest Run
🔥
0
Streak
🚫
—
Most Skipped Step
🔄
0
Resets
📝 My Notes