Google Chrome STIG for Windows (V2 R11)
19 items · Security · Hard difficulty · 2 hours
Practical steps to apply the Chrome STIG on Windows for managed environments.
-
Download latest STIG resources from DISA
Get SCAP, standalone XCCDF, GPOs, Intune policies, and SCC content.
-
Review the STIG benchmark and change history
Confirm version V2 R11 requirements and recent updates.
-
Map STIG controls to your organizational policy
Identify which controls are applicable or require formal exceptions.
-
Import DISA GPO files into a test OU
Load provided GPOs into Group Policy Management for review.
-
Test the imported GPOs in a non-production OU
Validate behavior on representative Windows clients before broad rollout.
-
Deploy validated GPOs to production OUs
Apply to production after successful testing and change control approvals.
-
Import and apply Intune policies for managed endpoints
Use provided Intune policy packs for cloud-managed devices.
-
Configure Chrome automatic update management
Ensure updates are enforced via policy or system management tooling.
- Harden privacy and data storage settings
-
Disable saving passwords in Chrome
Enforce via policy to prevent credential storage in browser.
-
Disable autofill for forms and payment methods
Prevent automatic filling of personal and financial data.
-
Block third-party cookies and site data as required
Reduce cross-site tracking and data leakage.
-
Restrict or whitelist browser extensions via policy
Disable user-installed extensions and allow only approved ones.
-
Enforce Safe Browsing and block malicious downloads
Enable enhanced protection and download restrictions via policy.
-
Enable site isolation and sandboxing features
Use process isolation policies to harden against web-based exploits.
-
Block external protocol handlers and unsafe protocols
Prevent automatic launching of external apps from web content.
-
Enable pop-up and redirect blocking
Reduce unwanted content and drive-by downloads.
-
Verify applied settings with SCAP/SCC or auditing tools
Run compliance scans and review audit results after deployment.
-
Document deviations, exceptions, and change approvals
Record justifications and authority for any non-applicable controls.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.