CIS Google Chrome Group Policy v1.1.0 L1

Audit Details

Name: CIS Google Chrome Group Policy v1.1.0 L1

Updated: 9/23/2026

Authority: CIS

Plugin: Windows

Revision: 1.0

Estimated Item Count: 103

File Details

Filename: CIS_Google_Chrome_Group_Policy_v1.1.0_L1.audit

Size: 214 kB

MD5: 7218595b578fae98b4a90b62158db220
SHA256: ce8fa8b0f83e8d1c69cb5c757eedd4c6f289639d12ab73c719952c49ade07681

Audit Items

DescriptionCategories
2.3.1 (L1) Ensure 'Allow clipboard for these sites' Is Configured

CONFIGURATION MANAGEMENT

2.3.2 (L1) Ensure 'Block clipboard on these sites' Is Configured

SYSTEM AND INFORMATION INTEGRITY

2.3.3 (L1) Ensure 'Default clipboard setting' Is 'Enabled' to 'Deny Permissions'

SYSTEM AND INFORMATION INTEGRITY

2.3.6 (L1) Ensure 'Default geolocation setting' is set to 'Enabled: Do not allow any site to track the users' physical location'

AUDIT AND ACCOUNTABILITY

2.3.7 (L1) Ensure 'Control use of insecure content exceptions' is set to 'Enabled: Do not allow any site to load mixed content'

SYSTEM AND COMMUNICATIONS PROTECTION

2.3.17 (L1) Ensure 'Allow local file access to file:// URLs on these sites in the PDF Viewer' Is Disabled

ACCESS CONTROL

2.4.1 (L1) Ensure 'Blocks external extensions from being installed' is set to 'Enabled'

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

2.4.2 (L1) Ensure 'Configure allowed app/extension types' is set to 'Enabled: extension, hosted_app, platform_app, theme'

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

2.4.3 (L1) Ensure 'Configure extension installation blocklist' is set to 'Enabled: *'

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

2.4.5 (L1) Ensure 'Control availability of extensions unpublished on the Chrome Web Store' Is Set to 'Enabled: Disable unpublished extensions'

RISK ASSESSMENT

2.5.1 Ensure 'Settings for Chrome DevTools Generative AI Features' Is Set to 'Enabled: Allow Chrome DevTools Generative AI Features without improving AI models.'

ACCESS CONTROL, CONFIGURATION MANAGEMENT

2.5.2 Ensure 'Settings for Help Me Write' Is Set to 'Enabled: Allow help me write without improving AI models.'

ACCESS CONTROL, CONFIGURATION MANAGEMENT

2.5.3 Ensure 'Settings for AI-powered History Search' Is Set to 'Enabled: Allow AI history search without improving AI models.'

ACCESS CONTROL, CONFIGURATION MANAGEMENT

2.5.4 Ensure 'Tab compare settings' Is Set to 'Enabled: Allow Tab Compare without improving AI models.'

ACCESS CONTROL, CONFIGURATION MANAGEMENT

2.5.5 (L1) Ensure 'Configure GenAI local foundational model settings' is set to 'Disabled'

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

2.6.1 (L1) Ensure 'Enable Google Cast' is set to 'Disabled'

CONFIGURATION MANAGEMENT

2.6.2 (L1) Ensure 'Allow Google Cast to connect to Cast devices on all IP addresses' is set to 'Disabled'

CONFIGURATION MANAGEMENT

2.7.1 (L1) Ensure 'Cross-origin HTTP Authentication prompts' is set to 'Disabled'

CONFIGURATION MANAGEMENT

2.7.2 (L1) Ensure 'Allow Basic authentication for HTTP' is set to 'Disabled'

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.9.1 (L1) Ensure 'Allow automatic sign-in to Microsoft cloud identity providers' Is Enabled

SYSTEM AND INFORMATION INTEGRITY

2.11.1 (L1) Ensure 'Enable leak detection for entered credentials' Is Set to 'Enabled'

SYSTEM AND INFORMATION INTEGRITY

2.11.2 (L1) Ensure 'Enable saving passwords to the password manager' is Explicitly Configured

SYSTEM AND INFORMATION INTEGRITY

2.11.3 (L1) Ensure 'Enable saving passkeys to the password manager' is Explicitly Configured

SYSTEM AND INFORMATION INTEGRITY

2.11.4 (L1) Ensure 'Enable sharing user credentials with other users' is Disabled

SYSTEM AND INFORMATION INTEGRITY

2.12.1 (L1) Ensure 'Enable Google Cloud Print Proxy' is set to 'Disabled'

CONFIGURATION MANAGEMENT

2.13.1 (L1) Ensure 'Enable Related Website Sets' Is Disabled

AUDIT AND ACCOUNTABILITY

2.14.1 (L1) Ensure 'Enable or disable PIN-less authentication for remote access hosts' is set to 'Disabled'

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

2.14.2 (L1) Ensure 'Enable the use of relay servers by the remote access host' is set to 'Disabled'.

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

2.14.3 Ensure 'Allow remote access connections to this machine' is set to 'Disabled'

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

2.14.4 (L1) Ensure 'Allow remote users to interact with elevated windows in remote assistance sessions' is set to 'Disabled'

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

2.14.5 (L1) Ensure 'Configure the required domain names for remote access clients' is set to 'Enabled' with a domain defined

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

2.14.6 (L1) Ensure 'Enable firewall traversal from remote access host' is set to 'Disabled'

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

2.14.7 (L1) Ensure 'Enable curtaining of remote access hosts' is set to 'Disabled'

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

2.15.1 (L1) Ensure 'Configure the list of domains on which Safe Browsing will not trigger warnings' is set to 'Disabled'

SYSTEM AND COMMUNICATIONS PROTECTION

2.15.2 (L1) Ensure 'Safe Browsing Protection Level' is set to 'Enabled: Safe Browsing is active in the standard mode.' or higher

SYSTEM AND COMMUNICATIONS PROTECTION

2.15.3 (L1) Ensure 'Disable proceeding from the Safe Browsing warning page' is set to 'Enabled'

SYSTEM AND COMMUNICATIONS PROTECTION

2.16.1 (L1) Ensure 'Bind Google credentials to a device' Is Disabled

IDENTIFICATION AND AUTHENTICATION

2.17 (L1) Ensure 'Ads setting for sites with intrusive ads' is set to 'Enabled: Do not allow ads on sites with intrusive ads'

SYSTEM AND INFORMATION INTEGRITY

2.19 (L1) Ensure 'Enable deleting browser and download history' is set to 'Disabled'

SYSTEM AND INFORMATION INTEGRITY

2.21 (L1) Ensure 'Allow Web Authentication requests on sites with broken TLS certificates' Is Disabled

ACCESS CONTROL, AWARENESS AND TRAINING, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.22 (L1) Ensure 'Enable alternate error pages' is set to 'Disabled'

SYSTEM AND INFORMATION INTEGRITY

2.24 (L1) Ensure 'Allow the audio sandbox to run' is set to 'Enabled'

AUDIT AND ACCOUNTABILITY

2.26 (L1) Ensure 'Enable AutoFill for credit cards' is set to 'Disabled'

SYSTEM AND INFORMATION INTEGRITY

2.27 (L1) Ensure 'Continue running background apps when Google Chrome is closed' is set to 'Disabled'

CONFIGURATION MANAGEMENT

2.28 (L1) Ensure 'Block third party cookies' is set to 'Enabled'

SYSTEM AND INFORMATION INTEGRITY

2.30 (L1) Ensure 'Allow queries to a Google time service' is set to 'Enabled'

AUDIT AND ACCOUNTABILITY

2.32 (L1) Ensure 'Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes' is set to 'Disabled'

CONFIGURATION MANAGEMENT

2.33 (L1) Ensure 'Disable Certificate Transparency enforcement for a list of URLs' is set to 'Disabled'

CONFIGURATION MANAGEMENT

2.34 (L1) Ensure 'Determine the availability of variations' is set to 'Enabled: Enable all variations'

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

2.35 (L1) Ensure 'Clear Browsing Data on Exit' is set to 'Disabled'

AUDIT AND ACCOUNTABILITY