| 2.1.1 (L2) Ensure 'Enable Translate' is set to 'Disabled' | SYSTEM AND INFORMATION INTEGRITY |
| 2.2.1 (L2) Ensure 'Allow or deny screen capture' is set to 'Disabled' | CONFIGURATION MANAGEMENT |
| 2.3.4 (L2) Ensure 'Default cookies setting' is set to 'Enabled: Keep cookies for the duration of the session' | CONFIGURATION MANAGEMENT |
| 2.3.5 (L2) Ensure 'Control use of the File System API for reading' is set to 'Enabled: Do not allow any site to request read access to files and directories via the File System API' | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.3.8 (L2) Ensure 'Control use of JavaScript JIT' is set to 'Enabled: Do not allow any site to run JavaScript JIT' | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.3.9 (L2) Ensure 'Default notification setting' is set to 'Enabled: Do not allow any site to show desktop notifications' | CONFIGURATION MANAGEMENT |
| 2.3.10 (L2) Ensure 'Default Sensors Setting' is set to 'Enabled: Do not allow any site to access sensors' | CONFIGURATION MANAGEMENT |
| 2.3.11 (L2) Ensure 'Control use of the Serial API' is set to 'Enabled: Do not allow any site to request access to serial ports via the Serial API' | CONFIGURATION MANAGEMENT |
| 2.3.12 (L2) Ensure 'Control use of the Web Bluetooth API' is set to 'Enabled: Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API' | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.3.13 (L2) Ensure 'Control use of the WebHID API' is set to 'Enabled: Do not allow any site to request access to HID devices via the WebHID API' | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.3.14 (L2) Ensure 'Control use of the WebUSB API' is set to 'Enabled: Do not allow any site to request access to USB devices via the WebUSB API' | CONFIGURATION MANAGEMENT |
| 2.3.15 (L2) Ensure 'Default Window Management permissions setting' Is 'Enabled' to 'Deny Permission' | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.3.16 (L2) Ensure 'Allow read access via the File System API on these sites' is set to 'Disabled' | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.3.18 (L2) Ensure 'Block Window Management permission on these sites' Is Configured | CONFIGURATION MANAGEMENT |
| 2.3.19 (L2) Ensure 'Allow Window Management permission on these sites' Is Configured | ACCESS CONTROL |
| 2.3.20 (L2) Ensure 'Allow write access via the File System API on these sites' is set to 'Disabled' | CONFIGURATION MANAGEMENT |
| 2.3.21 (L2) Ensure 'Control use of the File System API for writing' is set to 'Enabled: Do not allow any site to request write access to files and directories via the File System API' | CONFIGURATION MANAGEMENT |
| 2.4.4 (L2) Ensure 'Extension management settings' is set to 'Enabled: { '*': {'installation_mode': 'blocked' }}' | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.7.3 (L2) Ensure 'Supported authentication schemes' is set to 'Enabled: ntlm, negotiate' | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.8.1 L2 - Ensure 'Allow Local Network Access (LNA) requests in subframes without explicit delegation' is set to 'Disabled' | CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY |
| 2.10.1 (L2) Ensure 'Configure native messaging blocklist' is set to 'Enabled: *' | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.18 (L2) Ensure 'Enable additional protections for users enrolled in the Advanced Protection program' Is Set to 'Enabled' | ACCESS CONTROL |
| 2.20 (L2) Ensure 'Allow invocation of file selection dialogs' is set to 'Disabled' | CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY |
| 2.23 (L2) Ensure 'Allow or deny audio capture' is set to 'Disabled' | SYSTEM AND INFORMATION INTEGRITY |
| 2.25 (L2) Ensure 'Enable AutoFill for addresses' is set to 'Disabled' | SYSTEM AND INFORMATION INTEGRITY |
| 2.29 (L2) Ensure 'Enable guest mode in browser' is set to 'Disabled' | SYSTEM AND INFORMATION INTEGRITY |
| 2.31 (L2) Ensure 'Browser sign in settings' is set to 'Enabled: Disabled browser sign-in' | SYSTEM AND INFORMATION INTEGRITY |
| 2.40 (L2) Ensure 'Controls the mode of DNS-over-HTTPS' is set to 'Enabled: DNS-over-HTTPS without insecure fallback' | ACCESS CONTROL, AWARENESS AND TRAINING, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.47 (L2) Ensure 'Show an 'Always open' checkbox in external protocol dialog' is set to 'Disabled' | CONFIGURATION MANAGEMENT |
| 2.50 (L2) Ensure 'Force Google SafeSearch' is set to 'Enabled' | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.71 (L2) Ensure 'Require online OCSP/CRL checks for local trust anchors' is set to 'Enabled' | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.72 (L2) Ensure 'Allow proceeding from the SSL warning page' is set to 'Disabled' | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.74 (L2) Ensure 'Control SafeSites adult content filtering' is set to 'Enabled: Filter top level sites (but not embedded iframes) for adult content' | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.76 (L2) Ensure 'Enable search suggestions' is set to 'Disabled' | SYSTEM AND INFORMATION INTEGRITY |
| 2.86 (L2) Ensure 'Allow or deny video capture' is set to 'Disabled' | SYSTEM AND INFORMATION INTEGRITY |
| 2.89 (L2) Ensure 'Dynamic Code Settings' Is Enabled | SYSTEM AND INFORMATION INTEGRITY |
| 2.90 (L2) Ensure 'Enable Live Translate' Is Disabled | CONFIGURATION MANAGEMENT |
| 2.92 (L2) Ensure 'Allow pages to use the built-in AI APIs' Is Disabled | CONFIGURATION MANAGEMENT |
| CIS_Google_Chrome_Group_Policy_v1.1.0_L2.audit from CIS Google Chrome Group Policy v1.1.0 | |