Skip to content

The 26 Chrome Enterprise security checks Black Cat runs

Black Cat SSPM evaluates 26 security policies against your Chrome Enterprise configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect Chrome Enterprise — what access Black Cat needs, and why.

Identity, MFA & sign-in (5)

Access control & privilege (4)

Configuration hardening (10)

Lifecycle & offboarding (4)

Other checks (3)

severity: high Device Without Disk Encryption fix difficulty: medium #

Enable disk encryption on all Chrome Enterprise managed devices

  1. Navigate to Google Admin Console > Devices > Chrome > Settings > Device Settings
  2. Under Security, locate the Disk Encryption policy
  3. Set the policy to Encrypt all local user data for all applicable organizational units
  4. Save changes and allow policy to propagate to managed devices
  5. Verify encryption status in Admin Console > Devices > Chrome > Devices reports

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7

severity: medium Password Manager Disabled fix difficulty: easy #

Enable Chrome built-in Password Manager or ensure an approved enterprise password manager is deployed

  1. Navigate to Google Admin Console > Devices > Chrome > Settings > User & Browser Settings
  2. Search for Password Manager in the policy search bar
  3. Set the policy to Enable saving passwords in the Password Manager
  4. Alternatively, deploy an approved enterprise password manager extension via Apps & Extensions
  5. Save changes and communicate the password management policy to users

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.5 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.e.3 DORA (SaaS Security) DORA-9.8

severity: low Stale Extension Request fix difficulty: easy #

Review and action Chrome extension requests that have been pending for more than 7 days

  1. Navigate to Google Admin Console > Devices > Chrome > Apps & Extensions > Requests
  2. Locate the pending extension request identified in the finding
  3. Evaluate the extension against your acceptable-use and security policies
  4. Approve the request and add the extension to the managed catalog if it is acceptable
  5. Deny the request and notify the requester with a reason if it does not meet policy
  6. Consider setting a recurring review cadence for open extension requests to prevent future backlogs

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.3 NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial