The 26 Chrome Enterprise security checks Black Cat runs
Black Cat SSPM evaluates 26 security policies against your Chrome Enterprise configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect Chrome Enterprise — what access Black Cat needs, and why.
Identity, MFA & sign-in
5 checks · highest severity: high
Access control & privilege
4 checks · highest severity: medium
Configuration hardening
10 checks · highest severity: high
Lifecycle & offboarding
4 checks · highest severity: medium
Identity, MFA & sign-in (5)
- Widely Deployed Extension With Risky Permissions severity: high
- Browser Running on Unsupported OS severity: high
- Admin-Forced Extension With Risky Permissions severity: high
- Shadow IT Extension Widely Deployed severity: medium
- Device Running Outdated OS (Telemetry) severity: high
Access control & privilege (4)
- Download Restrictions Not Set severity: medium
- Incognito Mode Allowed severity: low
- Browser Without Organizational Unit Assignment severity: medium
- Extension With Excessive Permissions severity: medium
Configuration hardening (10)
- Sideloaded Extension Detected severity: medium
- Outdated Browser Version severity: medium
- Extension With Risky Permissions severity: high
- Safe Browsing Disabled severity: high
- Non-Stable Browser Channel In Use severity: medium
- Browser Running Windows 10 severity: medium
- Widespread Outdated Browser Version severity: high
- Telemetry Device Missing OS Version severity: low
- Browser Not Reporting Version severity: low
- Extension Not Hosted on Chrome Web Store severity: medium
Lifecycle & offboarding (4)
- Stale Browser (90+ Days Inactive) severity: medium
- Unmanaged Browser (30+ Days Inactive) severity: low
- Orphaned Extension With Zero Installs severity: low
- Browser Flagged as Needing Attention severity: medium
Other checks (3)
severity: high Device Without Disk Encryption fix difficulty: medium #
Enable disk encryption on all Chrome Enterprise managed devices
- Navigate to Google Admin Console > Devices > Chrome > Settings > Device Settings
- Under Security, locate the Disk Encryption policy
- Set the policy to Encrypt all local user data for all applicable organizational units
- Save changes and allow policy to propagate to managed devices
- Verify encryption status in Admin Console > Devices > Chrome > Devices reports
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7
severity: medium Password Manager Disabled fix difficulty: easy #
Enable Chrome built-in Password Manager or ensure an approved enterprise password manager is deployed
- Navigate to Google Admin Console > Devices > Chrome > Settings > User & Browser Settings
- Search for Password Manager in the policy search bar
- Set the policy to Enable saving passwords in the Password Manager
- Alternatively, deploy an approved enterprise password manager extension via Apps & Extensions
- Save changes and communicate the password management policy to users
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.5 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.e.3 DORA (SaaS Security) DORA-9.8
severity: low Stale Extension Request fix difficulty: easy #
Review and action Chrome extension requests that have been pending for more than 7 days
- Navigate to Google Admin Console > Devices > Chrome > Apps & Extensions > Requests
- Locate the pending extension request identified in the finding
- Evaluate the extension against your acceptable-use and security policies
- Approve the request and add the extension to the managed catalog if it is acceptable
- Deny the request and notify the requester with a reason if it does not meet policy
- Consider setting a recurring review cadence for open extension requests to prevent future backlogs
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.3 NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4