DEVICE-008: Chrome Extension Whitelist/Blocklist

Platform
Google Workspace
Category
Device & Endpoint Management
Severity
High
Zero Trust pillar
Devices (weight 3)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Chrome extensions should be managed through an allowlist or blocklist to prevent malicious extensions from accessing organizational data

Recommended value

Extension installation restricted to admin-approved extensions via allowlist

Remediation

Admin Console > Devices > Chrome > Apps & extensions > Configure extension allowlist and blocklist

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for DEVICE-008
ScenarioExpected verdict
cleanPASS
known-badWARN
throttledNot Assessed

Framework mappings

NIST SP 800-53
CM-7, CM-11
CIS Benchmark
6.8
MITRE ATT&CK
T1176