-
Notifications
You must be signed in to change notification settings - Fork 2
Check Reference
serbanb11 edited this page Sep 29, 2026
·
1 revision
The GWS Security Auditor implements 227 security checks across four frameworks:
| Framework | Full Name | Checks |
|---|---|---|
| CIS | CIS Google Workspace Foundations Benchmark v1.3.0 | 84 |
| CISA | CISA SCuBA Baselines for Google Workspace | 97 |
| Google Security Checklist for Medium & Large Businesses | 21 | |
| OTHER | Additional best-practice checks | 25 |
| Total | 227 |
- L1 (Level 1) -- 151 checks. Baseline security settings that should be applied to all organizations. Minimal performance impact, broad applicability.
- L2 (Level 2) -- 76 checks. Advanced security settings for organizations with higher security requirements. May restrict functionality or require additional configuration.
| Severity | Checks |
|---|---|
| CRITICAL | 24 |
| HIGH | 81 |
| MEDIUM | 80 |
| LOW | 42 |
13 checks are informational (inventory/review) and do not affect the posture score; they are marked unscored below.
| Status | Meaning |
|---|---|
| PASS | Configuration meets the benchmark requirement |
| FAIL | Configuration does not meet the requirement |
| WARN | Partial compliance or potential issue detected |
| PARTIAL | Remaining violations sit only in OUs designated for external sharing |
| ERROR | Check could not complete: an API error, or the data it needs was not collected |
| MANUAL | Requires manual verification. Returned when a setting is not exposed by any Google API, or when its state cannot be determined from the collected data -- the auditor does not guess PASS or FAIL |
| NOT_APPLICABLE | Check does not apply to this environment (for example, the licence tier lacks the feature) |
Some settings are not exposed by the Cloud Identity Policy API. Where Google records changes to them in the admin audit log, the auditor infers the current value from the most recent change event; with no event inside the log window the result is MANUAL.
| ID | Title | Level | Source | Severity | Notes |
|---|---|---|---|---|---|
| CIS-4.2.1.1 | Ensure third-party app access is restricted | L1 | CIS | CRITICAL | |
| CIS-4.2.1.2 | Ensure third-party apps are reviewed | L2 | CIS | HIGH | |
| CIS-4.2.1.3 | Ensure internal app API access is controlled | L2 | CIS | HIGH | |
| CIS-4.2.1.4 | Ensure domain-wide delegation is reviewed | L2 | CIS | CRITICAL | |
| CIS-4.2.2.1 | Ensure geo-blocking is configured | L2 | CIS | HIGH | Enterprise Standard+ |
| CIS-4.2.3.1 | Ensure DLP policies are configured for Drive | L1 | CIS | HIGH | Enterprise Standard+ |
| CIS-4.2.4.1 | Ensure Device Bound Session Credentials (DBSC) are enabled | L2 | CIS | CRITICAL | |
| CIS-4.2.5.1 | Ensure cloud session control is configured | L2 | CIS | HIGH | Enterprise Plus |
| ID | Title | Level | Source | Severity | Notes |
|---|---|---|---|---|---|
| CIS-6.1 | Ensure alert for user password change is configured | L1 | CIS | HIGH | |
| CIS-6.2 | Ensure alert for government-backed attacks is configured | L1 | CIS | HIGH | |
| CIS-6.3 | Ensure alert for suspicious activity is configured | L1 | CIS | MEDIUM | |
| CIS-6.4 | Ensure alert for admin privilege grant is configured | L1 | CIS | HIGH | |
| CIS-6.5 | Ensure alert for suspicious programmatic login is configured | L1 | CIS | MEDIUM | |
| CIS-6.6 | Ensure alert for suspicious login is configured | L1 | CIS | MEDIUM | |
| CIS-6.7 | Ensure alert for leaked password is configured | L1 | CIS | HIGH | |
| CIS-6.8 | Ensure alert for employee spoofing is configured | L1 | CIS | MEDIUM | |
| GWS.COMMONCONTROLS.13.1 | Ensure system-defined alerting rules are enabled | L1 | CISA | MEDIUM |
| ID | Title | Level | Source | Severity | Notes |
|---|---|---|---|---|---|
| GWS.ASSUREDCONTROLS.1.1 | Ensure access approvals are enabled | L2 | CISA | LOW | Assured Controls add-on |
| GWS.ASSUREDCONTROLS.1.2 | Ensure support access is restricted to US personnel | L2 | CISA | LOW | Assured Controls add-on |
| GWS.ASSUREDCONTROLS.2.1 | Ensure multi-region data processing is disabled | L2 | CISA | LOW | Assured Controls add-on |
| ID | Title | Level | Source | Severity | Notes |
|---|---|---|---|---|---|
| ADD-23 | Ensure DLP rules are configured for Calendar | L2 | MEDIUM | Enterprise Standard+ | |
| CIS-3.1.1.1.1 | Ensure external sharing for primary calendars is limited | L1 | CIS | MEDIUM | |
| CIS-3.1.1.1.2 | Ensure internal sharing for primary calendars is configured | L1 | CIS | MEDIUM | |
| CIS-3.1.1.1.3 | Ensure external invitations show warning | L1 | CIS | MEDIUM | |
| CIS-3.1.1.2.1 | Ensure external sharing for secondary calendars is limited | L1 | CIS | MEDIUM | |
| CIS-3.1.1.2.2 | Ensure internal sharing for secondary calendars is configured | L2 | CIS | MEDIUM | |
| CIS-3.1.1.3.1 | Ensure Calendar web offline access is disabled | L2 | CIS | MEDIUM | |
| GWS.CALENDAR.3.1 | Ensure Calendar Interop is disabled | L1 | CISA | MEDIUM | |
| GWS.CALENDAR.3.2 | Ensure Calendar Interop uses Microsoft 365 Graph API | L2 | CISA | MEDIUM | |
| GWS.CALENDAR.4.1 | Ensure paid appointment scheduling is disabled | L1 | CISA | LOW | Business Standard+ |
| ID | Title | Level | Source | Severity | Notes |
|---|---|---|---|---|---|
| GWS.CLASSROOM.1.1 | Ensure class membership is restricted to domain | L1 | CISA | LOW | |
| GWS.CLASSROOM.1.2 | Ensure classes users can join are restricted to domain | L1 | CISA | LOW | |
| GWS.CLASSROOM.2.1 | Ensure Classroom API access is disabled | L1 | CISA | LOW | |
| GWS.CLASSROOM.3.1 | Ensure roster import with Clever is disabled | L1 | CISA | LOW | |
| GWS.CLASSROOM.4.1 | Ensure only teachers can unenroll students | L1 | CISA | LOW | |
| GWS.CLASSROOM.5.1 | Ensure class creation is restricted to verified teachers | L1 | CISA | LOW |
| ID | Title | Level | Source | Severity | Notes |
|---|---|---|---|---|---|
| ADD-30 | Ensure mobile devices are syncing recently | L1 | OTHER | LOW | unscored |
| ADD-31 | Ensure ChromeOS devices are active recently | L1 | OTHER | LOW | unscored |
| ADD-38 | Ensure endpoint verification devices are syncing recently | L1 | OTHER | LOW | unscored |
| ADD-39 | Ensure pending devices are approved promptly | L2 | OTHER | LOW | unscored |
| ID | Title | Level | Source | Severity | Notes |
|---|---|---|---|---|---|
| ADD-42 | Ensure super admin accounts are actively used or removed | L1 | OTHER | HIGH | |
| ADD-43 | Ensure suspended users do not hold admin roles | L1 | OTHER | MEDIUM | |
| ADD-44 | Review active user accounts with no recent sign-in | L2 | OTHER | LOW | unscored |
| ADD-52 | Review active users without a Google Workspace licence | L2 | OTHER | LOW | unscored |
| CIS-1.1.1 | Ensure more than one Super Admin account exists | L1 | CIS | CRITICAL | |
| CIS-1.1.2 | Ensure fewer than 4 Super Admin accounts exist | L1 | CIS | HIGH | |
| CIS-1.1.3 | Ensure Super Admin accounts are only used for admin tasks | L2 | CIS | LOW | |
| CIS-1.2.1.1 | Ensure directory data is restricted from external access | L1 | CIS | HIGH | |
| GWS.COMMONCONTROLS.6.1 | Ensure admin accounts are cloud-only | L1 | CISA | HIGH |
| ID | Title | Level | Source | Severity | Notes |
|---|---|---|---|---|---|
| ADD-35 | Ensure Shared Drives have secure default restrictions | L1 | OTHER | HIGH | unscored |
| ID | Title | Level | Source | Severity | Notes |
|---|---|---|---|---|---|
| ADD-24 | Ensure AI-powered data classification is enabled for Drive | L2 | MEDIUM | ||
| ADD-25 | Ensure Drive trust rules are configured | L2 | MEDIUM | ||
| CIS-3.1.2.1.1.1 | Ensure users are warned when sharing outside domain | L1 | CIS | HIGH | |
| CIS-3.1.2.1.1.2 | Ensure users cannot publish files publicly | L1 | CIS | CRITICAL | |
| CIS-3.1.2.1.1.3 | Ensure sharing is controlled by domain allowlists | L2 | CIS | HIGH | |
| CIS-3.1.2.1.1.4 | Ensure users are warned when sharing with allowlisted domains | L2 | CIS | MEDIUM | |
| CIS-3.1.2.1.1.5 | Ensure Access Checker limits file access | L1 | CIS | HIGH | |
| CIS-3.1.2.1.1.6 | Ensure only internal users can distribute content externally | L2 | CIS | HIGH | |
| CIS-3.1.2.1.2.1 | Ensure Shared Drive creation is controlled | L1 | CIS | MEDIUM | |
| CIS-3.1.2.1.2.2 | Ensure manager cannot override shared drive settings | L2 | CIS | MEDIUM | Business Standard+ |
| CIS-3.1.2.1.2.3 | Ensure shared drive access is restricted to members | L1 | CIS | MEDIUM | Business Standard+ |
| CIS-3.1.2.1.2.4 | Ensure viewers cannot download, print, or copy files | L2 | CIS | MEDIUM | Business Standard+ |
| CIS-3.1.2.2.1 | Ensure offline access to Drive is disabled | L2 | CIS | MEDIUM | Enterprise Plus |
| CIS-3.1.2.2.2 | Ensure Desktop access to Drive is disabled | L2 | CIS | MEDIUM | |
| CIS-3.1.2.2.3 | Ensure Drive SDK is disabled | L2 | CIS | MEDIUM | |
| GWS.DRIVEDOCS.1.2 | Ensure receiving files from non-allowlisted domains is disabled | L1 | CISA | HIGH | |
| GWS.DRIVEDOCS.1.3 | Ensure sharing warnings for non-allowlisted domains are enabled | L1 | CISA | MEDIUM | |
| GWS.DRIVEDOCS.1.4 | Ensure sharing with non-Google accounts is disabled | L1 | CISA | CRITICAL | |
| GWS.DRIVEDOCS.1.5 | Ensure 'anyone with the link' sharing is disabled | L1 | CISA | CRITICAL | |
| GWS.DRIVEDOCS.1.6 | Ensure access checking is set to recipients only | L1 | CISA | MEDIUM | |
| GWS.DRIVEDOCS.1.7 | Ensure users cannot upload to external shared drives | L2 | CISA | MEDIUM | |
| GWS.DRIVEDOCS.1.8 | Ensure default access for new items is 'private to owner' | L1 | CISA | HIGH | |
| GWS.DRIVEDOCS.1.9 | Ensure out-of-domain file-level warnings are enabled | L1 | CISA | MEDIUM | |
| GWS.DRIVEDOCS.1.10 | Ensure forms cannot accept external responses when external sharing is off | L2 | CISA | LOW | |
| GWS.DRIVEDOCS.1.11 | Ensure users cannot respond to external forms when receiving files is off | L2 | CISA | LOW | |
| GWS.DRIVEDOCS.2.1 | Ensure shared drive manager override is disabled | L2 | CISA | MEDIUM | |
| GWS.DRIVEDOCS.2.2 | Ensure non-members can be added to shared drive files | L1 | CISA | MEDIUM | |
| GWS.DRIVEDOCS.3.1 | Ensure security updates for files are applied | L1 | CISA | MEDIUM | |
| GWS.DRIVEDOCS.5.1 | Ensure Google Drive Add-Ons are disabled | L1 | CISA | MEDIUM | |
| GWS.DRIVEDOCS.6.1 | Ensure Drive for Desktop is restricted to authorized devices | L1 | CISA | MEDIUM |
| ID | Title | Level | Source | Severity | Notes |
|---|---|---|---|---|---|
| ADD-13 | Ensure Gemini features in Workspace apps are controlled | L1 | LOW | ||
| ADD-14 | Ensure Gemini in Chrome is disabled | L2 | LOW | ||
| ADD-15 | Ensure Google Workspace Studio access is controlled | L2 | LOW | ||
| GWS.GEMINI.1.1 | Ensure Gemini app access is restricted to licensed users | L1 | CISA | LOW | |
| GWS.GEMINI.2.1 | Ensure alpha Gemini features are disabled | L1 | CISA | LOW |
| ID | Title | Level | Source | Severity | Notes |
|---|---|---|---|---|---|
| ADD-02 | Ensure Security Sandbox is enabled for Gmail | L1 | OTHER | HIGH | Business Standard+ |
| ADD-05 | Ensure MX records point to Google | L1 | HIGH | ||
| ADD-06 | Ensure inbound gateway SPF configuration is correct | L2 | MEDIUM | ||
| ADD-07 | Ensure TLS is enforced for partner domains | L2 | HIGH | ||
| ADD-12 | Ensure DLP rules are configured for Gmail | L1 | HIGH | Enterprise Standard+ | |
| ADD-22 | Ensure data classification labels are enabled for Gmail | L1 | MEDIUM | Business Standard+ | |
| ADD-26 | Ensure CSE is enabled for Gmail | L2 | MEDIUM | ||
| ADD-50 | Ensure MTA-STS is published for all mail domains | L2 | OTHER | MEDIUM | |
| ADD-51 | Ensure mailboxes do not forward to external addresses | L1 | OTHER | HIGH | |
| CIS-3.1.3.1.1 | Ensure mail delegation is disabled | L1 | CIS | CRITICAL | |
| CIS-3.1.3.1.2 | Ensure offline Gmail is disabled | L2 | CIS | MEDIUM | Enterprise Plus |
| CIS-3.1.3.2.1 | Ensure DKIM is enabled for all domains | L1 | CIS | CRITICAL | |
| CIS-3.1.3.2.2 | Ensure SPF records are configured for all domains | L1 | CIS | CRITICAL | |
| CIS-3.1.3.2.3 | Ensure DMARC records are configured for all domains | L1 | CIS | CRITICAL | |
| CIS-3.1.3.3.1 | Ensure quarantine admin notifications are enabled | L2 | CIS | MEDIUM | Enterprise Plus |
| CIS-3.1.3.4.1.1 | Ensure encrypted attachment protection is enabled | L1 | CIS | HIGH | |
| CIS-3.1.3.4.1.2 | Ensure script attachment protection is enabled | L1 | CIS | HIGH | |
| CIS-3.1.3.4.1.3 | Ensure anomalous attachment protection is enabled | L1 | CIS | HIGH | |
| CIS-3.1.3.4.2.1 | Ensure shortened URL identification is enabled | L1 | CIS | HIGH | |
| CIS-3.1.3.4.2.2 | Ensure linked image scanning is enabled | L1 | CIS | HIGH | |
| CIS-3.1.3.4.2.3 | Ensure warning for untrusted links is enabled | L1 | CIS | HIGH | |
| CIS-3.1.3.4.3.1 | Ensure domain spoofing protection is enabled | L1 | CIS | HIGH | |
| CIS-3.1.3.4.3.2 | Ensure employee name spoofing protection is enabled | L1 | CIS | HIGH | |
| CIS-3.1.3.4.3.3 | Ensure inbound domain spoofing protection is enabled | L1 | CIS | HIGH | |
| CIS-3.1.3.4.3.4 | Ensure unauthenticated email protection is enabled | L1 | CIS | HIGH | |
| CIS-3.1.3.4.3.5 | Ensure Groups inbound spoofing protection is enabled | L1 | CIS | HIGH | |
| CIS-3.1.3.5.1 | Ensure POP and IMAP access is disabled | L1 | CIS | HIGH | |
| CIS-3.1.3.5.2 | Ensure automatic email forwarding is disabled | L1 | CIS | CRITICAL | |
| CIS-3.1.3.5.3 | Ensure per-user outbound gateways are disabled | L1 | CIS | MEDIUM | |
| CIS-3.1.3.5.4 | Ensure external recipient warnings are enabled | L1 | CIS | MEDIUM | Enterprise Plus |
| CIS-3.1.3.6.1 | Ensure enhanced pre-delivery message scanning is enabled | L1 | CIS | HIGH | |
| CIS-3.1.3.6.2 | Ensure spam filters are not bypassed for internal senders | L1 | CIS | HIGH | Enterprise Plus |
| CIS-3.1.3.7.1 | Ensure comprehensive mail storage is enabled | L2 | CIS | MEDIUM | |
| CIS-3.1.3.7.2 | Ensure secure TLS connection is enforced | L1 | CIS | HIGH | Enterprise Plus |
| GWS.GMAIL.4.1 | Ensure DMARC policy is published for all domains | L1 | CISA | HIGH | |
| GWS.GMAIL.4.2 | Ensure DMARC policy is set to reject | L1 | CISA | CRITICAL | |
| GWS.GMAIL.4.3 | Ensure DMARC alignment mode is strict | L1 | CISA | HIGH | |
| GWS.GMAIL.4.4 | Ensure DMARC reporting is configured | L1 | CISA | MEDIUM | |
| GWS.GMAIL.5.4 | Ensure future recommended attachment protections are applied automatically | L1 | CISA | LOW | |
| GWS.GMAIL.5.5 | Ensure flagged emails are moved out of inbox | L1 | CISA | MEDIUM | |
| GWS.GMAIL.6.4 | Ensure future recommended link and image protections are applied automatically | L1 | CISA | LOW | |
| GWS.GMAIL.7.6 | Ensure spoofed and unauthenticated email is not kept in the inbox | L1 | CISA | HIGH | |
| GWS.GMAIL.7.7 | Ensure future recommended spoofing protections are applied automatically | L1 | CISA | LOW | |
| GWS.GMAIL.8.1 | Ensure user email uploads are disabled | L1 | CISA | MEDIUM | |
| GWS.GMAIL.10.1 | Ensure Google Workspace Sync is disabled | L1 | CISA | MEDIUM | |
| GWS.GMAIL.14.1 | Ensure email allowlist is not used | L1 | CISA | MEDIUM | |
| GWS.GMAIL.18.1 | Ensure no domains bypass spam filters | L1 | CISA | HIGH | |
| GWS.GMAIL.18.2 | Ensure no domains bypass spam filters and hide warnings | L1 | CISA | HIGH | |
| GWS.GMAIL.18.3 | Ensure global spam filter bypass is disabled | L1 | CISA | HIGH |
| ID | Title | Level | Source | Severity | Notes |
|---|---|---|---|---|---|
| ADD-29 | Ensure Chat spaces have recent activity | L2 | OTHER | LOW | unscored |
| ADD-45 | Ensure Chat spaces with external members are restricted | L2 | OTHER | MEDIUM | |
| CIS-3.1.4.2.1 | Ensure external chat is restricted to allowed domains | L1 | CIS | HIGH | |
| CIS-3.1.4.4.1 | Ensure Chat app installation is disabled | L2 | CIS | MEDIUM | |
| CIS-3.1.4.4.2 | Ensure incoming webhooks are disabled | L2 | CIS | MEDIUM | |
| GWS.CHAT.1.1 | Ensure Chat history is enabled | L1 | CISA | MEDIUM | |
| GWS.CHAT.1.2 | Ensure users cannot change Chat history setting | L1 | CISA | MEDIUM | |
| GWS.CHAT.2.1 | Ensure external file sharing in Chat is disabled | L1 | CISA | HIGH | |
| GWS.CHAT.3.1 | Ensure Chat space history is enabled | L2 | CISA | MEDIUM | |
| GWS.CHAT.5.1 | Ensure Chat content reporting is enabled | L1 | CISA | MEDIUM | Enterprise Plus |
| GWS.CHAT.5.2 | Ensure all Chat reporting categories are selected | L2 | CISA | MEDIUM | Enterprise Plus |
| ID | Title | Level | Source | Severity | Notes |
|---|---|---|---|---|---|
| ADD-27 | Ensure Meet compliance recording is configured | L2 | MEDIUM | Assured Controls add-on | |
| GWS.MEET.1.1 | Ensure external users must ask to join meetings | L1 | CISA | HIGH | |
| GWS.MEET.2.1 | Ensure non-GWS tenant meeting access is disabled | L1 | CISA | HIGH | |
| GWS.MEET.3.1 | Ensure host management is enabled | L1 | CISA | MEDIUM | |
| GWS.MEET.4.1 | Ensure external participant warning is enabled | L1 | CISA | MEDIUM | |
| GWS.MEET.5.1 | Ensure incoming calls are restricted to organization | L1 | CISA | MEDIUM | |
| GWS.MEET.6.1 | Ensure automatic recording is disabled | L1 | CISA | LOW | Business Standard+ |
| GWS.MEET.6.2 | Ensure automatic transcription is disabled | L1 | CISA | LOW | Business Standard+ |
| ID | Title | Level | Source | Severity | Notes |
|---|---|---|---|---|---|
| ADD-28 | Ensure groups have active members | L1 | OTHER | LOW | unscored |
| ADD-37 | Ensure group discoverability is restricted | L2 | OTHER | MEDIUM | |
| ADD-46 | Ensure groups cannot be joined by anyone on the internet | L1 | OTHER | MEDIUM | |
| CIS-3.1.6.1 | Ensure external Groups access is private | L1 | CIS | HIGH | |
| CIS-3.1.6.2 | Ensure group creation is restricted to admins | L1 | CIS | MEDIUM | |
| CIS-3.1.6.3 | Ensure group conversation viewing is restricted | L2 | CIS | MEDIUM | |
| CIS-3.1.8.1 | Ensure external Google Groups is disabled | L2 | CIS | MEDIUM | |
| GWS.GROUPS.1.1 | Ensure external group access is disabled by default | L1 | CISA | HIGH | |
| GWS.GROUPS.1.2 | Ensure external group members are disabled by default | L2 | CISA | HIGH | |
| GWS.GROUPS.1.3 | Ensure external posting to groups is disabled | L1 | CISA | HIGH | |
| GWS.GROUPS.3.1 | Ensure default conversation visibility is members-only | L2 | CISA | MEDIUM | |
| GWS.GROUPS.4.1 | Ensure groups cannot be hidden from directory | L1 | CISA | MEDIUM |
| ID | Title | Level | Source | Severity | Notes |
|---|---|---|---|---|---|
| CIS-3.1.9.1.1 | Ensure Marketplace apps are restricted | L1 | CIS | HIGH |
| ID | Title | Level | Source | Severity | Notes |
|---|---|---|---|---|---|
| CIS-5.1.1.1 | Ensure App Usage Activity Report is reviewed | L1 | CIS | LOW | |
| CIS-5.1.1.2 | Ensure Security Investigation Tool is used | L1 | CIS | LOW | Enterprise Standard+ |
| GWS.COMMONCONTROLS.14.1 | Ensure audit logging is enabled | L1 | CISA | HIGH | |
| GWS.COMMONCONTROLS.14.2 | Ensure audit log retention meets minimum requirements | L1 | CISA | HIGH |
| ID | Title | Level | Source | Severity | Notes |
|---|---|---|---|---|---|
| ADD-08 | Ensure password protection warning is enabled | L2 | HIGH | ||
| ADD-09 | Ensure Google Takeout is restricted | L1 | MEDIUM | ||
| ADD-11 | Ensure client-side encryption is enabled | L2 | MEDIUM | Enterprise Plus | |
| ADD-16 | Ensure Apple Intelligence Writing Tools are disabled for Workspace | L2 | LOW | ||
| ADD-18 | Ensure passkeys are enforced as primary authentication | L2 | CRITICAL | ||
| ADD-20 | Ensure Context-Aware Access is applied to OIDC apps | L2 | MEDIUM | Enterprise Standard+ | |
| ADD-21 | Ensure Multi-Party Approval covers Vault exports | L2 | MEDIUM | Enterprise Standard+ | |
| ADD-32 | Users without 2-Step Verification by OU inventory | L1 | OTHER | LOW | unscored |
| ADD-33 | Ensure no OAuth apps have dangerous privilege grants | L1 | OTHER | CRITICAL | unscored |
| ADD-34 | Ensure no users have active App-Specific Passwords | L1 | OTHER | HIGH | unscored |
| ADD-36 | Ensure no active OAuth tokens grant dangerous privileges | L1 | OTHER | CRITICAL | |
| ADD-40 | Ensure default Context-Aware Access policy is enabled for SAML applications | L2 | MEDIUM | Enterprise Standard+ | |
| ADD-41 | Ensure admin roles are not assigned to groups anyone can join | L1 | OTHER | HIGH | |
| ADD-47 | Ensure compromised, unencrypted or unlocked devices do not keep access | L1 | OTHER | HIGH | |
| ADD-48 | Review custom admin roles with account-takeover privileges | L2 | OTHER | MEDIUM | |
| ADD-49 | Review who holds Google Vault privileges | L2 | OTHER | LOW | unscored |
| CIS-4.1.1.1 | Ensure 2-Step Verification is enforced for all admins | L1 | CIS | CRITICAL | |
| CIS-4.1.1.2 | Ensure hardware security keys are required for admins | L2 | CIS | CRITICAL | |
| CIS-4.1.1.3 | Ensure 2-Step Verification is enforced for all users | L1 | CIS | CRITICAL | |
| CIS-4.1.2.1 | Ensure super admin account recovery is disabled | L1 | CIS | CRITICAL | |
| CIS-4.1.2.2 | Ensure user account recovery is enabled | L1 | CIS | HIGH | |
| CIS-4.1.3.1 | Ensure Advanced Protection Program is available | L2 | CIS | HIGH | |
| CIS-4.1.4.1 | Ensure login challenges are enforced | L1 | CIS | HIGH | |
| CIS-4.1.5.1 | Ensure password policy is enhanced | L1 | CIS | HIGH | |
| CIS-4.2.6.1 | Ensure less secure app access is disabled | L1 | CIS | CRITICAL | |
| GWS.COMMONCONTROLS.1.1 | Ensure phishing-resistant MFA is required for all users | L2 | CISA | HIGH | |
| GWS.COMMONCONTROLS.1.3 | Ensure SMS/Voice MFA methods are disabled | L1 | CISA | CRITICAL | |
| GWS.COMMONCONTROLS.1.4 | Ensure MFA enrollment period is configured | L1 | CISA | HIGH | |
| GWS.COMMONCONTROLS.1.5 | Ensure 'trust this device' is disabled | L1 | CISA | HIGH | |
| GWS.COMMONCONTROLS.2.1 | Ensure context-aware access policies are implemented | L2 | CISA | HIGH | Enterprise Standard+ |
| GWS.COMMONCONTROLS.3.1 | Ensure SSO verification is enabled for organization SSO profile | L2 | CISA | HIGH | Enterprise Plus |
| GWS.COMMONCONTROLS.3.2 | Ensure post-SSO verification is enabled for third-party SSO | L2 | CISA | HIGH | Enterprise Plus |
| GWS.COMMONCONTROLS.4.1 | Ensure users re-authenticate after 12-hour session expiry | L1 | CISA | HIGH | Business Plus+ |
| GWS.COMMONCONTROLS.5.1 | Ensure strong password strength is enforced | L1 | CISA | MEDIUM | |
| GWS.COMMONCONTROLS.5.3 | Ensure minimum password length is at least 15 characters | L2 | CISA | LOW | |
| GWS.COMMONCONTROLS.5.5 | Ensure password reuse is not allowed | L1 | CISA | MEDIUM | |
| GWS.COMMONCONTROLS.5.6 | Ensure passwords are not set to expire | L1 | CISA | LOW | |
| GWS.COMMONCONTROLS.7.1 | Ensure conflicting account management is configured | L1 | CISA | LOW | |
| GWS.COMMONCONTROLS.8.1 | Ensure super admin account self-recovery is disabled | L1 | CISA | CRITICAL | |
| GWS.COMMONCONTROLS.8.2 | Ensure user account self-recovery is disabled | L1 | CISA | MEDIUM | |
| GWS.COMMONCONTROLS.8.3 | Ensure adding recovery information is disabled | L2 | CISA | MEDIUM | |
| GWS.COMMONCONTROLS.9.1 | Ensure privileged accounts are in Advanced Protection Program | L1 | CISA | HIGH | |
| GWS.COMMONCONTROLS.9.2 | Ensure sensitive users are in Advanced Protection Program | L2 | CISA | HIGH | |
| GWS.COMMONCONTROLS.10.1 | Ensure app access control policies restrict third-party access | L1 | CISA | HIGH | |
| GWS.COMMONCONTROLS.10.2 | Ensure users cannot consent to low-risk app scopes | L1 | CISA | HIGH | Enterprise Plus |
| GWS.COMMONCONTROLS.10.3 | Ensure unconfigured internal apps are not trusted | L1 | CISA | HIGH | |
| GWS.COMMONCONTROLS.10.4 | Ensure unconfigured third-party apps are blocked | L1 | CISA | CRITICAL | |
| GWS.COMMONCONTROLS.15.1 | Ensure data regions are configured | L2 | CISA | LOW | Business Standard+ |
| GWS.COMMONCONTROLS.15.2 | Ensure data is processed in the selected storage region | L2 | CISA | LOW | Business Standard+ |
| GWS.COMMONCONTROLS.16.1 | Ensure unused Google services are disabled | L2 | CISA | MEDIUM | Enterprise Plus |
| GWS.COMMONCONTROLS.16.2 | Ensure early access apps are disabled | L2 | CISA | LOW | Enterprise Plus |
| GWS.COMMONCONTROLS.17.1 | Ensure multi-party approval is enabled | L2 | CISA | HIGH | Enterprise Standard+ |
| GWS.COMMONCONTROLS.18.2 | Ensure DLP policy is configured for Google Chat | L1 | CISA | MEDIUM | Enterprise Standard+ |
| GWS.COMMONCONTROLS.18.3 | Ensure DLP policy is configured for Gmail | L1 | CISA | HIGH | Enterprise Plus |
| GWS.COMMONCONTROLS.18.4 | Ensure DLP policies block external sharing | L1 | CISA | HIGH | Enterprise Standard+ |
| ID | Title | Level | Source | Severity | Notes |
|---|---|---|---|---|---|
| CIS-3.1.7.1 | Ensure Google Sites creation is disabled | L2 | CIS | HIGH | |
| GWS.SITES.1.1 | Ensure Sites service is disabled | L1 | CISA | MEDIUM |