Skip to content

Check Reference

serbanb11 edited this page Sep 29, 2026 · 1 revision

GWS Security Auditor - Complete Check Reference

Overview

The GWS Security Auditor implements 227 security checks across four frameworks:

Framework Full Name Checks
CIS CIS Google Workspace Foundations Benchmark v1.3.0 84
CISA CISA SCuBA Baselines for Google Workspace 97
GOOGLE Google Security Checklist for Medium & Large Businesses 21
OTHER Additional best-practice checks 25
Total 227

Check Levels

  • L1 (Level 1) -- 151 checks. Baseline security settings that should be applied to all organizations. Minimal performance impact, broad applicability.
  • L2 (Level 2) -- 76 checks. Advanced security settings for organizations with higher security requirements. May restrict functionality or require additional configuration.

Severity

Severity Checks
CRITICAL 24
HIGH 81
MEDIUM 80
LOW 42

13 checks are informational (inventory/review) and do not affect the posture score; they are marked unscored below.

Check Statuses

Status Meaning
PASS Configuration meets the benchmark requirement
FAIL Configuration does not meet the requirement
WARN Partial compliance or potential issue detected
PARTIAL Remaining violations sit only in OUs designated for external sharing
ERROR Check could not complete: an API error, or the data it needs was not collected
MANUAL Requires manual verification. Returned when a setting is not exposed by any Google API, or when its state cannot be determined from the collected data -- the auditor does not guess PASS or FAIL
NOT_APPLICABLE Check does not apply to this environment (for example, the licence tier lacks the feature)

Some settings are not exposed by the Cloud Identity Policy API. Where Google records changes to them in the admin audit log, the auditor infers the current value from the most recent change event; with no event inside the log window the result is MANUAL.


Access Control

ID Title Level Source Severity Notes
CIS-4.2.1.1 Ensure third-party app access is restricted L1 CIS CRITICAL
CIS-4.2.1.2 Ensure third-party apps are reviewed L2 CIS HIGH
CIS-4.2.1.3 Ensure internal app API access is controlled L2 CIS HIGH
CIS-4.2.1.4 Ensure domain-wide delegation is reviewed L2 CIS CRITICAL
CIS-4.2.2.1 Ensure geo-blocking is configured L2 CIS HIGH Enterprise Standard+
CIS-4.2.3.1 Ensure DLP policies are configured for Drive L1 CIS HIGH Enterprise Standard+
CIS-4.2.4.1 Ensure Device Bound Session Credentials (DBSC) are enabled L2 CIS CRITICAL
CIS-4.2.5.1 Ensure cloud session control is configured L2 CIS HIGH Enterprise Plus

Alert Rules

ID Title Level Source Severity Notes
CIS-6.1 Ensure alert for user password change is configured L1 CIS HIGH
CIS-6.2 Ensure alert for government-backed attacks is configured L1 CIS HIGH
CIS-6.3 Ensure alert for suspicious activity is configured L1 CIS MEDIUM
CIS-6.4 Ensure alert for admin privilege grant is configured L1 CIS HIGH
CIS-6.5 Ensure alert for suspicious programmatic login is configured L1 CIS MEDIUM
CIS-6.6 Ensure alert for suspicious login is configured L1 CIS MEDIUM
CIS-6.7 Ensure alert for leaked password is configured L1 CIS HIGH
CIS-6.8 Ensure alert for employee spoofing is configured L1 CIS MEDIUM
GWS.COMMONCONTROLS.13.1 Ensure system-defined alerting rules are enabled L1 CISA MEDIUM

Assured Controls

ID Title Level Source Severity Notes
GWS.ASSUREDCONTROLS.1.1 Ensure access approvals are enabled L2 CISA LOW Assured Controls add-on
GWS.ASSUREDCONTROLS.1.2 Ensure support access is restricted to US personnel L2 CISA LOW Assured Controls add-on
GWS.ASSUREDCONTROLS.2.1 Ensure multi-region data processing is disabled L2 CISA LOW Assured Controls add-on

Calendar

ID Title Level Source Severity Notes
ADD-23 Ensure DLP rules are configured for Calendar L2 GOOGLE MEDIUM Enterprise Standard+
CIS-3.1.1.1.1 Ensure external sharing for primary calendars is limited L1 CIS MEDIUM
CIS-3.1.1.1.2 Ensure internal sharing for primary calendars is configured L1 CIS MEDIUM
CIS-3.1.1.1.3 Ensure external invitations show warning L1 CIS MEDIUM
CIS-3.1.1.2.1 Ensure external sharing for secondary calendars is limited L1 CIS MEDIUM
CIS-3.1.1.2.2 Ensure internal sharing for secondary calendars is configured L2 CIS MEDIUM
CIS-3.1.1.3.1 Ensure Calendar web offline access is disabled L2 CIS MEDIUM
GWS.CALENDAR.3.1 Ensure Calendar Interop is disabled L1 CISA MEDIUM
GWS.CALENDAR.3.2 Ensure Calendar Interop uses Microsoft 365 Graph API L2 CISA MEDIUM
GWS.CALENDAR.4.1 Ensure paid appointment scheduling is disabled L1 CISA LOW Business Standard+

Classroom

ID Title Level Source Severity Notes
GWS.CLASSROOM.1.1 Ensure class membership is restricted to domain L1 CISA LOW
GWS.CLASSROOM.1.2 Ensure classes users can join are restricted to domain L1 CISA LOW
GWS.CLASSROOM.2.1 Ensure Classroom API access is disabled L1 CISA LOW
GWS.CLASSROOM.3.1 Ensure roster import with Clever is disabled L1 CISA LOW
GWS.CLASSROOM.4.1 Ensure only teachers can unenroll students L1 CISA LOW
GWS.CLASSROOM.5.1 Ensure class creation is restricted to verified teachers L1 CISA LOW

Devices

ID Title Level Source Severity Notes
ADD-30 Ensure mobile devices are syncing recently L1 OTHER LOW unscored
ADD-31 Ensure ChromeOS devices are active recently L1 OTHER LOW unscored
ADD-38 Ensure endpoint verification devices are syncing recently L1 OTHER LOW unscored
ADD-39 Ensure pending devices are approved promptly L2 OTHER LOW unscored

Directory

ID Title Level Source Severity Notes
ADD-42 Ensure super admin accounts are actively used or removed L1 OTHER HIGH
ADD-43 Ensure suspended users do not hold admin roles L1 OTHER MEDIUM
ADD-44 Review active user accounts with no recent sign-in L2 OTHER LOW unscored
ADD-52 Review active users without a Google Workspace licence L2 OTHER LOW unscored
CIS-1.1.1 Ensure more than one Super Admin account exists L1 CIS CRITICAL
CIS-1.1.2 Ensure fewer than 4 Super Admin accounts exist L1 CIS HIGH
CIS-1.1.3 Ensure Super Admin accounts are only used for admin tasks L2 CIS LOW
CIS-1.2.1.1 Ensure directory data is restricted from external access L1 CIS HIGH
GWS.COMMONCONTROLS.6.1 Ensure admin accounts are cloud-only L1 CISA HIGH

Drive

ID Title Level Source Severity Notes
ADD-35 Ensure Shared Drives have secure default restrictions L1 OTHER HIGH unscored

Drive and Docs

ID Title Level Source Severity Notes
ADD-24 Ensure AI-powered data classification is enabled for Drive L2 GOOGLE MEDIUM
ADD-25 Ensure Drive trust rules are configured L2 GOOGLE MEDIUM
CIS-3.1.2.1.1.1 Ensure users are warned when sharing outside domain L1 CIS HIGH
CIS-3.1.2.1.1.2 Ensure users cannot publish files publicly L1 CIS CRITICAL
CIS-3.1.2.1.1.3 Ensure sharing is controlled by domain allowlists L2 CIS HIGH
CIS-3.1.2.1.1.4 Ensure users are warned when sharing with allowlisted domains L2 CIS MEDIUM
CIS-3.1.2.1.1.5 Ensure Access Checker limits file access L1 CIS HIGH
CIS-3.1.2.1.1.6 Ensure only internal users can distribute content externally L2 CIS HIGH
CIS-3.1.2.1.2.1 Ensure Shared Drive creation is controlled L1 CIS MEDIUM
CIS-3.1.2.1.2.2 Ensure manager cannot override shared drive settings L2 CIS MEDIUM Business Standard+
CIS-3.1.2.1.2.3 Ensure shared drive access is restricted to members L1 CIS MEDIUM Business Standard+
CIS-3.1.2.1.2.4 Ensure viewers cannot download, print, or copy files L2 CIS MEDIUM Business Standard+
CIS-3.1.2.2.1 Ensure offline access to Drive is disabled L2 CIS MEDIUM Enterprise Plus
CIS-3.1.2.2.2 Ensure Desktop access to Drive is disabled L2 CIS MEDIUM
CIS-3.1.2.2.3 Ensure Drive SDK is disabled L2 CIS MEDIUM
GWS.DRIVEDOCS.1.2 Ensure receiving files from non-allowlisted domains is disabled L1 CISA HIGH
GWS.DRIVEDOCS.1.3 Ensure sharing warnings for non-allowlisted domains are enabled L1 CISA MEDIUM
GWS.DRIVEDOCS.1.4 Ensure sharing with non-Google accounts is disabled L1 CISA CRITICAL
GWS.DRIVEDOCS.1.5 Ensure 'anyone with the link' sharing is disabled L1 CISA CRITICAL
GWS.DRIVEDOCS.1.6 Ensure access checking is set to recipients only L1 CISA MEDIUM
GWS.DRIVEDOCS.1.7 Ensure users cannot upload to external shared drives L2 CISA MEDIUM
GWS.DRIVEDOCS.1.8 Ensure default access for new items is 'private to owner' L1 CISA HIGH
GWS.DRIVEDOCS.1.9 Ensure out-of-domain file-level warnings are enabled L1 CISA MEDIUM
GWS.DRIVEDOCS.1.10 Ensure forms cannot accept external responses when external sharing is off L2 CISA LOW
GWS.DRIVEDOCS.1.11 Ensure users cannot respond to external forms when receiving files is off L2 CISA LOW
GWS.DRIVEDOCS.2.1 Ensure shared drive manager override is disabled L2 CISA MEDIUM
GWS.DRIVEDOCS.2.2 Ensure non-members can be added to shared drive files L1 CISA MEDIUM
GWS.DRIVEDOCS.3.1 Ensure security updates for files are applied L1 CISA MEDIUM
GWS.DRIVEDOCS.5.1 Ensure Google Drive Add-Ons are disabled L1 CISA MEDIUM
GWS.DRIVEDOCS.6.1 Ensure Drive for Desktop is restricted to authorized devices L1 CISA MEDIUM

Gemini

ID Title Level Source Severity Notes
ADD-13 Ensure Gemini features in Workspace apps are controlled L1 GOOGLE LOW
ADD-14 Ensure Gemini in Chrome is disabled L2 GOOGLE LOW
ADD-15 Ensure Google Workspace Studio access is controlled L2 GOOGLE LOW
GWS.GEMINI.1.1 Ensure Gemini app access is restricted to licensed users L1 CISA LOW
GWS.GEMINI.2.1 Ensure alpha Gemini features are disabled L1 CISA LOW

Gmail

ID Title Level Source Severity Notes
ADD-02 Ensure Security Sandbox is enabled for Gmail L1 OTHER HIGH Business Standard+
ADD-05 Ensure MX records point to Google L1 GOOGLE HIGH
ADD-06 Ensure inbound gateway SPF configuration is correct L2 GOOGLE MEDIUM
ADD-07 Ensure TLS is enforced for partner domains L2 GOOGLE HIGH
ADD-12 Ensure DLP rules are configured for Gmail L1 GOOGLE HIGH Enterprise Standard+
ADD-22 Ensure data classification labels are enabled for Gmail L1 GOOGLE MEDIUM Business Standard+
ADD-26 Ensure CSE is enabled for Gmail L2 GOOGLE MEDIUM
ADD-50 Ensure MTA-STS is published for all mail domains L2 OTHER MEDIUM
ADD-51 Ensure mailboxes do not forward to external addresses L1 OTHER HIGH
CIS-3.1.3.1.1 Ensure mail delegation is disabled L1 CIS CRITICAL
CIS-3.1.3.1.2 Ensure offline Gmail is disabled L2 CIS MEDIUM Enterprise Plus
CIS-3.1.3.2.1 Ensure DKIM is enabled for all domains L1 CIS CRITICAL
CIS-3.1.3.2.2 Ensure SPF records are configured for all domains L1 CIS CRITICAL
CIS-3.1.3.2.3 Ensure DMARC records are configured for all domains L1 CIS CRITICAL
CIS-3.1.3.3.1 Ensure quarantine admin notifications are enabled L2 CIS MEDIUM Enterprise Plus
CIS-3.1.3.4.1.1 Ensure encrypted attachment protection is enabled L1 CIS HIGH
CIS-3.1.3.4.1.2 Ensure script attachment protection is enabled L1 CIS HIGH
CIS-3.1.3.4.1.3 Ensure anomalous attachment protection is enabled L1 CIS HIGH
CIS-3.1.3.4.2.1 Ensure shortened URL identification is enabled L1 CIS HIGH
CIS-3.1.3.4.2.2 Ensure linked image scanning is enabled L1 CIS HIGH
CIS-3.1.3.4.2.3 Ensure warning for untrusted links is enabled L1 CIS HIGH
CIS-3.1.3.4.3.1 Ensure domain spoofing protection is enabled L1 CIS HIGH
CIS-3.1.3.4.3.2 Ensure employee name spoofing protection is enabled L1 CIS HIGH
CIS-3.1.3.4.3.3 Ensure inbound domain spoofing protection is enabled L1 CIS HIGH
CIS-3.1.3.4.3.4 Ensure unauthenticated email protection is enabled L1 CIS HIGH
CIS-3.1.3.4.3.5 Ensure Groups inbound spoofing protection is enabled L1 CIS HIGH
CIS-3.1.3.5.1 Ensure POP and IMAP access is disabled L1 CIS HIGH
CIS-3.1.3.5.2 Ensure automatic email forwarding is disabled L1 CIS CRITICAL
CIS-3.1.3.5.3 Ensure per-user outbound gateways are disabled L1 CIS MEDIUM
CIS-3.1.3.5.4 Ensure external recipient warnings are enabled L1 CIS MEDIUM Enterprise Plus
CIS-3.1.3.6.1 Ensure enhanced pre-delivery message scanning is enabled L1 CIS HIGH
CIS-3.1.3.6.2 Ensure spam filters are not bypassed for internal senders L1 CIS HIGH Enterprise Plus
CIS-3.1.3.7.1 Ensure comprehensive mail storage is enabled L2 CIS MEDIUM
CIS-3.1.3.7.2 Ensure secure TLS connection is enforced L1 CIS HIGH Enterprise Plus
GWS.GMAIL.4.1 Ensure DMARC policy is published for all domains L1 CISA HIGH
GWS.GMAIL.4.2 Ensure DMARC policy is set to reject L1 CISA CRITICAL
GWS.GMAIL.4.3 Ensure DMARC alignment mode is strict L1 CISA HIGH
GWS.GMAIL.4.4 Ensure DMARC reporting is configured L1 CISA MEDIUM
GWS.GMAIL.5.4 Ensure future recommended attachment protections are applied automatically L1 CISA LOW
GWS.GMAIL.5.5 Ensure flagged emails are moved out of inbox L1 CISA MEDIUM
GWS.GMAIL.6.4 Ensure future recommended link and image protections are applied automatically L1 CISA LOW
GWS.GMAIL.7.6 Ensure spoofed and unauthenticated email is not kept in the inbox L1 CISA HIGH
GWS.GMAIL.7.7 Ensure future recommended spoofing protections are applied automatically L1 CISA LOW
GWS.GMAIL.8.1 Ensure user email uploads are disabled L1 CISA MEDIUM
GWS.GMAIL.10.1 Ensure Google Workspace Sync is disabled L1 CISA MEDIUM
GWS.GMAIL.14.1 Ensure email allowlist is not used L1 CISA MEDIUM
GWS.GMAIL.18.1 Ensure no domains bypass spam filters L1 CISA HIGH
GWS.GMAIL.18.2 Ensure no domains bypass spam filters and hide warnings L1 CISA HIGH
GWS.GMAIL.18.3 Ensure global spam filter bypass is disabled L1 CISA HIGH

Google Chat

ID Title Level Source Severity Notes
ADD-29 Ensure Chat spaces have recent activity L2 OTHER LOW unscored
ADD-45 Ensure Chat spaces with external members are restricted L2 OTHER MEDIUM
CIS-3.1.4.2.1 Ensure external chat is restricted to allowed domains L1 CIS HIGH
CIS-3.1.4.4.1 Ensure Chat app installation is disabled L2 CIS MEDIUM
CIS-3.1.4.4.2 Ensure incoming webhooks are disabled L2 CIS MEDIUM
GWS.CHAT.1.1 Ensure Chat history is enabled L1 CISA MEDIUM
GWS.CHAT.1.2 Ensure users cannot change Chat history setting L1 CISA MEDIUM
GWS.CHAT.2.1 Ensure external file sharing in Chat is disabled L1 CISA HIGH
GWS.CHAT.3.1 Ensure Chat space history is enabled L2 CISA MEDIUM
GWS.CHAT.5.1 Ensure Chat content reporting is enabled L1 CISA MEDIUM Enterprise Plus
GWS.CHAT.5.2 Ensure all Chat reporting categories are selected L2 CISA MEDIUM Enterprise Plus

Google Meet

ID Title Level Source Severity Notes
ADD-27 Ensure Meet compliance recording is configured L2 GOOGLE MEDIUM Assured Controls add-on
GWS.MEET.1.1 Ensure external users must ask to join meetings L1 CISA HIGH
GWS.MEET.2.1 Ensure non-GWS tenant meeting access is disabled L1 CISA HIGH
GWS.MEET.3.1 Ensure host management is enabled L1 CISA MEDIUM
GWS.MEET.4.1 Ensure external participant warning is enabled L1 CISA MEDIUM
GWS.MEET.5.1 Ensure incoming calls are restricted to organization L1 CISA MEDIUM
GWS.MEET.6.1 Ensure automatic recording is disabled L1 CISA LOW Business Standard+
GWS.MEET.6.2 Ensure automatic transcription is disabled L1 CISA LOW Business Standard+

Groups

ID Title Level Source Severity Notes
ADD-28 Ensure groups have active members L1 OTHER LOW unscored
ADD-37 Ensure group discoverability is restricted L2 OTHER MEDIUM
ADD-46 Ensure groups cannot be joined by anyone on the internet L1 OTHER MEDIUM
CIS-3.1.6.1 Ensure external Groups access is private L1 CIS HIGH
CIS-3.1.6.2 Ensure group creation is restricted to admins L1 CIS MEDIUM
CIS-3.1.6.3 Ensure group conversation viewing is restricted L2 CIS MEDIUM
CIS-3.1.8.1 Ensure external Google Groups is disabled L2 CIS MEDIUM
GWS.GROUPS.1.1 Ensure external group access is disabled by default L1 CISA HIGH
GWS.GROUPS.1.2 Ensure external group members are disabled by default L2 CISA HIGH
GWS.GROUPS.1.3 Ensure external posting to groups is disabled L1 CISA HIGH
GWS.GROUPS.3.1 Ensure default conversation visibility is members-only L2 CISA MEDIUM
GWS.GROUPS.4.1 Ensure groups cannot be hidden from directory L1 CISA MEDIUM

Marketplace

ID Title Level Source Severity Notes
CIS-3.1.9.1.1 Ensure Marketplace apps are restricted L1 CIS HIGH

Reporting

ID Title Level Source Severity Notes
CIS-5.1.1.1 Ensure App Usage Activity Report is reviewed L1 CIS LOW
CIS-5.1.1.2 Ensure Security Investigation Tool is used L1 CIS LOW Enterprise Standard+
GWS.COMMONCONTROLS.14.1 Ensure audit logging is enabled L1 CISA HIGH
GWS.COMMONCONTROLS.14.2 Ensure audit log retention meets minimum requirements L1 CISA HIGH

Security

ID Title Level Source Severity Notes
ADD-08 Ensure password protection warning is enabled L2 GOOGLE HIGH
ADD-09 Ensure Google Takeout is restricted L1 GOOGLE MEDIUM
ADD-11 Ensure client-side encryption is enabled L2 GOOGLE MEDIUM Enterprise Plus
ADD-16 Ensure Apple Intelligence Writing Tools are disabled for Workspace L2 GOOGLE LOW
ADD-18 Ensure passkeys are enforced as primary authentication L2 GOOGLE CRITICAL
ADD-20 Ensure Context-Aware Access is applied to OIDC apps L2 GOOGLE MEDIUM Enterprise Standard+
ADD-21 Ensure Multi-Party Approval covers Vault exports L2 GOOGLE MEDIUM Enterprise Standard+
ADD-32 Users without 2-Step Verification by OU inventory L1 OTHER LOW unscored
ADD-33 Ensure no OAuth apps have dangerous privilege grants L1 OTHER CRITICAL unscored
ADD-34 Ensure no users have active App-Specific Passwords L1 OTHER HIGH unscored
ADD-36 Ensure no active OAuth tokens grant dangerous privileges L1 OTHER CRITICAL
ADD-40 Ensure default Context-Aware Access policy is enabled for SAML applications L2 GOOGLE MEDIUM Enterprise Standard+
ADD-41 Ensure admin roles are not assigned to groups anyone can join L1 OTHER HIGH
ADD-47 Ensure compromised, unencrypted or unlocked devices do not keep access L1 OTHER HIGH
ADD-48 Review custom admin roles with account-takeover privileges L2 OTHER MEDIUM
ADD-49 Review who holds Google Vault privileges L2 OTHER LOW unscored
CIS-4.1.1.1 Ensure 2-Step Verification is enforced for all admins L1 CIS CRITICAL
CIS-4.1.1.2 Ensure hardware security keys are required for admins L2 CIS CRITICAL
CIS-4.1.1.3 Ensure 2-Step Verification is enforced for all users L1 CIS CRITICAL
CIS-4.1.2.1 Ensure super admin account recovery is disabled L1 CIS CRITICAL
CIS-4.1.2.2 Ensure user account recovery is enabled L1 CIS HIGH
CIS-4.1.3.1 Ensure Advanced Protection Program is available L2 CIS HIGH
CIS-4.1.4.1 Ensure login challenges are enforced L1 CIS HIGH
CIS-4.1.5.1 Ensure password policy is enhanced L1 CIS HIGH
CIS-4.2.6.1 Ensure less secure app access is disabled L1 CIS CRITICAL
GWS.COMMONCONTROLS.1.1 Ensure phishing-resistant MFA is required for all users L2 CISA HIGH
GWS.COMMONCONTROLS.1.3 Ensure SMS/Voice MFA methods are disabled L1 CISA CRITICAL
GWS.COMMONCONTROLS.1.4 Ensure MFA enrollment period is configured L1 CISA HIGH
GWS.COMMONCONTROLS.1.5 Ensure 'trust this device' is disabled L1 CISA HIGH
GWS.COMMONCONTROLS.2.1 Ensure context-aware access policies are implemented L2 CISA HIGH Enterprise Standard+
GWS.COMMONCONTROLS.3.1 Ensure SSO verification is enabled for organization SSO profile L2 CISA HIGH Enterprise Plus
GWS.COMMONCONTROLS.3.2 Ensure post-SSO verification is enabled for third-party SSO L2 CISA HIGH Enterprise Plus
GWS.COMMONCONTROLS.4.1 Ensure users re-authenticate after 12-hour session expiry L1 CISA HIGH Business Plus+
GWS.COMMONCONTROLS.5.1 Ensure strong password strength is enforced L1 CISA MEDIUM
GWS.COMMONCONTROLS.5.3 Ensure minimum password length is at least 15 characters L2 CISA LOW
GWS.COMMONCONTROLS.5.5 Ensure password reuse is not allowed L1 CISA MEDIUM
GWS.COMMONCONTROLS.5.6 Ensure passwords are not set to expire L1 CISA LOW
GWS.COMMONCONTROLS.7.1 Ensure conflicting account management is configured L1 CISA LOW
GWS.COMMONCONTROLS.8.1 Ensure super admin account self-recovery is disabled L1 CISA CRITICAL
GWS.COMMONCONTROLS.8.2 Ensure user account self-recovery is disabled L1 CISA MEDIUM
GWS.COMMONCONTROLS.8.3 Ensure adding recovery information is disabled L2 CISA MEDIUM
GWS.COMMONCONTROLS.9.1 Ensure privileged accounts are in Advanced Protection Program L1 CISA HIGH
GWS.COMMONCONTROLS.9.2 Ensure sensitive users are in Advanced Protection Program L2 CISA HIGH
GWS.COMMONCONTROLS.10.1 Ensure app access control policies restrict third-party access L1 CISA HIGH
GWS.COMMONCONTROLS.10.2 Ensure users cannot consent to low-risk app scopes L1 CISA HIGH Enterprise Plus
GWS.COMMONCONTROLS.10.3 Ensure unconfigured internal apps are not trusted L1 CISA HIGH
GWS.COMMONCONTROLS.10.4 Ensure unconfigured third-party apps are blocked L1 CISA CRITICAL
GWS.COMMONCONTROLS.15.1 Ensure data regions are configured L2 CISA LOW Business Standard+
GWS.COMMONCONTROLS.15.2 Ensure data is processed in the selected storage region L2 CISA LOW Business Standard+
GWS.COMMONCONTROLS.16.1 Ensure unused Google services are disabled L2 CISA MEDIUM Enterprise Plus
GWS.COMMONCONTROLS.16.2 Ensure early access apps are disabled L2 CISA LOW Enterprise Plus
GWS.COMMONCONTROLS.17.1 Ensure multi-party approval is enabled L2 CISA HIGH Enterprise Standard+
GWS.COMMONCONTROLS.18.2 Ensure DLP policy is configured for Google Chat L1 CISA MEDIUM Enterprise Standard+
GWS.COMMONCONTROLS.18.3 Ensure DLP policy is configured for Gmail L1 CISA HIGH Enterprise Plus
GWS.COMMONCONTROLS.18.4 Ensure DLP policies block external sharing L1 CISA HIGH Enterprise Standard+

Sites

ID Title Level Source Severity Notes
CIS-3.1.7.1 Ensure Google Sites creation is disabled L2 CIS HIGH
GWS.SITES.1.1 Ensure Sites service is disabled L1 CISA MEDIUM

Clone this wiki locally