Skip to content

Google Workspace data sharing & exposure security checks

External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.

On Google Workspace, Black Cat runs 36 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Google Workspace connector needs.

Checks (36)

severity: medium Group Allows External Members fix difficulty: easy #

Restrict Google Workspace group membership to organization members only

  1. Navigate to Google Admin Console > Directory > Groups
  2. Select the group that allows external members
  3. Click Group Settings and set Who Can Join to Only People in the Organization
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.18 SOC 2 Type II CC9.1 CIS Controls v8 CIS-15.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high Group Allows External Posting fix difficulty: easy #

Restrict Google Workspace group posting to organization members only

  1. Navigate to Google Admin Console > Directory > Groups
  2. Select the group that allows external posting
  3. Click Group Settings and restrict posting to organization members only
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: low Group Allows Open Join fix difficulty: easy #

Change Google Workspace group join policy to Invite Only or Approval Required

  1. Navigate to Google Admin Console > Directory > Groups
  2. Select the group with open join
  3. Click Group Settings and change join policy to Invite Only or Approval Required
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Group Public Conversations fix difficulty: easy #

Set Google Workspace group conversation visibility to Members Only

  1. Navigate to Google Admin Console > Directory > Groups
  2. Select the group with public conversations
  3. Click Group Settings and set conversation visibility to Members Only
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Group Domain-Wide Membership Visibility fix difficulty: easy #

Restrict Google Workspace group membership visibility to Members Only or Managers Only

  1. Navigate to Google Admin Console > Directory > Groups
  2. Select the group with domain-wide membership visibility
  3. Click Group Settings and restrict membership visibility to Members Only or Managers Only
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Group Contact Owner Anyone fix difficulty: easy #

Restrict Google Workspace group contact-owner to group members only

  1. Navigate to Google Admin Console > Directory > Groups
  2. Select the group where anyone can contact the owner
  3. Click Group Settings and restrict contact owner to group members only
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Group Discoverable by Anyone fix difficulty: easy #

Restrict Google Workspace group discoverability to organization members only

  1. Navigate to Google Admin Console > Directory > Groups
  2. Select the group discoverable by anyone
  3. Click Group Settings and restrict discoverability to organization members
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Mail Delegation Enabled fix difficulty: easy #

Disable mail delegation in Google Workspace Gmail end user access settings

  1. Navigate to Google Admin Console > Apps > Google Workspace > Gmail > End User Access
  2. Disable mail delegation for the organization
  3. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: critical Drive External Sharing Enabled fix difficulty: easy #

Disable external sharing for Google Drive at the organization level

  1. Navigate to Google Admin Console > Apps > Google Workspace > Drive and Docs > Sharing settings
  2. Under Sharing outside of your organization, select Off — no files or folders can be shared outside the domain
  3. Save changes
  4. Notify users that external sharing has been disabled

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.14 ISO 27001:2022 A.8.12 SOC 2 Type II CC6.1 SOC 2 Type II CC9.1 CIS Controls v8 CIS-03.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

Disable anyone-with-the-link sharing for Google Drive organization-wide

  1. Navigate to Google Admin Console > Apps > Google Workspace > Drive and Docs > Sharing settings
  2. Under Sharing outside of your organization, disable the option that allows sharing to anyone with a link
  3. Set the default link sharing to restricted (only people explicitly added can access)
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.14 ISO 27001:2022 A.8.12 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high Drive Sharing Outside Organization fix difficulty: easy #

Restrict Google Drive sharing to within the organization only

  1. Navigate to Google Admin Console > Apps > Google Workspace > Drive and Docs > Sharing settings
  2. Under Sharing outside of your organization, select Off or Allowlisted domains only
  3. If allowlisting specific domains, add only approved partner domains
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.14 SOC 2 Type II CC6.6 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high Drive Publish to Web Allowed fix difficulty: easy #

Disable the option for users to publish Google Drive files to the web

  1. Navigate to Google Admin Console > Apps > Google Workspace > Drive and Docs > Sharing settings
  2. Locate the option Allow users to publish files on the web
  3. Disable this setting for the organization
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.14 ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Drive External Shared Drives Allowed fix difficulty: easy #

Prevent external users from accessing organization shared drives in Google Drive

  1. Navigate to Google Admin Console > Apps > Google Workspace > Drive and Docs > Sharing settings
  2. Under Shared drive creation, disable the option allowing external users to access shared drives
  3. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.14 SOC 2 Type II CC6.6 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: critical Drive File Public Sharing fix difficulty: medium #

Remove public sharing from the flagged Google Drive file and contact the file owner

  1. Identify the file owner from the finding details
  2. Contact the file owner and request they restrict sharing via Drive > Share > Change to Restricted
  3. Alternatively, use the Drive Admin audit log to locate the file and take ownership if needed
  4. Configure organization-wide DLP rules to prevent future public sharing of sensitive files
  5. Consider enabling Google Drive Trust Rules to block public sharing by policy

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.14 ISO 27001:2022 A.8.12 SOC 2 Type II CC6.1 SOC 2 Type II CC9.1 CIS Controls v8 CIS-03.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: critical Drive File Publicly Indexed fix difficulty: medium #

Remove public indexing from the flagged Google Drive file so it is not discoverable by search engines

  1. Identify the file owner from the finding details
  2. Contact the file owner and request they restrict sharing to remove public indexing
  3. Alternatively, navigate to Admin Console > Apps > Google Workspace > Drive and Docs > Sharing settings and disable Allow users to publish files on the web
  4. Verify the file is no longer publicly accessible or indexed

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.14 ISO 27001:2022 A.8.12 SOC 2 Type II CC6.1 SOC 2 Type II CC9.1 CIS Controls v8 CIS-03.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

Restrict the flagged Google Drive file from anyone-with-the-link access

  1. Identify the file owner from the finding details
  2. Contact the file owner and request they change sharing to Restricted (only specific people)
  3. Alternatively, use the Google Admin Drive audit log to identify and remediate at scale
  4. Enable organization-wide DLP rules to prevent link sharing of sensitive files

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.14 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high Drive File Shared With Personal Email fix difficulty: medium #

Remove personal email address access from the flagged Google Drive file

  1. Identify the file owner from the finding details
  2. Contact the file owner and request they remove the personal email from the file's sharing permissions
  3. Alternatively, use the Google Admin Drive audit report to identify files shared with personal emails
  4. Configure a DLP or Trust Rule to block sharing with consumer email domains (gmail.com, yahoo.com, etc.)

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.14 SOC 2 Type II CC6.6 CIS Controls v8 CIS-03.1 NIST CSF 2.0 ID.RA GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high Drive File External Edit Access fix difficulty: medium #

Remove external edit access from the flagged Google Drive file

  1. Identify the file owner from the finding details
  2. Contact the file owner and request they downgrade external users from Editor to Viewer or remove them entirely
  3. Alternatively, use the Google Admin Drive audit report to review and remediate at scale
  4. Consider enabling organization-wide settings to prevent external users from being granted edit permissions

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high Drive Shared Drive Has External Members fix difficulty: medium #

Remove external members from the flagged Google Drive shared drive

  1. Identify the shared drive from the finding details
  2. Navigate to the shared drive in Google Drive and open Manage Members
  3. Remove any external (non-organization) members
  4. Review shared drive settings to restrict future external member additions
  5. In Admin Console, set shared drives to disallow external members under Sharing settings

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.6 CIS Controls v8 CIS-03.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high Drive File Owner Is External fix difficulty: hard #

Transfer ownership of the flagged Google Drive file back to an internal organization user

  1. Identify the file from the finding details
  2. Use Admin Console > Reports > Drive audit log to locate the file
  3. As Super Admin, transfer file ownership to an internal user via Admin SDK or by contacting the current owner
  4. Ensure the file is moved to a location accessible by the organization
  5. Review how an external user became owner and close the gap (e.g., disable external sharing)

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Drive File Shared With External Domain fix difficulty: medium #

Remove sharing with unapproved external domains from the flagged Google Drive file

  1. Identify the file owner and the external domain from the finding details
  2. Contact the file owner and request they remove the external domain from the file's sharing permissions
  3. Alternatively, configure Drive Sharing settings to restrict sharing to an allowlist of approved domains
  4. Use DLP rules to detect and prevent future sharing with unapproved domains

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.14 SOC 2 Type II CC6.6 CIS Controls v8 CIS-03.1 NIST CSF 2.0 ID.RA GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Drive File Stale External Sharing fix difficulty: medium #

Remove stale external sharing permissions from the flagged Google Drive file

  1. Identify the file owner from the finding details
  2. Contact the file owner and request they audit and remove external users who no longer need access
  3. Alternatively, use the Google Admin Drive audit report to review inactive external shares at scale
  4. Establish a regular access review process for files shared externally

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.3 SOC 2 Type II CC6.3 CIS Controls v8 CIS-03.1 NIST CSF 2.0 ID.RA GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Drive File Excessive Permissions fix difficulty: medium #

Reduce permissions on the flagged Google Drive file to the minimum required

  1. Identify the file owner from the finding details
  2. Contact the file owner and request they review and reduce sharing permissions to least-privilege
  3. Downgrade Editors to Viewers where edit access is not required, and remove users who no longer need access
  4. Use the Google Admin Drive audit report to identify files with excessive permissions at scale

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.3 CIS Controls v8 CIS-03.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Drive File External Commenter Access fix difficulty: medium #

Remove external commenter access from the flagged Google Drive file

  1. Identify the file owner from the finding details
  2. Contact the file owner and request they remove external users with commenter access
  3. Evaluate whether the external commenter access is business-justified; if not, revoke it
  4. Configure Drive sharing settings to limit external commenting permissions if needed

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.3 SOC 2 Type II CC6.6 CIS Controls v8 CIS-03.1 NIST CSF 2.0 ID.RA GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Drive File Broad Internal Sharing fix difficulty: medium #

Restrict the flagged Google Drive file from being accessible to the entire organization

  1. Identify the file owner from the finding details
  2. Contact the file owner and request they change sharing from organization-wide to specific users or groups
  3. Encourage use of team-specific Shared Drives instead of broad organization-wide links
  4. Use DLP rules to flag or block domain-wide link sharing for sensitive file types

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.3 CIS Controls v8 CIS-03.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

Change the flagged Google Drive file from organization-wide link sharing to restricted access

  1. Identify the file owner from the finding details
  2. Contact the file owner and request they change the link sharing setting from Anyone in the organization to Restricted
  3. Confirm the file does not need to be broadly accessible before restricting

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.14 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Drive User Excessive External Sharing fix difficulty: medium #

Review and reduce excessive external sharing by the flagged Google Drive user

  1. Navigate to Google Admin Console > Reports > Audit and investigation > Drive log events
  2. Filter by the flagged user and review files shared externally
  3. Contact the user and their manager to review and justify each external share
  4. Remove external sharing for files that do not require it
  5. Consider restricting the user's external sharing privileges via an organizational unit policy

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.14 SOC 2 Type II CC6.3 CIS Controls v8 CIS-03.1 NIST CSF 2.0 ID.RA GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high Shared Drive Allows External Users fix difficulty: medium #

Remove external user access from the flagged Google Workspace shared drive

  1. Navigate to Google Admin Console > Apps > Google Workspace > Drive and Docs > Manage shared drives
  2. Select the flagged shared drive
  3. Review and remove external (non-organization) members
  4. Disable the option to allow external users in this shared drive's settings
  5. Optionally, configure organization-wide settings to prevent external users in all shared drives

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Shared Drive Allows Non-Members fix difficulty: easy #

Restrict the flagged Google Workspace shared drive so only members can access it

  1. Navigate to Google Admin Console > Apps > Google Workspace > Drive and Docs > Manage shared drives
  2. Select the flagged shared drive
  3. Disable the setting that allows non-members to access files via links
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: low Shared Drive No Download Restriction fix difficulty: easy #

Enable download restrictions on the flagged Google Workspace shared drive for viewers and commenters

  1. Navigate to Google Admin Console > Apps > Google Workspace > Drive and Docs > Manage shared drives
  2. Select the flagged shared drive
  3. Enable Prevent viewers and commenters from downloading, printing, and copying files
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high Shared Drive Has External Members fix difficulty: medium #

Remove external members from the flagged Google Workspace shared drive

  1. Navigate to Google Admin Console > Apps > Google Workspace > Drive and Docs > Manage shared drives
  2. Select the flagged shared drive and click Manage Members
  3. Remove any external (non-organization) members
  4. Review and update shared drive settings to prevent future external member additions
  5. Optionally, configure organization-wide settings under Sharing settings to block external shared drive membership

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Chat External Access Enabled fix difficulty: easy #

Disable external chat in Google Chat to prevent outside users from messaging members

  1. Navigate to Google Admin Console > Apps > Google Workspace > Google Chat > External chat settings
  2. Disable chat with external users, or restrict to allowlisted domains
  3. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.14 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high DLP Rules Not Configured fix difficulty: medium #

Configure data loss prevention (DLP) rules in Google Workspace

  1. Navigate to Google Admin Console > Security > Data protection
  2. Create DLP rules to detect and protect sensitive content
  3. Apply the rules to the appropriate organizational units
  4. Save and enable the rules

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high Gmail Filter Forwards Externally fix difficulty: medium #

Remove Gmail filter rules that forward mail to external addresses

  1. Navigate to Google Admin Console > Apps > Google Workspace > Gmail > Compliance
  2. Review the flagged user's filter forwarding rules
  3. Remove rules forwarding to external addresses

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high Gmail Multiple Forwarding Destinations fix difficulty: medium #

Reduce Gmail forwarding destinations to limit data exfiltration risk

  1. Navigate to Google Admin Console > Apps > Google Workspace > Gmail > Compliance
  2. Review the flagged user's forwarding destinations
  3. Remove unnecessary forwarding addresses

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high Gmail Suspicious Forwarding fix difficulty: medium #

Investigate and remove suspicious Gmail mail forwarding

  1. Navigate to Google Admin Console > Apps > Google Workspace > Gmail > Compliance
  2. Review the flagged user's accepted forwarding addresses
  3. Remove forwarding that is not authorized

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

More Google Workspace checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial