Cybersecurity and Infrastructure Security Agency Logo

Light mode

Common Controls Baseline Report

Customer Name Customer Domain Customer ID Report Date Baseline Version Tool Version
Cool Example Org example.org ABCDEFG 07/20/2026 12:43:08 PDT 1 v1.0.0
Policy Indicators:

COMMONCONTROLS-1 Phishing-Resistant Multifactor Authentication

Control ID Requirement Result Criticality Details
GWS.COMMONCONTROLS.1.1v1 Phishing-Resistant MFA SHALL be required for all users.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • 2SV Exempt: 2-step verification (2SV) is not enforced.
  • Jeffrey Burns's OU: Allowed 2-step verification (2SV) method is set to "Any".
  • Anna White's OU: Allowed 2-step verification (2SV) method is set to "Any except verification codes via text, phone call".
  • Anna White's OU v2: 2-step verification (2SV) is not enforced.
  • Cool Example Org: Allowed 2-step verification (2SV) method is set to "Any".
  • Cool Example Org (group WORKSPACE_ALL_ADMIN_GROUP): 2-step verification (2SV) is not enforced.
  • Cool Example Org (group chenrichard@example.net): Allowed 2-step verification (2SV) method is set to "Any".
  • Christina Garcia's OU (in Jeffrey Burns's OU): 2-step verification (2SV) is not enforced.
  • Mark Duncan's OU: Users cannot enable 2-step verification (2SV).
  • Kimberly Shelton's OU: Allowed 2-step verification (2SV) method is set to "Any".
GWS.COMMONCONTROLS.1.2v1 If phishing-resistant MFA has not been enforced, an alternative MFA method SHALL be enforced for all users.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • 2SV Exempt: 2-step verification (2SV) is not enforced.
  • Anna White's OU v2: 2-step verification (2SV) is not enforced.
  • Cool Example Org (group WORKSPACE_ALL_ADMIN_GROUP): 2-step verification (2SV) is not enforced.
  • Christina Garcia's OU (in Jeffrey Burns's OU): 2-step verification (2SV) is not enforced.
  • Mark Duncan's OU: Users cannot enable 2-step verification (2SV).
GWS.COMMONCONTROLS.1.3v1 SMS or Voice SHALL NOT be used as the MFA method.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • 2SV Exempt: 2-step verification (2SV) is not enforced.
  • Jeffrey Burns's OU: Verification codes via text and phone call allowed.
  • Anna White's OU v2: 2-step verification (2SV) is not enforced.
  • Cool Example Org: Verification codes via text and phone call allowed.
  • Cool Example Org (group WORKSPACE_ALL_ADMIN_GROUP): 2-step verification (2SV) is not enforced.
  • Cool Example Org (group chenrichard@example.net): Verification codes via text and phone call allowed.
  • Christina Garcia's OU (in Jeffrey Burns's OU): 2-step verification (2SV) is not enforced.
  • Mark Duncan's OU: Users cannot enable 2-step verification (2SV).
  • Kimberly Shelton's OU: Verification codes via text and phone call allowed.
GWS.COMMONCONTROLS.1.4v1 The Google 2-Step Verification (2SV) new user enrollment period SHALL be set to at least one day and at most one week.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • 2SV Exempt: 2-step verification (2SV) is not enforced.
  • Jeffrey Burns's OU: New user enrollment period 180 days (longer than 7 days)
  • Anna White's OU v2: 2-step verification (2SV) is not enforced.
  • Cool Example Org (group WORKSPACE_ALL_ADMIN_GROUP): 2-step verification (2SV) is not enforced.
  • Cool Example Org (group chenrichard@example.net): New user enrollment period is NONE
  • Christina Garcia's OU (in Jeffrey Burns's OU): 2-step verification (2SV) is not enforced.
  • Mark Duncan's OU: Users cannot enable 2-step verification (2SV).
GWS.COMMONCONTROLS.1.5v1 Allow users to trust the device SHALL be disabled.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • 2SV Exempt: 2-step verification (2SV) is not enforced.
  • Jeffrey Burns's OU: User is allowed to trust device.
  • Anna White's OU: User is allowed to trust device.
  • Anna White's OU v2: 2-step verification (2SV) is not enforced.
  • Cool Example Org: User is allowed to trust device.
  • Cool Example Org (group WORKSPACE_ALL_ADMIN_GROUP): 2-step verification (2SV) is not enforced.
  • Cool Example Org (group chenrichard@example.net): User is allowed to trust device.
  • Christina Garcia's OU (in Jeffrey Burns's OU): 2-step verification (2SV) is not enforced.
  • Mark Duncan's OU: Users cannot enable 2-step verification (2SV).
  • Kimberly Shelton's OU: User is allowed to trust device.

COMMONCONTROLS-2 Context-aware Access

Control ID Requirement Result Criticality Details
GWS.COMMONCONTROLS.2.1v1 Policies restricting access to Google Workspace (GWS) based on enterprise device signals SHOULD be implemented.
Automated Check Log-Based Check
No events found Should No relevant event in the current logs. While we are unable to determine the state from the logs, the default setting is non-compliant; manual check recommended.

COMMONCONTROLS-3 Login Challenges

Control ID Requirement Result Criticality Details
GWS.COMMONCONTROLS.3.1v1 Post-single sign-on (SSO) verification SHOULD be enabled for users signing in using the organization's SSO profile.
Automated Check Log-Based Check
No events found Should No relevant event in the current logs for the top-level OU, Cool Example Org. While we are unable to determine the state from the logs, the default setting is non-compliant; manual check recommended.

GWS.COMMONCONTROLS.3.2v1 Post-SSO verification SHOULD be enabled for users signing in using other SSO profiles.
Automated Check Log-Based Check
No events found Should No relevant event in the current logs for the top-level OU, Cool Example Org. While we are unable to determine the state from the logs, the default setting is non-compliant; manual check recommended.

COMMONCONTROLS-4 User Session Duration

Control ID Requirement Result Criticality Details
GWS.COMMONCONTROLS.4.1v1 Users SHALL be forced to re-authenticate after an established 12-hour GWS login session has expired.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • Anna White's OU: Web session duration: 24 hours
  • Kimberly Shelton's OU: Web session duration: 20 hours

COMMONCONTROLS-5 Secure Passwords

Control ID Requirement Result Criticality Details
GWS.COMMONCONTROLS.5.1v1 User password strength SHALL be enforced.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • Cool Example Org: Password strength is WEAK, not STRONG
GWS.COMMONCONTROLS.5.2v1 User password length SHALL be at least 12 characters.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • Anna White's OU: Minimum password length: 8, less than 12
GWS.COMMONCONTROLS.5.3v1 User password length SHOULD be at least 16 characters.
Automated Check
Warning Should The following OUs are non-compliant:
  • 2SV Exempt: Minimum password length: 12, recommended is at least 16
  • Jeffrey Burns's OU: Minimum password length: 12, recommended is at least 16
  • Anna White's OU: Minimum password length: 8, recommended is at least 16
  • Cool Example Org: Minimum password length: 12, recommended is at least 16
  • Troy Arnold's OU: Minimum password length: 15, recommended is at least 16
  • Kimberly Shelton's OU: Minimum password length: 12, recommended is at least 16
GWS.COMMONCONTROLS.5.4v1 Password policy SHALL be enforced at next sign-in.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • 2SV Exempt: Enforce password policy at next sign-in is OFF
  • Anna White's OU: Enforce password policy at next sign-in is OFF
  • Cool Example Org: Enforce password policy at next sign-in is OFF
  • Troy Arnold's OU: Enforce password policy at next sign-in is OFF
GWS.COMMONCONTROLS.5.5v1 User passwords SHALL NOT be reused.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • Jeffrey Burns's OU: Allow password reuse is ON
  • Anna White's OU: Allow password reuse is ON
GWS.COMMONCONTROLS.5.6v1 User passwords SHALL NOT expire.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • Jeffrey Burns's OU: Password reset frequency is 30 days
  • Anna White's OU: Password reset frequency is 5184000 seconds

COMMONCONTROLS-6 Privileged Accounts

Control ID Requirement Result Criticality Details
GWS.COMMONCONTROLS.6.1v1 All administrative accounts SHALL be provisioned as cloud-only accounts separate from an agency's authoritative on-premises or other federated identity providers.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • Cool Example Org: SSO is enabled for an OU containing privileged accounts. Privileged accounts must authenticate via Google Workspace, not via an external identity provider.
  • Erica Little's OU: SSO is enabled for an OU containing privileged accounts. Privileged accounts must authenticate via Google Workspace, not via an external identity provider.
GWS.COMMONCONTROLS.6.2v1 A minimum of **two** and a maximum of **eight** separate and distinct super admin users SHALL be configured.
BOD 25-01 Requirement Automated Check Configurable
Fail Shall The following super admins are configured: chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net. Note: Exceptions are allowed for "break glass" super admin accounts. "Break glass" accounts can be specified in a config file. 0 break glass accounts are currently configured.

COMMONCONTROLS-7 Conflicting Account Management

Control ID Requirement Result Criticality Details
GWS.COMMONCONTROLS.7.1v1 Account conflict management SHOULD be configured to replace conflicting unmanaged accounts with managed accounts.
Manual
N/A Should/Not-Implemented Currently not able to be tested automatically; please manually check.

COMMONCONTROLS-8 Account Recovery Options

Control ID Requirement Result Criticality Details
GWS.COMMONCONTROLS.8.1v1 Account self-recovery for super admins SHALL be disabled.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • Cool Example Org (group chenrichard@example.net): Super admins are allowed to recover their accounts.
  • Cool Example Org (group chenrichard@example.net): Super admins are allowed to recover their accounts.
GWS.COMMONCONTROLS.8.2v1 Account self-recovery for users and non-super admins SHALL be disabled.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • Cool Example Org: Users and non-super admins are allowed to recover their accounts.
GWS.COMMONCONTROLS.8.3v1 Ability to add recovery information SHOULD be disabled.
Manual
N/A Should/Not-Implemented Currently not able to be tested automatically; please manually check.

COMMONCONTROLS-9 GWS Advanced Protection Program

Control ID Requirement Result Criticality Details
GWS.COMMONCONTROLS.9.1v1 Highly privileged accounts SHALL be enrolled in the Google Workspace (GWS) Advanced Protection Program.
Manual
N/A Shall/Not-Implemented Currently not able to be tested automatically; please manually check.
GWS.COMMONCONTROLS.9.2v1 All sensitive user accounts SHOULD be enrolled into the GWS Advanced Protection Program.
Manual
N/A Should/Not-Implemented Currently not able to be tested automatically; please manually check.

COMMONCONTROLS-10 App Access to Google APIs

Control ID Requirement Result Criticality Details
GWS.COMMONCONTROLS.10.1v1 Agencies SHALL use GWS application access control policies to restrict access to all GWS services by third-party applications.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.
GWS.COMMONCONTROLS.10.2v1 Agencies SHALL NOT allow users to grant consent for access to low-risk scopes.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.
GWS.COMMONCONTROLS.10.3v1 Agencies SHALL NOT trust unconfigured internal applications.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.
GWS.COMMONCONTROLS.10.4v1 Agencies SHALL NOT allow users to access unconfigured third-party applications.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.
GWS.COMMONCONTROLS.10.5v1 Access to GWS applications by less secure applications that do not meet security authentication standards SHALL be prevented.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • Cool Example Org: Users are allowed to manage access to less secure apps.

COMMONCONTROLS-11 Authorized Google Marketplace Apps

Control ID Requirement Result Criticality Details
GWS.COMMONCONTROLS.11.1v1 Only approved Google Workspace (GWS) Marketplace applications SHALL be allowed for installation.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • Troy Arnold's OU: Users can install and run any internal app, even if it's not allowlisted.

COMMONCONTROLS-12 Google Takeout Services for Users

Control ID Requirement Result Criticality Details
GWS.COMMONCONTROLS.12.1v1 Google Takeout services SHALL be disabled.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • Jeffrey Burns's OU: The following apps with individual admin control have Takeout enabled: YouTube
  • Cool Example Org: Takeout is enabled for services without an individual admin control.
  • Cool Example Org: The following apps with individual admin control have Takeout enabled: Blogger, Google Books, Timeline - Location History

COMMONCONTROLS-13 System-defined Rules

Control ID Requirement Result Criticality Details
GWS.COMMONCONTROLS.13.1v1 Required system-defined alerting rules, as listed in the policy group description, SHALL be enabled with alerts.
BOD 25-01 Requirement Automated Check
Fail Shall Of the 30 required rules, 29 are enabled and 1 is disabled. See System Defined Alerts for more details.

COMMONCONTROLS-14 Google Workspace Logs

Control ID Requirement Result Criticality Details
GWS.COMMONCONTROLS.14.1v1 The following critical logs SHALL be sent to the agency's centralized SIEM.
Manual
N/A Shall/Not-Implemented Currently not able to be tested automatically; please manually check.
GWS.COMMONCONTROLS.14.2v1 Audit logs SHALL be retained and searchable for a minimum of 3 months and retrievable for a minimum of 12 months.
Manual
N/A Shall/Not-Implemented Currently not able to be tested automatically; please manually check.

COMMONCONTROLS-15 Data Regions and Storage

Control ID Requirement Result Criticality Details
GWS.COMMONCONTROLS.15.1v1 The data storage region SHALL be set to be the United States for all users in the agency's GWS environment.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.
GWS.COMMONCONTROLS.15.2v1 Data SHALL be processed in the region selected for data at rest.
BOD 25-01 Requirement Automated Check
Pass Should Requirement met.

COMMONCONTROLS-16 Additional Google Services

Control ID Requirement Result Criticality Details
GWS.COMMONCONTROLS.16.1v1 Service status for Google services that do not have an individual control SHOULD be set to OFF for everyone.
Automated Check
Warning Should The following OUs are non-compliant:
  • Cool Example Org: Access to additional services without individual control is ON
GWS.COMMONCONTROLS.16.2v1 User access to Early Access applications SHOULD be disabled.
Automated Check
Warning Should The following OUs are non-compliant:
  • Cool Example Org: Early access apps are ENABLED
GWS.COMMONCONTROLS.16.3v1 Looker Studio Sharing outside org SHOULD be set to OFF.
Automated Check
N/A Shall/Not-Implemented Currently not able to be tested automatically; please manually check.
GWS.COMMONCONTROLS.16.4v1 Pinpoint access to drive SHOULD be set to OFF.
Automated Check
N/A Shall/Not-Implemented Currently not able to be tested automatically; please manually check.

COMMONCONTROLS-17 Multi-Party Approval

Control ID Requirement Result Criticality Details
GWS.COMMONCONTROLS.17.1v1 Require multi-party approval for sensitive admin actions SHOULD be enabled.
Automated Check Log-Based Check
Warning Should The following OUs are non-compliant:
  • Cool Example Org: Require multi party approval for sensitive admin actions is DISABLED

COMMONCONTROLS-18 Data Loss Prevention

Control ID Requirement Result Criticality Details
GWS.COMMONCONTROLS.18.1v1 A custom policy SHALL be configured for Google Drive, Google Calendar, Google Chat, and Gmail to protect PII and sensitive information as defined by the agency, covering at a minimum: credit card numbers, U.S. Individual Taxpayer Identification Numbers (ITIN), and U.S. Social Security numbers (SSN).
Manual
N/A Shall/Not-Implemented Currently not able to be tested automatically; please manually check.
GWS.COMMONCONTROLS.18.2v1 The action for DLP policies SHOULD be set to block.
Manual
N/A Should/Not-Implemented Currently not able to be tested automatically; please manually check.

Tenant Licensing Information

Product Name Status Assigned Licenses
Google Workspace Enterprise Plus Active 101
Gemini Enterprise - Legacy Active 50
Cloud Identity Free Active 101
Google Workspace Assured Controls Plus Active 50

System Defined Alerts

Alert Name Description Status
Account suspension warning Google Workspace accounts engaging in suspicious activity may have their account suspended. Google Workspace accounts must comply with the Google Workspace Terms of Service, Google Workspace for Education Terms of Service, Google Cloud Platform Terms of Service or Cloud Identity Terms of Service. Enabled
Calendar settings changed An admin has changed Google Workspace Calendar settings. Enabled
Device compromised Provides details about devices in your domain that have entered a compromised state. Enabled
Domain data export initiated A Super Administrator for your Google account has started exporting data from your domain. Enabled
Drive settings changed An admin has changed Google Workspace Drive settings. Enabled
Email settings changed An admin has changed Google Workspace Gmail settings. Enabled
Gmail potential employee spoofing Incoming messages where a sender's name is in your Google Workspace directory, but the mail is not from your company's domains or domain aliases. Enabled
Google Operations Provides details about security and privacy issues that affect your Google Workspace services. Enabled
Government-backed attacks Warnings about potential government-backed attacks. Enabled
Leaked password Google detected compromised credentials requiring a reset of the user's password. Enabled
Malware message detected post-delivery Messages detected as malware post-delivery that are automatically reclassified. Enabled
Mobile settings changed An admin has changed mobile management settings. Enabled
Phishing in inboxes due to bad whitelist Messages classified as spam by Gmail filters delivered to user inboxes due to whitelisting settings in the Google Admin console that override the spam filters. Enabled
Phishing message detected post-delivery Messages detected as phishing post-delivery that are automatically reclassified. Enabled
Rate limited recipient A high rate of incoming email indicating a potential malicious attack or misconfigured setting. Enabled
SSO profile added Alerts you when a new SSO profile allows users to sign in to Google services through your third-party identity provider. Enabled
SSO profile updated Alerts you when there's a change to the SSO profile that allows users to sign in to Google services through your third-party identity provider. Enabled
Spike in user-reported spam An unusually high volume of messages from a sender that users have marked as spam. Enabled
Super admin password reset Alerts you when the password for a super admin account changes. This admin can manage all features in your Admin console and Admin APIs. Enabled
Suspicious device activity Provides details if device properties such as device ID, serial number, type of device, or device manufacturer are updated. Enabled
Suspicious login Google detected a sign-in attempt that doesn't match a user's normal behavior, such as a sign-in from an unusual location. Enabled
Suspicious message reported A sender has sent messages to your domain that users have classified as spam. Enabled
Suspicious programmatic login Google detected suspicious login attempts from potential applications or computer programs. Enabled
User granted Admin privilege A user is granted an admin privilege. Enabled
User suspended (Google identity alert) Google detected suspicious activity and suspended the account. Enabled
User suspended due to suspicious activity Google suspended a user's account due to a potential compromise detected. Disabled
User suspended for spamming Google detected suspicious activity such as spamming and suspended the account. Enabled
User suspended for spamming through relay Google detected suspicious activity such as spamming through a SMTP relay service and suspended the account. Enabled
User's Admin privilege revoked A user is revoked of their admin privilege. Enabled
User-reported phishing A sender has sent messages to your domain that users have classified as phishings. Enabled