Light mode
Common Controls Baseline Report
| Customer Name | Customer Domain | Customer ID | Report Date | Baseline Version | Tool Version |
|---|---|---|---|---|---|
| Cool Example Org | example.org | ABCDEFG | 07/20/2026 12:43:08 PDT | 1 | v1.0.0 |
Policy Indicators:
- Automated CheckAutomatically verified by ScubaGoggles
- BOD 25-01 RequirementRequired by CISA BOD 25-01
- ConfigurableCustomizable via config file
- Log-Based CheckRequires log-based verification
- ManualRequires manual verification
COMMONCONTROLS-1 Phishing-Resistant Multifactor Authentication
| Control ID | Requirement | Result | Criticality | Details |
|---|---|---|---|---|
| GWS.COMMONCONTROLS.1.1v1 | Phishing-Resistant MFA SHALL be required for all users.
BOD 25-01 Requirement
Automated Check
|
Fail | Shall | The following OUs are non-compliant:
|
| GWS.COMMONCONTROLS.1.2v1 | If phishing-resistant MFA has not been enforced, an alternative MFA method SHALL be enforced for all users.
BOD 25-01 Requirement
Automated Check
|
Fail | Shall | The following OUs are non-compliant:
|
| GWS.COMMONCONTROLS.1.3v1 | SMS or Voice SHALL NOT be used as the MFA method.
BOD 25-01 Requirement
Automated Check
|
Fail | Shall | The following OUs are non-compliant:
|
| GWS.COMMONCONTROLS.1.4v1 | The Google 2-Step Verification (2SV) new user enrollment period SHALL be set to at least one day and at most one week.
BOD 25-01 Requirement
Automated Check
|
Fail | Shall | The following OUs are non-compliant:
|
| GWS.COMMONCONTROLS.1.5v1 | Allow users to trust the device SHALL be disabled.
BOD 25-01 Requirement
Automated Check
|
Fail | Shall | The following OUs are non-compliant:
|
COMMONCONTROLS-2 Context-aware Access
| Control ID | Requirement | Result | Criticality | Details |
|---|---|---|---|---|
| GWS.COMMONCONTROLS.2.1v1 | Policies restricting access to Google Workspace (GWS) based on enterprise device signals SHOULD be implemented.
Automated Check
Log-Based Check
|
No events found | Should | No relevant event in the current logs. While we are unable to determine the state from the logs, the default setting is non-compliant; manual check recommended. |
COMMONCONTROLS-3 Login Challenges
| Control ID | Requirement | Result | Criticality | Details |
|---|---|---|---|---|
| GWS.COMMONCONTROLS.3.1v1 | Post-single sign-on (SSO) verification SHOULD be enabled for users signing in using the organization's SSO profile.
Automated Check
Log-Based Check
|
No events found | Should | No relevant event in the current logs for the top-level OU, Cool Example Org. While we are unable to determine the state from the logs, the default setting is non-compliant; manual check recommended. |
| GWS.COMMONCONTROLS.3.2v1 | Post-SSO verification SHOULD be enabled for users signing in using other SSO profiles.
Automated Check
Log-Based Check
|
No events found | Should | No relevant event in the current logs for the top-level OU, Cool Example Org. While we are unable to determine the state from the logs, the default setting is non-compliant; manual check recommended. |
COMMONCONTROLS-4 User Session Duration
| Control ID | Requirement | Result | Criticality | Details |
|---|---|---|---|---|
| GWS.COMMONCONTROLS.4.1v1 | Users SHALL be forced to re-authenticate after an established 12-hour GWS login session has expired.
BOD 25-01 Requirement
Automated Check
|
Fail | Shall | The following OUs are non-compliant:
|
COMMONCONTROLS-5 Secure Passwords
| Control ID | Requirement | Result | Criticality | Details |
|---|---|---|---|---|
| GWS.COMMONCONTROLS.5.1v1 | User password strength SHALL be enforced.
BOD 25-01 Requirement
Automated Check
|
Fail | Shall | The following OUs are non-compliant:
|
| GWS.COMMONCONTROLS.5.2v1 | User password length SHALL be at least 12 characters.
BOD 25-01 Requirement
Automated Check
|
Fail | Shall | The following OUs are non-compliant:
|
| GWS.COMMONCONTROLS.5.3v1 | User password length SHOULD be at least 16 characters.
Automated Check
|
Warning | Should | The following OUs are non-compliant:
|
| GWS.COMMONCONTROLS.5.4v1 | Password policy SHALL be enforced at next sign-in.
BOD 25-01 Requirement
Automated Check
|
Fail | Shall | The following OUs are non-compliant:
|
| GWS.COMMONCONTROLS.5.5v1 | User passwords SHALL NOT be reused.
BOD 25-01 Requirement
Automated Check
|
Fail | Shall | The following OUs are non-compliant:
|
| GWS.COMMONCONTROLS.5.6v1 | User passwords SHALL NOT expire.
BOD 25-01 Requirement
Automated Check
|
Fail | Shall | The following OUs are non-compliant:
|
COMMONCONTROLS-6 Privileged Accounts
| Control ID | Requirement | Result | Criticality | Details |
|---|---|---|---|---|
| GWS.COMMONCONTROLS.6.1v1 | All administrative accounts SHALL be provisioned as cloud-only accounts separate from an agency's authoritative on-premises or other federated identity providers.
BOD 25-01 Requirement
Automated Check
|
Fail | Shall | The following OUs are non-compliant:
|
| GWS.COMMONCONTROLS.6.2v1 | A minimum of **two** and a maximum of **eight** separate and distinct super admin users SHALL be configured.
BOD 25-01 Requirement
Automated Check
Configurable
|
Fail | Shall | The following super admins are configured: chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net, chenrichard@example.net. Note: Exceptions are allowed for "break glass" super admin accounts. "Break glass" accounts can be specified in a config file. 0 break glass accounts are currently configured. |
COMMONCONTROLS-7 Conflicting Account Management
| Control ID | Requirement | Result | Criticality | Details |
|---|---|---|---|---|
| GWS.COMMONCONTROLS.7.1v1 | Account conflict management SHOULD be configured to replace conflicting unmanaged accounts with managed accounts.
Manual
|
N/A | Should/Not-Implemented | Currently not able to be tested automatically; please manually check. |
COMMONCONTROLS-8 Account Recovery Options
| Control ID | Requirement | Result | Criticality | Details |
|---|---|---|---|---|
| GWS.COMMONCONTROLS.8.1v1 | Account self-recovery for super admins SHALL be disabled.
BOD 25-01 Requirement
Automated Check
|
Fail | Shall | The following OUs are non-compliant:
|
| GWS.COMMONCONTROLS.8.2v1 | Account self-recovery for users and non-super admins SHALL be disabled.
BOD 25-01 Requirement
Automated Check
|
Fail | Shall | The following OUs are non-compliant:
|
| GWS.COMMONCONTROLS.8.3v1 | Ability to add recovery information SHOULD be disabled.
Manual
|
N/A | Should/Not-Implemented | Currently not able to be tested automatically; please manually check. |
COMMONCONTROLS-9 GWS Advanced Protection Program
| Control ID | Requirement | Result | Criticality | Details |
|---|---|---|---|---|
| GWS.COMMONCONTROLS.9.1v1 | Highly privileged accounts SHALL be enrolled in the Google Workspace (GWS) Advanced Protection Program.
Manual
|
N/A | Shall/Not-Implemented | Currently not able to be tested automatically; please manually check. |
| GWS.COMMONCONTROLS.9.2v1 | All sensitive user accounts SHOULD be enrolled into the GWS Advanced Protection Program.
Manual
|
N/A | Should/Not-Implemented | Currently not able to be tested automatically; please manually check. |
COMMONCONTROLS-10 App Access to Google APIs
| Control ID | Requirement | Result | Criticality | Details |
|---|---|---|---|---|
| GWS.COMMONCONTROLS.10.1v1 | Agencies SHALL use GWS application access control policies to restrict access to all GWS services by third-party applications.
BOD 25-01 Requirement
Automated Check
|
Pass | Shall | Requirement met. |
| GWS.COMMONCONTROLS.10.2v1 | Agencies SHALL NOT allow users to grant consent for access to low-risk scopes.
BOD 25-01 Requirement
Automated Check
|
Pass | Shall | Requirement met. |
| GWS.COMMONCONTROLS.10.3v1 | Agencies SHALL NOT trust unconfigured internal applications.
BOD 25-01 Requirement
Automated Check
|
Pass | Shall | Requirement met. |
| GWS.COMMONCONTROLS.10.4v1 | Agencies SHALL NOT allow users to access unconfigured third-party applications.
BOD 25-01 Requirement
Automated Check
|
Pass | Shall | Requirement met. |
| GWS.COMMONCONTROLS.10.5v1 | Access to GWS applications by less secure applications that do not meet security authentication standards SHALL be prevented.
BOD 25-01 Requirement
Automated Check
|
Fail | Shall | The following OUs are non-compliant:
|
COMMONCONTROLS-11 Authorized Google Marketplace Apps
| Control ID | Requirement | Result | Criticality | Details |
|---|---|---|---|---|
| GWS.COMMONCONTROLS.11.1v1 | Only approved Google Workspace (GWS) Marketplace applications SHALL be allowed for installation.
BOD 25-01 Requirement
Automated Check
|
Fail | Shall | The following OUs are non-compliant:
|
COMMONCONTROLS-12 Google Takeout Services for Users
| Control ID | Requirement | Result | Criticality | Details |
|---|---|---|---|---|
| GWS.COMMONCONTROLS.12.1v1 | Google Takeout services SHALL be disabled.
BOD 25-01 Requirement
Automated Check
|
Fail | Shall | The following OUs are non-compliant:
|
COMMONCONTROLS-13 System-defined Rules
| Control ID | Requirement | Result | Criticality | Details |
|---|---|---|---|---|
| GWS.COMMONCONTROLS.13.1v1 | Required system-defined alerting rules, as listed in the policy group description, SHALL be enabled with alerts.
BOD 25-01 Requirement
Automated Check
|
Fail | Shall | Of the 30 required rules, 29 are enabled and 1 is disabled. See System Defined Alerts for more details. |
COMMONCONTROLS-14 Google Workspace Logs
| Control ID | Requirement | Result | Criticality | Details |
|---|---|---|---|---|
| GWS.COMMONCONTROLS.14.1v1 | The following critical logs SHALL be sent to the agency's centralized SIEM.
Manual
|
N/A | Shall/Not-Implemented | Currently not able to be tested automatically; please manually check. |
| GWS.COMMONCONTROLS.14.2v1 | Audit logs SHALL be retained and searchable for a minimum of 3 months and retrievable for a minimum of 12 months.
Manual
|
N/A | Shall/Not-Implemented | Currently not able to be tested automatically; please manually check. |
COMMONCONTROLS-15 Data Regions and Storage
| Control ID | Requirement | Result | Criticality | Details |
|---|---|---|---|---|
| GWS.COMMONCONTROLS.15.1v1 | The data storage region SHALL be set to be the United States for all users in the agency's GWS environment.
BOD 25-01 Requirement
Automated Check
|
Pass | Shall | Requirement met. |
| GWS.COMMONCONTROLS.15.2v1 | Data SHALL be processed in the region selected for data at rest.
BOD 25-01 Requirement
Automated Check
|
Pass | Should | Requirement met. |
COMMONCONTROLS-16 Additional Google Services
| Control ID | Requirement | Result | Criticality | Details |
|---|---|---|---|---|
| GWS.COMMONCONTROLS.16.1v1 | Service status for Google services that do not have an individual control SHOULD be set to OFF for everyone.
Automated Check
|
Warning | Should | The following OUs are non-compliant:
|
| GWS.COMMONCONTROLS.16.2v1 | User access to Early Access applications SHOULD be disabled.
Automated Check
|
Warning | Should | The following OUs are non-compliant:
|
| GWS.COMMONCONTROLS.16.3v1 | Looker Studio Sharing outside org SHOULD be set to OFF.
Automated Check
|
N/A | Shall/Not-Implemented | Currently not able to be tested automatically; please manually check. |
| GWS.COMMONCONTROLS.16.4v1 | Pinpoint access to drive SHOULD be set to OFF.
Automated Check
|
N/A | Shall/Not-Implemented | Currently not able to be tested automatically; please manually check. |
COMMONCONTROLS-17 Multi-Party Approval
| Control ID | Requirement | Result | Criticality | Details |
|---|---|---|---|---|
| GWS.COMMONCONTROLS.17.1v1 | Require multi-party approval for sensitive admin actions SHOULD be enabled.
Automated Check
Log-Based Check
|
Warning | Should | The following OUs are non-compliant:
|
COMMONCONTROLS-18 Data Loss Prevention
| Control ID | Requirement | Result | Criticality | Details |
|---|---|---|---|---|
| GWS.COMMONCONTROLS.18.1v1 | A custom policy SHALL be configured for Google Drive, Google Calendar, Google Chat, and Gmail to protect PII and sensitive information as defined by the agency, covering at a minimum: credit card numbers, U.S. Individual Taxpayer Identification Numbers (ITIN), and U.S. Social Security numbers (SSN).
Manual
|
N/A | Shall/Not-Implemented | Currently not able to be tested automatically; please manually check. |
| GWS.COMMONCONTROLS.18.2v1 | The action for DLP policies SHOULD be set to block.
Manual
|
N/A | Should/Not-Implemented | Currently not able to be tested automatically; please manually check. |
Tenant Licensing Information
| Product Name | Status | Assigned Licenses |
|---|---|---|
| Google Workspace Enterprise Plus | Active | 101 |
| Gemini Enterprise - Legacy | Active | 50 |
| Cloud Identity Free | Active | 101 |
| Google Workspace Assured Controls Plus | Active | 50 |
System Defined Alerts
| Alert Name | Description | Status |
|---|---|---|
| Account suspension warning | Google Workspace accounts engaging in suspicious activity may have their account suspended. Google Workspace accounts must comply with the Google Workspace Terms of Service, Google Workspace for Education Terms of Service, Google Cloud Platform Terms of Service or Cloud Identity Terms of Service. | Enabled |
| Calendar settings changed | An admin has changed Google Workspace Calendar settings. | Enabled |
| Device compromised | Provides details about devices in your domain that have entered a compromised state. | Enabled |
| Domain data export initiated | A Super Administrator for your Google account has started exporting data from your domain. | Enabled |
| Drive settings changed | An admin has changed Google Workspace Drive settings. | Enabled |
| Email settings changed | An admin has changed Google Workspace Gmail settings. | Enabled |
| Gmail potential employee spoofing | Incoming messages where a sender's name is in your Google Workspace directory, but the mail is not from your company's domains or domain aliases. | Enabled |
| Google Operations | Provides details about security and privacy issues that affect your Google Workspace services. | Enabled |
| Government-backed attacks | Warnings about potential government-backed attacks. | Enabled |
| Leaked password | Google detected compromised credentials requiring a reset of the user's password. | Enabled |
| Malware message detected post-delivery | Messages detected as malware post-delivery that are automatically reclassified. | Enabled |
| Mobile settings changed | An admin has changed mobile management settings. | Enabled |
| Phishing in inboxes due to bad whitelist | Messages classified as spam by Gmail filters delivered to user inboxes due to whitelisting settings in the Google Admin console that override the spam filters. | Enabled |
| Phishing message detected post-delivery | Messages detected as phishing post-delivery that are automatically reclassified. | Enabled |
| Rate limited recipient | A high rate of incoming email indicating a potential malicious attack or misconfigured setting. | Enabled |
| SSO profile added | Alerts you when a new SSO profile allows users to sign in to Google services through your third-party identity provider. | Enabled |
| SSO profile updated | Alerts you when there's a change to the SSO profile that allows users to sign in to Google services through your third-party identity provider. | Enabled |
| Spike in user-reported spam | An unusually high volume of messages from a sender that users have marked as spam. | Enabled |
| Super admin password reset | Alerts you when the password for a super admin account changes. This admin can manage all features in your Admin console and Admin APIs. | Enabled |
| Suspicious device activity | Provides details if device properties such as device ID, serial number, type of device, or device manufacturer are updated. | Enabled |
| Suspicious login | Google detected a sign-in attempt that doesn't match a user's normal behavior, such as a sign-in from an unusual location. | Enabled |
| Suspicious message reported | A sender has sent messages to your domain that users have classified as spam. | Enabled |
| Suspicious programmatic login | Google detected suspicious login attempts from potential applications or computer programs. | Enabled |
| User granted Admin privilege | A user is granted an admin privilege. | Enabled |
| User suspended (Google identity alert) | Google detected suspicious activity and suspended the account. | Enabled |
| User suspended due to suspicious activity | Google suspended a user's account due to a potential compromise detected. | Disabled |
| User suspended for spamming | Google detected suspicious activity such as spamming and suspended the account. | Enabled |
| User suspended for spamming through relay | Google detected suspicious activity such as spamming through a SMTP relay service and suspended the account. | Enabled |
| User's Admin privilege revoked | A user is revoked of their admin privilege. | Enabled |
| User-reported phishing | A sender has sent messages to your domain that users have classified as phishings. | Enabled |