Cybersecurity and Infrastructure Security Agency Logo

Light mode

Groups for Business Baseline Report

Customer Name Customer Domain Customer ID Report Date Baseline Version Tool Version
Cool Example Org example.org ABCDEFG 07/20/2026 12:43:08 PDT 1 v1.0.0
Policy Indicators:

GROUPS-1 External Group Access

Control ID Requirement Result Criticality Details
GWS.GROUPS.1.1v1 Group access from outside the organization SHALL be disabled unless explicitly granted by the group owner.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.
GWS.GROUPS.1.2v1 Group owners' ability to add external members to groups SHOULD be disabled unless necessary for agency mission fulfillment.
Automated Check
Pass Should Requirement met.
GWS.GROUPS.1.3v1 Group owners' ability to allow external, non-group members to post in the group SHOULD be disabled unless necessary for agency mission fulfillment.
Automated Check
Pass Should Requirement met.

GROUPS-2 Group Creation

Control ID Requirement Result Criticality Details
GWS.GROUPS.2.1v1 Group creation SHOULD be restricted to administrators within the organization unless alternative creators are necessary for agency mission fulfillment.
Automated Check
Pass Should Requirement met.

GROUPS-3 Default Permissions for Viewing Conversations

Control ID Requirement Result Criticality Details
GWS.GROUPS.3.1v1 The default permission to view conversations SHOULD be set to "All group members."
Automated Check
Pass Should Requirement met.

GROUPS-4 Ability to Hide Groups from the Directory

Control ID Requirement Result Criticality Details
GWS.GROUPS.4.1v1 The ability for groups to be hidden from the directory SHALL be disabled.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • Cool Example Org: New groups may be hidden