EMAIL-015: Attachment Safety Settings
- Platform
- Google Workspace
- Category
- Advanced Threat Protection
- Severity
- High
- Zero Trust pillar
- Applications & Workloads (weight 2)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
All attachment safety protections should be enabled to detect and block malicious file attachments including encrypted archives, anomalous file types, and scripts
Recommended value
All attachment protection options enabled with quarantine action
Remediation
Admin Console > Apps > Google Workspace > Gmail > Safety > Attachments > Enable all protections: encrypted attachments, scripts from untrusted senders, and anomalous attachment types
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | WARN |
| no-data | Not Assessed |
Framework mappings
- NIST SP 800-53
- SI-3, SI-8
- CIS Benchmark
- 2.15
- CISA SCuBA
- GWS.GMAIL.5.1v1, GWS.GMAIL.5.2v1, GWS.GMAIL.5.3v1, GWS.GMAIL.5.4v1
- MITRE ATT&CK
- T1566.001, T1204.002