EMAIL-015: Attachment Safety Settings

Platform
Google Workspace
Category
Advanced Threat Protection
Severity
High
Zero Trust pillar
Applications & Workloads (weight 2)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

All attachment safety protections should be enabled to detect and block malicious file attachments including encrypted archives, anomalous file types, and scripts

Recommended value

All attachment protection options enabled with quarantine action

Remediation

Admin Console > Apps > Google Workspace > Gmail > Safety > Attachments > Enable all protections: encrypted attachments, scripts from untrusted senders, and anomalous attachment types

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EMAIL-015
ScenarioExpected verdict
cleanPASS
known-badWARN
no-dataNot Assessed

Framework mappings

NIST SP 800-53
SI-3, SI-8
CIS Benchmark
2.15
CISA SCuBA
GWS.GMAIL.5.1v1, GWS.GMAIL.5.2v1, GWS.GMAIL.5.3v1, GWS.GMAIL.5.4v1
MITRE ATT&CK
T1566.001, T1204.002