EMAIL-019: DLP Rules Configuration

Platform
Google Workspace
Category
Advanced Threat Protection
Severity
Medium
Zero Trust pillar
Applications & Workloads (weight 1)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Data Loss Prevention (DLP) rules should be configured to detect and prevent sensitive data from leaving the organization via email. DLP provides automated content inspection and policy enforcement

Recommended value

DLP rules configured for key data types (credit cards, SSNs, health records) with block or warn action

Remediation

Security > Data protection > Manage rules: create a Gmail DLP rule that detects sensitive content patterns (credit cards, SSNs, health records) and applies a block or warn action

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EMAIL-019
ScenarioExpected verdict
cleanPASS
known-badWARN
no-dataNot Assessed

Framework mappings

NIST SP 800-53
AC-4, SC-7, SI-4
CIS Benchmark
2.19
MITRE ATT&CK
T1048, T1567, T1020