EMAIL-019: DLP Rules Configuration
- Platform
- Google Workspace
- Category
- Advanced Threat Protection
- Severity
- Medium
- Zero Trust pillar
- Applications & Workloads (weight 1)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
Data Loss Prevention (DLP) rules should be configured to detect and prevent sensitive data from leaving the organization via email. DLP provides automated content inspection and policy enforcement
Recommended value
DLP rules configured for key data types (credit cards, SSNs, health records) with block or warn action
Remediation
Security > Data protection > Manage rules: create a Gmail DLP rule that detects sensitive content patterns (credit cards, SSNs, health records) and applies a block or warn action
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | WARN |
| no-data | Not Assessed |
Framework mappings
- NIST SP 800-53
- AC-4, SC-7, SI-4
- CIS Benchmark
- 2.19
- MITRE ATT&CK
- T1048, T1567, T1020