EMAIL-024: Gmail Security Sandbox enabled (GWS.GMAIL.16.1)
- Platform
- Google Workspace
- Category
- Advanced Threat Protection
- Severity
- Medium
- Zero Trust pillar
- Applications & Workloads (weight 2)
- Golden fixtures
- 4
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
SCuBA GWS.GMAIL.16.1 recommends enabling the Gmail Security Sandbox, which detonates inbound attachments in a virtual environment to detect zero-day malware that signature scanning misses. This check reads the gmail.security_sandbox policy from the Cloud Identity Policy API and flags organizational units where the sandbox is disabled. The exact policy field is best-effort pending confirmation on a licensed tenant; when the policy is not returned the result is Not Assessed rather than a fabricated verdict.
Recommended value
Security Sandbox enabled (virtual attachment detonation) for all organizational units
Remediation
In the Google Admin console under Apps > Google Workspace > Gmail > Safety > Attachments, enable Security Sandbox so inbound attachments are detonated in a virtual environment before delivery. Note Security Sandbox requires the appropriate Google Workspace edition.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| no-data | Not Assessed |
| no-policy | Not Assessed |
Framework mappings
- CISA SCuBA
- GWS.GMAIL.16.1v1
- NIST SP 800-53
- SI-3, SC-44