EMAIL-024: Gmail Security Sandbox enabled (GWS.GMAIL.16.1)

Platform
Google Workspace
Category
Advanced Threat Protection
Severity
Medium
Zero Trust pillar
Applications & Workloads (weight 2)
Golden fixtures
4
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA GWS.GMAIL.16.1 recommends enabling the Gmail Security Sandbox, which detonates inbound attachments in a virtual environment to detect zero-day malware that signature scanning misses. This check reads the gmail.security_sandbox policy from the Cloud Identity Policy API and flags organizational units where the sandbox is disabled. The exact policy field is best-effort pending confirmation on a licensed tenant; when the policy is not returned the result is Not Assessed rather than a fabricated verdict.

Recommended value

Security Sandbox enabled (virtual attachment detonation) for all organizational units

Remediation

In the Google Admin console under Apps > Google Workspace > Gmail > Safety > Attachments, enable Security Sandbox so inbound attachments are detonated in a virtual environment before delivery. Note Security Sandbox requires the appropriate Google Workspace edition.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EMAIL-024
ScenarioExpected verdict
cleanPASS
known-badFAIL
no-dataNot Assessed
no-policyNot Assessed

Framework mappings

CISA SCuBA
GWS.GMAIL.16.1v1
NIST SP 800-53
SI-3, SC-44