EMAIL-026: Gmail POP and IMAP access disabled (GWS.GMAIL.9.1)
- Platform
- Google Workspace
- Category
- Advanced Threat Protection
- Severity
- High
- Zero Trust pillar
- Identity (weight 3)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
SCuBA GWS.GMAIL.9.1: legacy POP and IMAP protocols bypass modern authentication and are a credential-stuffing / MFA-bypass vector. Reads gmail.imap_access and gmail.pop_access; fails where either is enabled.
Recommended value
POP and IMAP access disabled
Remediation
In Gmail settings > End User Access, disable POP and IMAP so mail clients must use modern authenticated protocols.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| bad | FAIL |
| clean | PASS |
| no-data | Not Assessed |
Framework mappings
- CISA SCuBA
- GWS.GMAIL.9.1v1
- NIST SP 800-53
- IA-2, AC-17, AC-14