EMAIL-026: Gmail POP and IMAP access disabled (GWS.GMAIL.9.1)

Platform
Google Workspace
Category
Advanced Threat Protection
Severity
High
Zero Trust pillar
Identity (weight 3)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA GWS.GMAIL.9.1: legacy POP and IMAP protocols bypass modern authentication and are a credential-stuffing / MFA-bypass vector. Reads gmail.imap_access and gmail.pop_access; fails where either is enabled.

Recommended value

POP and IMAP access disabled

Remediation

In Gmail settings > End User Access, disable POP and IMAP so mail clients must use modern authenticated protocols.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EMAIL-026
ScenarioExpected verdict
badFAIL
cleanPASS
no-dataNot Assessed

Framework mappings

CISA SCuBA
GWS.GMAIL.9.1v1
NIST SP 800-53
IA-2, AC-17, AC-14