GROUP-003: Groups cannot receive mail from outside the org (GWS.GROUPS.1.3)

Platform
Google Workspace
Category
Collaboration
Severity
Medium
Zero Trust pillar
Applications & Workloads (weight 2)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA GWS.GROUPS.1.3 requires that group owners not be permitted to allow incoming email from outside the organization. Allowing public inbound mail to groups is an inbound phishing and spam vector. This check flags organizational units where owners can allow incoming mail from the public (ownersCanAllowIncomingMailFromPublic is enabled).

Recommended value

Group owners cannot allow incoming mail from the public (ownersCanAllowIncomingMailFromPublic disabled)

Remediation

In Groups for Business sharing settings, disable the option that lets group owners accept incoming email from outside the organization, restricting group mail to internal senders unless explicitly configured.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for GROUP-003
ScenarioExpected verdict
cleanPASS
known-badFAIL
no-dataNot Assessed

Framework mappings

CISA SCuBA
GWS.GROUPS.1.3v1
NIST SP 800-53
SC-7, SI-8