GROUP-003: Groups cannot receive mail from outside the org (GWS.GROUPS.1.3)
- Platform
- Google Workspace
- Category
- Collaboration
- Severity
- Medium
- Zero Trust pillar
- Applications & Workloads (weight 2)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
SCuBA GWS.GROUPS.1.3 requires that group owners not be permitted to allow incoming email from outside the organization. Allowing public inbound mail to groups is an inbound phishing and spam vector. This check flags organizational units where owners can allow incoming mail from the public (ownersCanAllowIncomingMailFromPublic is enabled).
Recommended value
Group owners cannot allow incoming mail from the public (ownersCanAllowIncomingMailFromPublic disabled)
Remediation
In Groups for Business sharing settings, disable the option that lets group owners accept incoming email from outside the organization, restricting group mail to internal senders unless explicitly configured.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| no-data | Not Assessed |
Framework mappings
- CISA SCuBA
- GWS.GROUPS.1.3v1
- NIST SP 800-53
- SC-7, SI-8