LOG-007: System-defined alerting rules all enabled (GWS.COMMONCONTROLS.13.1)
- Platform
- Google Workspace
- Category
- Logging, Alerting & Monitoring
- Severity
- High
- Zero Trust pillar
- Visibility & Analytics (weight 3)
- Golden fixtures
- 4
- Branch coverage
- Declared verdict paths, each proven by a fixture
- Provenance
- baseline
What it checks
SCuBA GWS.COMMONCONTROLS.13.1: Google ships a set of system-defined alerting rules covering the events an administrator most needs to hear about, including suspicious logins, government-backed attack warnings and admin privilege changes. A rule left inactive means the event still occurs and nobody is told. Reads rule.system_defined_alerts and fails where any rule is not in the ACTIVE state, naming the inactive rules.
Recommended value
Every system-defined alerting rule is active
Remediation
Admin console > Rules > System-defined rules. Review the inactive rules and enable each one, adding recipients so the alerts reach a monitored mailbox rather than an unattended alias.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| empty | Not Assessed |
| known-bad | FAIL |
| not-assessed | Not Assessed |
Framework mappings
- CISA SCuBA
- GWS.COMMONCONTROLS.13.1v1
- NIST SP 800-53
- SI-4, AU-6, IR-5