LOG-007: System-defined alerting rules all enabled (GWS.COMMONCONTROLS.13.1)

Platform
Google Workspace
Category
Logging, Alerting & Monitoring
Severity
High
Zero Trust pillar
Visibility & Analytics (weight 3)
Golden fixtures
4
Branch coverage
Declared verdict paths, each proven by a fixture
Provenance
baseline

What it checks

SCuBA GWS.COMMONCONTROLS.13.1: Google ships a set of system-defined alerting rules covering the events an administrator most needs to hear about, including suspicious logins, government-backed attack warnings and admin privilege changes. A rule left inactive means the event still occurs and nobody is told. Reads rule.system_defined_alerts and fails where any rule is not in the ACTIVE state, naming the inactive rules.

Recommended value

Every system-defined alerting rule is active

Remediation

Admin console > Rules > System-defined rules. Review the inactive rules and enable each one, adding recipients so the alerts reach a monitored mailbox rather than an unattended alias.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for LOG-007
ScenarioExpected verdict
cleanPASS
emptyNot Assessed
known-badFAIL
not-assessedNot Assessed

Framework mappings

CISA SCuBA
GWS.COMMONCONTROLS.13.1v1
NIST SP 800-53
SI-4, AU-6, IR-5