EMAIL-024: Gmail Security Sandbox enabled (GWS.GMAIL.16.1)

Plataforma
Google Workspace
Categoría
Advanced Threat Protection
Severidad
Medium
Pilar de Zero Trust
Applications & Workloads (peso 2)
Fixtures de referencia
4
Cobertura de ramas
Observada: los fixtures prueban los veredictos que ejercitan
Procedencia
baseline

Qué comprueba

SCuBA GWS.GMAIL.16.1 recommends enabling the Gmail Security Sandbox, which detonates inbound attachments in a virtual environment to detect zero-day malware that signature scanning misses. This check reads the gmail.security_sandbox policy from the Cloud Identity Policy API and flags organizational units where the sandbox is disabled. The exact policy field is best-effort pending confirmation on a licensed tenant; when the policy is not returned the result is Not Assessed rather than a fabricated verdict.

Valor recomendado

Security Sandbox enabled (virtual attachment detonation) for all organizational units

Remediación

In the Google Admin console under Apps > Google Workspace > Gmail > Safety > Attachments, enable Security Sandbox so inbound attachments are detonated in a virtual environment before delivery. Note Security Sandbox requires the appropriate Google Workspace edition.

Veredictos probados con fixtures

Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.

Escenarios de veredicto de EMAIL-024
EscenarioVeredicto esperado
cleanPASS
known-badFAIL
no-dataNot Assessed
no-policyNot Assessed

Mapeos a marcos de referencia

CISA SCuBA
GWS.GMAIL.16.1v1
NIST SP 800-53
SI-3, SC-44