EMAIL-024: Gmail Security Sandbox enabled (GWS.GMAIL.16.1)
- Plataforma
- Google Workspace
- Categoría
- Advanced Threat Protection
- Severidad
- Medium
- Pilar de Zero Trust
- Applications & Workloads (peso 2)
- Fixtures de referencia
- 4
- Cobertura de ramas
- Observada: los fixtures prueban los veredictos que ejercitan
- Procedencia
- baseline
Qué comprueba
SCuBA GWS.GMAIL.16.1 recommends enabling the Gmail Security Sandbox, which detonates inbound attachments in a virtual environment to detect zero-day malware that signature scanning misses. This check reads the gmail.security_sandbox policy from the Cloud Identity Policy API and flags organizational units where the sandbox is disabled. The exact policy field is best-effort pending confirmation on a licensed tenant; when the policy is not returned the result is Not Assessed rather than a fabricated verdict.
Valor recomendado
Security Sandbox enabled (virtual attachment detonation) for all organizational units
Remediación
In the Google Admin console under Apps > Google Workspace > Gmail > Safety > Attachments, enable Security Sandbox so inbound attachments are detonated in a virtual environment before delivery. Note Security Sandbox requires the appropriate Google Workspace edition.
Veredictos probados con fixtures
Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.
| Escenario | Veredicto esperado |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| no-data | Not Assessed |
| no-policy | Not Assessed |
Mapeos a marcos de referencia
- CISA SCuBA
- GWS.GMAIL.16.1v1
- NIST SP 800-53
- SI-3, SC-44