| name | cis-gworkspace-3.1.1.1.2 |
| description | Ensure internal sharing options for primary calendars are configured |
| category | cis-gworkspace |
| version | 1.3.0 |
| author | cyberstrike-official |
| tags | ["cis","gcp","google-workspace","calendar","sharing","external-sharing","offline"] |
| cis_id | 3.1.1.1.2 |
| cis_benchmark | CIS Google Workspace Foundations Benchmark v1.3.0 |
| tech_stack | ["gcp","google-workspace"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
3.1.1.1.2 Ensure internal sharing options for primary calendars are configured (Manual)
Description
Control how much calendar information users in your organization can share internally.
Rationale
In general, not everyone in the organization needs to know the schedule details of everyone else (operational security). Free/busy indication is enough for most people.
Impact
This will be the default for the user's primary calendar. The user can override this setting to allow other specific users greater visibility of their calendar.
Audit Procedure
To verify this setting via the Google Workspace Admin Console:
- Log in to
https://admin.google.com as an administrator
- Select
Apps
- Select
Google Workspace
- Select
Calendar
- Under
Sharing settings, select Internal sharing options for primary calendars
- Ensure
Only free/busy information (hide event details) is selected
Expected Result
Only free/busy information (hide event details) should be selected for internal sharing options for primary calendars.
Remediation
To configure this setting via the Google Workspace Admin Console:
- Log in to
https://admin.google.com as an administrator
- Select
Apps
- Select
Google Workspace
- Select
Calendar
- Under
Sharing settings, select Internal sharing options for primary calendars
- Select
Only free/busy information (hide event details)
- Select
Save
Default Value
Internal sharing options for primary calendars is Share all information
References
CIS Controls
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|
| v8 | 3.3 Configure Data Access Control Lists |