| name | cis-gworkspace-3.1.3.4.3.2 |
| description | Ensure protection against spoofing of employee names is enabled |
| category | cis-gworkspace |
| version | 1.3.0 |
| author | cyberstrike-official |
| tags | ["cis","gcp","google-workspace","gmail","spoofing","phishing","email-security"] |
| cis_id | 3.1.3.4.3.2 |
| cis_benchmark | CIS Google Workspace Foundations Benchmark v1.3.0 |
| tech_stack | ["gcp","google-workspace"] |
| cwe_ids | [] |
| chains_with | ["cis-gworkspace-3.1.3.4.3.1","cis-gworkspace-3.1.3.4.3.3","cis-gworkspace-3.1.3.4.3.4","cis-gworkspace-3.1.3.4.3.5"] |
| prerequisites | [] |
| severity_boost | {} |
3.1.3.4.3.2 Ensure protection against spoofing of employee names is enabled
Overview
| Property | Value |
|---|
| CIS ID | 3.1.3.4.3.2 |
| Level | L1 |
| Profile Applicability | Enterprise Level 1 |
| Assessment Type | Manual |
| Section | Gmail > Safety > Spoofing and authentication |
Description
Moves employee spoofing emails to spam folder.
Rationale
You should protect your users from employee spoofing emails.
Impact
Employee spoofed emails will be moved to a user's spam folder.
Default Value
Protect against spoofing of employee names = checked
Action = Keep email in inbox and show warning (default)
Audit
To verify this setting via the Google Workspace Admin Console:
- Log in to https://admin.google.com as an administrator
- Select Apps
- Select Google Workspace
- Select Gmail
- Under
Safety - Spoofing and authentication, ensure Protect against spoofing of employee names is checked
- Ensure
Action is Move email to spam
Remediation
To configure this setting via the Google Workspace Admin Console:
- Log in to https://admin.google.com as an administrator
- Select Apps
- Select Google Workspace
- Select Gmail
- Under
Safety - Spoofing and authentication, set Protect against spoofing of employee names to checked
- Set
Action to Move email to spam
- Select Save