| name | cis-gworkspace-4.2.3.1 |
| description | Ensure DLP policies for Google Drive are configured |
| category | cis-gworkspace |
| version | 1.3.0 |
| author | cyberstrike-official |
| tags | ["cis","gcp","google-workspace","security","dlp","data-protection","google-drive"] |
| cis_id | 4.2.3.1 |
| cis_benchmark | CIS Google Workspace Foundations Benchmark v1.3.0 |
| tech_stack | ["gcp","google-workspace"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
4.2.3.1 Ensure DLP policies for Google Drive are configured
Profile Applicability
Description
Enabling Data Loss Prevention (DLP) policies for Google Drive allows organizations to control the content that users can share in Google Drive files outside the organization.
Rationale
Enabling DLP policies alerts users and administrators that specific types of data should not be exposed, helping to protect the data from accidental exposure. DLP gives you control over what users can share, and prevents unintended exposure of sensitive information such as credit card numbers or identity numbers.
Impact
Configuring a DLP policy for Google Drive will detect or block sensitive information.
Audit
To verify this setting via the Google Workspace Admin Console:
- Log in to
https://admin.google.com as an administrator
- Select
Security
- Select
Access and Data Control
- Select
Data protection
- Select
Manage Rules
- Ensure data protection rules
exist and are enabled
Remediation
To configure this setting via the Google Workspace Admin Console:
- Log in to
https://admin.google.com as an administrator
- Select
Security
- Select
Access and Data Control
- Select
Data protection
- Select
Manage Rules
- Select
ADD RULE, then select either New rule or New rule from template
New rule
Examples can be found in Google documentation.
- Set the rule
Name
- Optionally - Set the rule
Description
- Set the
Scope as appropriate
- Select
Continue
- Set
Triggers by checking File modified under Google Drive
- Select
ADD CONDITION and configure values (Field, Comparison Operator, Content to match) - Repeat as appropriate