| name | cis-gworkspace-4.3.1 |
| description | Ensure the Dashboard is reviewed regularly for anomalies |
| category | cis-gworkspace |
| version | 1.3.0 |
| author | cyberstrike-official |
| tags | ["cis","gcp","google-workspace","security","security-center","monitoring","dashboard"] |
| cis_id | 4.3.1 |
| cis_benchmark | CIS Google Workspace Foundations Benchmark v1.3.0 |
| tech_stack | ["gcp","google-workspace"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
4.3.1 Ensure the Dashboard is reviewed regularly for anomalies
Profile Applicability
Description
As an administrator, you can use the security dashboard to see an overview of different security reports. By default, each security report panel displays data from the last 7 days. You can customize the dashboard to view data from Today, Yesterday, This week, Last week, This month, Last month, or Days ago (up to 180 days).
Charts/reports available (Minimum, but could be many more depending on account type):
- DLP incidents
- Top policy incidents
- Failed device password attempts
- Compromised device events
- Suspicious device activities
- OAuth scope grants by product (beta customers only)
- OAuth grant activity
- OAuth grants to new apps
- User login attempts -- Challenge method
- User login attempts -- Failed
- User login attempts -- Suspicious
Details on what each of these charts/reports mean can be found in Google documentation. This report should be reviewed weekly.
NOTE: The availability of each individual report on the security dashboard depends on your Google Workspace edition. See Google documentation for more details.
NOTE: In larger organizations reviewing this entire report weekly may not be possible. At a minimum, all Administrator and Super Administrator users should be reviewed, since they are a higher risk. These can be filtered from the overall user list.
Rationale
The Security report provides a comprehensive view of how people share and access data and whether they take appropriate security precautions. For example, you can review who installs external apps, shares numerous files, skips 2-Step Verification, and uses security keys.
Impact
No user impact.
Audit
To verify this setting via the Google Workspace Admin Console:
- Log in to
https://admin.google.com as an administrator.
- Select
Reporting
- Select
Reports
- Select
User Reports
- Select
Security, and a table of results will be displayed with the fields listed in the Recommendation description above.
- Review the displayed users and values for anomalies
Remediation
The remediation for any anomalies in the various fields varies widely (different sections of the Google Workspace Admin UI). Please refer to Google's documentation for specifics.