cisagov / ScubaGoggles

SCuBA Secure Configuration Baselines and assessment tool for Google Workspace
https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project
Creative Commons Zero v1.0 Universal
164 stars 22 forks source link

GWS.COMMONCONTROLS.6.1v0.3 Iinstructions unclear #461

Closed adhilto closed 2 weeks ago

adhilto commented 1 month ago

💡 Summary

Update GWS.COMMONCONTROLS.6.1v0.3 instructions to more relevant to the policy.

Motivation and context

The current policy:

All highly privileged accounts SHALL leverage Google Account authentication with phishing-resistant MFA and not the agency's authoritative on-premises or federated identity system.

The current instructions:

The implementation process for this can be located here.

The "here" link isn't relevant. It's just a general discussion of admin roles. It makes no mention of federated identity.

Implementation notes

Ideally, the instructions would tell you how to identify any privileged users you have that are leveraging on-prem or federated identity.

Acceptance criteria