Google Workspace Security Posture Kit
Assess what a compromised Google Workspace account can actually reach, scored against your edition, and close the gaps before an insurer or auditor asks. The Workspace counterpart to the M365 kit, built around the two blind spots a login audit cannot see: a granted OAuth token, and shared-drive sharing that looks like a leak.
What this actually gives you
- A granted OAuth token needs no fresh login to be used. Login-audit review — the first place most admins look — is structurally blind to it. An attacker whose token was authorised weeks ago never signs in again.
- Shared-drive membership propagation is a false-positive trap in both directions. Reviewed carelessly it reads as bulk external sharing; reviewed too casually, real exposure is waved through as "just a shared drive thing".
- Business Plus has Vault but no DLP and no Context-Aware Access. Assuming retention implies data-loss protection is the commonest finding on a mid-market tenant, and the edition tab is step one for that reason.
- Workspace has no Defender XDR equivalent: the Security Investigation Tool queries six sources and merges none of them. File 06 says so as a platform ceiling rather than hiding it in a score.
- Same five modules and the same scoring bands as the M365 kit, so a vCISO on a mixed-tenant client uses one mental model twice.
Same question as the M365 kit, different platform, and two blind spots of its own. "If one account were compromised right now, what could the attacker reach, and how would we know?" On Google Workspace a large share of compromise activity never appears in a login log at all. It appears as a previously granted OAuth token being used — a granted token needs no fresh login, so the first place most admins look during an investigation is structurally blind to it. Or it appears as a Drive ACL change that looks identical to normal shared-drive membership propagation, which is a known false-positive trap in both directions: reviewed carelessly it reads as bulk external sharing, reviewed too casually real exposure gets waved through. This kit is built around those, not translated from the Microsoft control list.
The score depends on your edition, and Business Plus is the trap. Vault arrives at Business Plus; DLP and Context-Aware Access do not arrive until Enterprise Standard/Plus or Cloud Identity Premium. Many mid-market tenants run Business Plus and assume Vault's retention implies data-loss protection. It does not. Confirming the edition is step one of every module, and the scoring tool changes its arithmetic when you do. It is also where the central finding on most tenants comes from: what you assume you have versus what you actually have.
There is no Defender XDR equivalent, and the kit says so. The Security Investigation Tool queries six sources — Login, OAuth Token, Drive, Admin, Groups, Gmail — and does not merge them. File 06 states that as a platform ceiling rather than hiding it in a score.
What you get
01 Assessment Methodology (DOCX) — the five modules, the two Workspace blind spots, the run order, cross-links, and the assumptions that bound the scoring.
02 Identity & Access Review Workbook (XLSX) — Context-Aware Access coverage, Authentication (2-Step Verification enforcement, security keys for privileged roles, Advanced Protection Program, account-recovery hygiene), Admin Roles and External Access, as 18 weighted controls across four tabs rolling into one identity posture score. Workspace has no PIM, so the Admin Roles tab scores custom-role scoping, standing-privilege minimisation and review cadence rather than a feature that does not exist.
03 Blast Radius Scoring Tool (XLSX) — the flagship module. Select the tenant's edition and add-ons, answer the control questions across Gmail, Drive & Docs, OAuth / Marketplace and Detection, and get a single blast-radius score, a band from Low to High on the same bands as the M365 kit, and a closure list ranked by risk-weighted points with owner and target date.
04 CIS-Aligned Hardening Baseline Checklist (XLSX) — Identity Management, Data Sharing, Email Security, Authentication and Logging & Monitoring families structured after the CIS Google Workspace Foundations Benchmark, scored gap-to-target rather than pass/fail, with a hardening percentage per family.
05 Data Governance Review (DOCX) — Vault retention and eDiscovery, DLP scope where licensed, and Drive default-sharing posture, with the commonest gap named plainly: DLP is not misconfigured, it is not licensed.
06 Detection Readiness Matrix (XLSX) — activity type to log source to minimum edition to retention to whether it is a single query in the Security Investigation Tool.
07 Executive Summary Template (DOCX) — one page: the four module scores, the top five findings, what they mean in plain terms, a remediation timeline and the next review date.
gws01.json — scoring bands, edition components, surfaces and the module map.
A worked example throughout. Cobalt Ridge Analytics, a fictional mid-market analytics firm on Business Plus — Vault but no DLP, deliberately the partial-licensing case rather than a best-case demo tenant.
Where it sits. This is the assessment layer, and it is the direct sibling of the M365 Security Posture Kit: a vCISO running both on a mixed-tenant client uses one mental model twice. The Okta / Identity Provider Security Posture Kit is the front door in front of both, the Salesforce Security Posture Kit covers the CRM behind it, the GitHub / GitLab Security Posture Kit the pipeline, and the set of five is cheaper than buying them separately. The IR Runbook Library is the response layer — its runbook 03 is cloud account takeover. Implement what this flags with Build Series vol. 06 — Identity & Access; go further than file 06 with vol. 01 — Detection & Monitoring. Run it against a vendor's tenant with the TPRM Program Kit; hand file 07 to the Director's Cyber Oversight Kit.
Written against Google Workspace edition names and features as of Q3 2026 for a standard commercial tenant — not Google Cloud Platform IAM, and not Gemini data-access governance. Google re-tiers features regularly, so the edition logic is marked verify. Scores are a prioritisation aid, not a certification, an audit opinion or an insurance-underwriting determination. Not legal advice.
Also available in a bundle
This product is sold on its own and as part of a set. If you need more than this one, the set is cheaper than buying the parts.
What's included
- Complete Library (.zip) — all formats included — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
- Practitioner License: unlimited client use (vCISO / MSP)
More from the CISO Marketplace ecosystem
Choose your license:
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee