← Google Workspace audit scope

Benchmarks & Compliance Mapping

9 checks · 2 sub-categories

Findings only become useful when they're prioritised and defensible. Every item in the audit is scored for severity and mapped to a recognised framework, so the report doubles as evidence for cyber insurance applications, client security questionnaires and board reporting.

Framework alignment

  • CIS Google Workspace Foundations Benchmark

    Findings are mapped to the relevant CIS control so you can show which benchmark items pass, fail or don't apply to your licence tier.

  • CISA SCuBA Google Workspace baselines

    The SCuBA baselines are the most complete public configuration standard for Workspace. We report conformance by service.

  • Cyber Essentials alignment

    Useful for businesses with UK or education-sector counterparties, and a clean way to describe baseline hygiene.

  • ACSC Essential Eight maturity indication

    We indicate where your Workspace configuration sits against the Essential Eight strategies that apply to a cloud productivity suite — MFA, restricting admin privileges, application control and event log monitoring.

    • Essential Eight
  • Privacy Act and NDB readiness

    We assess whether you could actually determine the scope of a breach within the statutory window, and whether APP 11 reasonable-steps obligations are being met.

    • Privacy Act APP 11
    • NDB scheme

Reporting outputs

  • Severity-rated findings, critical to low

    Every finding carries a severity so the first fixes are the ones that actually reduce risk, not the ones that are easiest to tick off.

  • Plain-English remediation steps

    Each finding includes what to change and where, written so a business owner can hand it to any IT provider — or action it themselves.

  • Posture score and re-scan comparison

    A single score gives you a before-and-after, so remediation work can be evidenced rather than asserted.

  • Evidence pack for insurers and client questionnaires

    The report is structured to answer the security questions insurers and enterprise clients actually ask, without you having to translate it first.

Want to know where you actually stand?

Every one of these checks runs as part of a single point-in-time, read-only audit, delivered as a plain-English, risk-prioritised report.