Groups & Mailing Lists
8 checks · 2 sub-categories
Google Groups are simultaneously mailing lists and access-control objects. One group set to 'anyone on the internet can view' can publish years of internal email conversations, and one over-broad membership can silently grant access to half your Drive.
Group visibility and access
Groups accessible to anyone on the internet
Publicly viewable groups can expose archived conversations and member lists. Each affected group is named.
- CIS GW 5.1
- SCuBA GWS.GROUPS
- Privacy Act APP 11
Domain-wide default group access setting
We check the default sharing setting for new groups so future groups don't repeat the same mistake.
Groups allowing external members
External members receive everything the group receives, indefinitely. All groups permitting outside membership are listed with their current external members.
Groups accepting mail from outside the organisation
Open posting turns an internal list into an unauthenticated inbound channel — a common phishing and spam vector. Each open group is flagged.
Governance
Groups used to grant Drive or app access
We identify which groups act as access-control groups so their membership can be governed accordingly rather than treated as a mailing list.
Groups with no owner or a stale owner
Owner-less groups accumulate members and nobody prunes them. Each is reported with member count and last activity.
Suspended and ex-staff members across groups
Departed staff commonly remain in distribution and access groups. We list every group containing suspended accounts.
Members who can view conversation archives
Archive visibility settings decide whether new members can read years of past discussion. We report groups where the archive is broader than the membership.
Want to know where you actually stand?
Every one of these checks runs as part of a single point-in-time, read-only audit, delivered as a plain-English, risk-prioritised report.