Google Workspace Audit | Free OCSA Tool

Google Workspace Security Assessment Tool

Review Google Workspace security across admin roles, MFA, Gmail protection, Drive sharing, mobile access, Vault, logs, and OAuth apps.

Google Workspace Security Assessment Tool featured cybersecurity audit image

Built for audit and compliance decisions

OC Security Audit focuses on independent assessment, cybersecurity audit, compliance readiness, control validation, and executive-level risk communication. This page does not duplicate ITperfection managed IT services. If remediation or implementation is needed after validation, that work can be handled separately through ITperfection.

Important note: This tool is for initial guidance only and does not replace a professional cybersecurity audit, compliance assessment, penetration test, legal review, or insurance underwriting review.

Assessment items with audit guidance

Open each item to review what it means, how to check it, why it matters, the likely risk level, the business impact, and trusted reference links.

Admin role and super admin governanceRisk: HighImpact: High

Description

Admin role and super admin governance should be reviewed as an evidence-based audit area for google workspace audit. The goal is to determine whether the organization can prove the control exists, works consistently, and has an accountable owner.

How to check

Check administrator portals, identity policies, privileged role assignments, conditional access or MFA reports, and recent sign-in logs. Confirm both ordinary users and administrators are covered.

Why it is important

Identity compromise is one of the fastest paths to ransomware, data theft, cloud compromise, and unauthorized administrative change.

MFA and context-aware access settingsRisk: HighImpact: High

Description

MFA and context-aware access settings should be reviewed as an evidence-based audit area for google workspace audit. The goal is to determine whether the organization can prove the control exists, works consistently, and has an accountable owner.

How to check

Check administrator portals, identity policies, privileged role assignments, conditional access or MFA reports, and recent sign-in logs. Confirm both ordinary users and administrators are covered.

Why it is important

Identity compromise is one of the fastest paths to ransomware, data theft, cloud compromise, and unauthorized administrative change.

Gmail phishing and spoofing protectionRisk: HighImpact: High

Description

Gmail phishing and spoofing protection should be reviewed as an evidence-based audit area for google workspace audit. The goal is to determine whether the organization can prove the control exists, works consistently, and has an accountable owner.

How to check

Review anti-phishing, SPF, DKIM, DMARC, safe links or attachment controls, quarantine reports, user reporting workflow, and recent email security incidents.

Why it is important

Email remains a common entry point for credential theft, invoice fraud, malware delivery, and business email compromise.

Drive sharing and external collaborationRisk: MediumImpact: Medium

Description

Drive sharing and external collaboration should be reviewed as an evidence-based audit area for google workspace audit. The goal is to determine whether the organization can prove the control exists, works consistently, and has an accountable owner.

How to check

Review the related admin console, screenshots, policies, logs, reports, tickets, exception records, and owner accountability evidence. Validate the control by evidence, not by memory.

Why it is important

This control supports audit readiness, risk reduction, executive visibility, and practical remediation planning.

Mobile and endpoint access policiesRisk: HighImpact: Medium

Description

Mobile and endpoint access policies should be reviewed as an evidence-based audit area for google workspace audit. The goal is to determine whether the organization can prove the control exists, works consistently, and has an accountable owner.

How to check

Review the related admin console, screenshots, policies, logs, reports, tickets, exception records, and owner accountability evidence. Validate the control by evidence, not by memory.

Why it is important

This control supports audit readiness, risk reduction, executive visibility, and practical remediation planning.

Data retention and Vault readinessRisk: MediumImpact: High

Description

Data retention and Vault readiness should be reviewed as an evidence-based audit area for google workspace audit. The goal is to determine whether the organization can prove the control exists, works consistently, and has an accountable owner.

How to check

Review the related admin console, screenshots, policies, logs, reports, tickets, exception records, and owner accountability evidence. Validate the control by evidence, not by memory.

Why it is important

This control supports audit readiness, risk reduction, executive visibility, and practical remediation planning.

Audit logs and alerting coverageRisk: MediumImpact: Medium

Description

Audit logs and alerting coverage should be reviewed as an evidence-based audit area for google workspace audit. The goal is to determine whether the organization can prove the control exists, works consistently, and has an accountable owner.

How to check

Confirm audit logs are enabled, retained long enough for investigation, protected from tampering, and reviewed through alerts, reports, or SIEM workflows.

Why it is important

Without reliable logs, the organization may not be able to investigate incidents, support insurance claims, or prove control operation during an audit.

Third-party app and OAuth risk reviewRisk: MediumImpact: Medium

Description

Third-party app and OAuth risk review should be reviewed as an evidence-based audit area for google workspace audit. The goal is to determine whether the organization can prove the control exists, works consistently, and has an accountable owner.

How to check

Review the related admin console, screenshots, policies, logs, reports, tickets, exception records, and owner accountability evidence. Validate the control by evidence, not by memory.

Why it is important

Third parties can create risk even when internal controls are strong, especially when they access sensitive data or critical systems.

Quick self-score

Use this scoring panel after reviewing the detail sections above. Score based on evidence: screenshots, policies, logs, reports, tickets, and owner accountability.

0%
Not started

Select each control area to see the readiness level.

Priority remediation roadmap

1. Validate

Confirm the real control state with evidence and identify gaps that could affect audit, insurance, compliance, or executive risk decisions.

2. Prioritize

Rank findings by business impact, likelihood, compliance exposure, and operational dependency.

3. Track

Create a remediation roadmap with owners, dates, evidence requirements, and follow-up validation.

Ali Hassani, CISO and cybersecurity audit consultant in Orange County

Created by Ali Hassani, CISO

Ali Hassani brings 25+ years of IT, cybersecurity, compliance, Microsoft infrastructure, cloud security, network security, firewall, vulnerability management, and executive advisory experience. OC Security Audit uses this experience to help organizations understand risk clearly before making remediation, compliance, or insurance decisions.

CISSPCCISOvCISO25+ Years Experience

CISSP certification badgeCCISO certification badge

View Ali Hassani’s profile for professional background, certifications, and consulting focus.

Request a professional review from OC Security Audit

Use the self-score as a starting point. For audit-ready evidence, executive reporting, and professional validation, schedule a focused review with OC Security Audit.

Contact OC Security Audit