Security Setup Checklist
70 steps across the ten Brilliant at the Basics requirements. Check each box as you complete it. Confirm every step against Google Workspace’s own documentation before you rely on it.
Handling CUI in Workspace requires Assured Controls and careful scoping. Confirm an authorization path before you store CUI.
Phishing-Resistant Multi-Factor Authentication
- Open 2-Step Verification settingsIn the Google Admin console, go to Security > Authentication > 2-Step Verification.
- Turn on enforcementCheck 'Allow users to turn on 2-Step Verification' and set Enforcement to On for the whole organization.
- Create an Admins org unitIn the Google Admin console, go to Directory > Organizational units and add an OU named 'Admins' for privileged accounts.
- Require security keys for adminsBack in Security > Authentication > 2-Step Verification, select the Admins OU and set the method to 'Only security key' (includes hardware keys and passkeys).
- Hand out keys firstGive every affected user a hardware security key or set up a passkey before the enforcement date so no one gets locked out.
- Set an enrollment grace periodUnder the same 2-Step Verification page, set a 'New user enrollment period' so new hires have a short window to register a key.
- Confirm coverageIn the Google Admin console, go to Reporting > Reports > Security to view the 2-Step Verification enrollment report and confirm everyone is covered.
Evidence to keep: 2-Step Verification enrollment report · Screenshot of 'Only security key' policy on Admins OU · List of issued security keys/passkeys
Least-Privilege Access Control
- Review current adminsIn the Google Admin console, go to Account > Admin roles to see who holds Super Admin and other roles.
- Limit super adminsKeep Super Admin to two or three trusted people; open each role to see 'Admins' assigned and remove anyone who doesn't need it.
- Build organizational unitsIn the Google Admin console, go to Directory > Organizational units and create OUs (for example, by department) so policies can target the right people.
- Create a custom roleIn Account > Admin roles, click 'Create new role' and pick only the specific privileges that job needs (for example, help-desk password resets).
- Assign the scoped roleOpen your new role, click 'Assign users,' and, where offered, limit the role to a single OU so power stays contained.
- Enforce MFA on adminsIn the Google Admin console, go to Security > Authentication > 2-Step Verification and require security keys for all admin roles.
- Schedule periodic reviewEvery quarter, revisit Account > Admin roles and Directory > Users to confirm access still matches each person's job.
Evidence to keep: List of admin role assignments · Custom role definitions with privileges · Quarterly access review record
Asset & Account Inventory
- Turn on endpoint managementIn the Google Admin console, go to Devices > Mobile & endpoints > Settings > Universal settings and enable basic or advanced mobile management.
- View the device inventoryIn the Google Admin console, go to Devices > Mobile & endpoints > Devices to see every phone and computer signed in to your accounts.
- Check Chrome devicesIn the Google Admin console, go to Devices > Chrome > Devices to inventory managed Chromebooks and their status.
- Audit user accountsIn the Google Admin console, go to Directory > Users to list every account and suspend any that are unused or unknown.
- Review connected appsIn the Google Admin console, go to Security > Access and data control > API controls > Manage third-party app access to see apps that can reach your data.
- Export the listsUse the download/export button on the Users and Devices pages to save a dated inventory for your records.
- Reconcile regularlyCompare the exported lists monthly against your known staff and equipment, and remove anything that doesn't belong.
Evidence to keep: Exported device inventory (dated) · User account list · Connected/third-party app report
Logging, Monitoring & Audit
- Open the audit logsIn the Google Admin console, go to Reporting > Audit and investigation and review Login, Admin, and Drive log events.
- Use the investigation toolIn the Google Admin console, go to Security > Security center > Investigation tool to search across events and take action on threats.
- Check the alert centerIn the Google Admin console, go to Security > Alert center to view and triage automatic alerts like suspicious logins.
- Turn on BigQuery exportIn the Google Admin console, go to Reporting > Audit and investigation > BigQuery Export settings and connect a Google Cloud BigQuery project.
- Set long-term retentionBecause Admin console logs are kept only about six months, use the BigQuery export to store logs for the years an auditor may require.
- Create custom alertsIn Security > Alert center (or the Investigation tool), create rules that email you when high-risk events occur.
- Review on a scheduleSet a weekly time to review alerts and key log events, and record that the review happened.
Evidence to keep: BigQuery log export configuration · Alert center rules and history · Weekly log-review records
Network Segmentation & Boundary Protection
- Open Context-Aware AccessIn the Google Admin console, go to Security > Access and data control > Context-Aware Access and turn it on.
- Create an access levelClick Access levels > Create access level and pick attributes such as IP subnet, device policy, or location.
- Assign to an appOn the Context-Aware Access page, find an app (or Admin console) in the list and click Assign to require your access level.
- Start in monitor modeAssign the access level in monitor mode for at least a week so you can see who would be blocked before enforcing.
- Use OUs as boundariesIn the Google Admin console, go to Directory > Organizational units and place CUI users in a dedicated OU that gets the strictest access levels.
- Restrict admin access by IPCreate an access level limited to your office/VPN IP subnet and assign it to the Admin console app to lock admin work to trusted networks.
- Enforce and monitorSwitch the access level out of monitor mode to active, then watch the logs for blocked attempts.
Evidence to keep: Context-Aware Access level definitions · App assignment screenshots · Blocked-access log entries
Vulnerability & Patch Management
- Set ChromeOS auto-updateIn the Google Admin console, go to Devices > Chrome > Settings > Device settings and configure Auto-update settings to keep ChromeOS current.
- Enforce browser updatesIn the Google Admin console, go to Devices > Chrome > Settings > Users & browsers and set Chrome updates to apply automatically and require relaunch.
- Require a minimum versionIn the same Chrome settings, set a minimum allowed Chrome version so out-of-date browsers are blocked from use.
- Enroll managed browsersIn the Google Admin console, go to Devices > Chrome > Managed browsers to enroll and track browser versions across your fleet.
- Check the security health pageIn the Google Admin console, go to Security > Security center > Security dashboard/health to review flagged weak settings.
- Keep mobile OS currentIn the Google Admin console, go to Devices > Mobile & endpoints > Settings and require a minimum OS version for enrolled phones.
- Track and documentRecord update policies and version reports so you can show devices stay patched.
Evidence to keep: Chrome/ChromeOS update policy settings · Managed browser version report · Security health page results
Data Protection & Encryption
- Plan your key serviceChoose a Google CSE partner key service (KACLS) or build one, plus an identity provider, before enabling CSE.
- Connect the key serviceIn the Google Admin console, go to Security > Access and data control > Client-side encryption and add your external key service URL and IdP.
- Assign CSE to usersOn the Client-side encryption page, under the encryption key service, click Assign to choose the OUs or groups that get CSE.
- Turn CSE on per appUnder Apps on the same page, enable CSE for the services you need, such as Drive, Gmail, Calendar, and Meet.
- Turn on S/MIME for emailIn the Google Admin console, go to Apps > Google Workspace > Gmail > User settings and enable hosted S/MIME for signed, encrypted mail.
- Confirm TLS for mailIn Apps > Google Workspace > Gmail > Compliance, require secure TLS transport with your key partners so mail stays encrypted in transit.
- Test with a real fileCreate an encrypted document in Drive and confirm the CSE lock icon appears before rolling CSE out widely.
Evidence to keep: CSE key service configuration · List of OUs/apps with CSE enabled · Sample encrypted Drive file
Backup & Recovery
- Open Google VaultSign in to vault.google.com as a user with Vault privileges and click Retention.
- Set a default retention ruleIn Vault > Retention, create a default rule so Gmail, Drive, and Chat data is kept for your required time.
- Add custom retentionCreate custom retention rules by organizational unit for teams that must keep data longer, such as those handling CUI.
- Place holds when neededIn Vault > Matters, create a matter and place a hold on specific users so their data can't be deleted during an investigation.
- Practice a restore/exportIn Vault, run a search and export for a sample account to prove you can recover data (exports are available for 15 days).
- Require dual approval on exportsIn the Google Admin console, turn on multi-party approval so one admin must approve another admin's Vault export.
- Add an independent backupUse Google Takeout or a third-party Workspace backup tool to keep a copy outside the tenant for extra resilience.
Evidence to keep: Vault retention rule configuration · Successful test export record · Multi-party approval setting screenshot
Secure Configuration Baseline
- Open the security dashboardIn the Google Admin console, go to Security > Security center > Security dashboard to see your overall posture.
- Review the health pageOn the security health/status page, read each recommendation and note settings marked as risky.
- Harden sharing and accessApply recommended fixes, such as tightening external sharing in Apps > Google Workspace > Drive and Docs > Sharing settings.
- Write down your baselineRecord each chosen setting and its value in a baseline document so future changes can be compared against it.
- Apply per OUIn the Google Admin console, go to Directory > Organizational units and apply stricter baseline settings to your CUI OU.
- Alert on driftIn the Google Admin console, go to Security > Alert center and enable alerts for changes to key security settings.
- Re-check on a scheduleRevisit the security health page monthly and confirm settings still match your written baseline.
Evidence to keep: Security health page screenshot · Written configuration baseline document · Change/drift alert settings
Secure AI Adoption & Data Loss Prevention
- Open data protectionIn the Google Admin console, go to Security > Access and data control > Data protection.
- Create a DLP rule for DriveClick 'Add rule,' choose Drive, and use a detector (such as a custom pattern for CUI markings) to block or warn on risky sharing.
- Add a DLP rule for GmailIn the same Data protection area, create a Gmail rule to block or quarantine outbound email that contains sensitive content.
- Apply IRM to sensitive filesConfigure your DLP rule to apply information rights management so protected files can't be downloaded, printed, or copied.
- Control Gemini's data accessIn the Google Admin console, go to Generative AI (or Apps > Additional Google services > Gemini app) and set whether Gemini can access Workspace data.
- Protect data from the AIRely on IRM and client-side encryption so DLP-protected and encrypted files are not read by Gemini when generating answers.
- Test then enforceRun rules in audit-only mode first, review the hits in Reporting, then switch to blocking once tuned.
Evidence to keep: DLP rule definitions for Drive and Gmail · Gemini data-access configuration · DLP incident/audit report