-
Notifications
You must be signed in to change notification settings - Fork 28
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. Weβll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Updating Common Controls 1/MFA #603
base: main
Are you sure you want to change the base?
Conversation
drift-rules/GWS Drift Monitoring Rules - Common Controls as of 11-14-23.csv
Outdated
Show resolved
Hide resolved
Co-authored-by: Alden Hilton <106177711+adhilto@users.noreply.github.com>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks great
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Formatting stuff.
Feel free to merge once suggested changes are addressed.
@@ -158,29 +159,22 @@ If phishing-resistant MFA is not yet tenable, an MFA method from the following l | |||
- [T1566: Phishing](https://attack.mitre.org/techniques/T1566/) | |||
- [T1566:001: Phishing: Spearphishing Attachment](https://attack.mitre.org/techniques/T1566/001/) | |||
|
|||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
unnecessary
|
||
#### GWS.COMMONCONTROLS.1.3v0.4 Instructions | ||
1. Under Frequency, deselect the **Allow user to trust device** checkbox. | ||
1. Under **Methods**, select **Any except verification codes via text, phone call**. | ||
2. Select **Save** |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
2. Select **Save** | |
2. Select **Save**. |
Period
If security keys are not yet available for your organization: | ||
1. Under **Methods**, select **Any except verification codes via text, phone call**. | ||
#### GWS.COMMONCONTROLS.1.5v0.4 Instructions | ||
1. Under Frequency, deselect the **Allow user to trust device** checkbox. | ||
2. Select **Save** |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
2. Select **Save** | |
2. Select **Save**. |
Period
@@ -193,30 +187,21 @@ To enforce Phishing-Resistant 2-Step Verification (MFA) for all users, use the G | |||
5. Select **Save** |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
5. Select **Save** | |
5. Select **Save**. |
Period
To enforce Phishing-Resistant 2-Step Verification (MFA) for all users, use the Google Workspace Admin Console: | ||
|
||
#### Policy 1 common Instructions | ||
#### Policy 1 Common Instructions | ||
1. Sign in to [Google Admin console](https://admin.google.com/) as an administrator. | ||
2. Select **Security** -\> **Authentication.** | ||
3. Select **2-Step Verification.** |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
3. Select **2-Step Verification.** | |
3. Select **2-Step Verification**. |
To enforce Phishing-Resistant 2-Step Verification (MFA) for all users, use the Google Workspace Admin Console: | ||
|
||
#### Policy 1 common Instructions | ||
#### Policy 1 Common Instructions | ||
1. Sign in to [Google Admin console](https://admin.google.com/) as an administrator. | ||
2. Select **Security** -\> **Authentication.** |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
2. Select **Security** -\> **Authentication.** | |
2. Select **Security** -\> **Authentication**. |
|
||
If using security keys: | ||
1. Under **Methods**, select **Only security Key**. Next, select **Don't allow users to select security codes**. | ||
1. Set **New user enrollment** period to at least **1 Day** or at most **1 Week**. | ||
2. Select **Save** |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
2. Select **Save** | |
2. Select **Save**. |
Period
π£ Description
Updating Common Control 1/MFA Policies
π Motivation and context
Updating policies for clarity.
Closes #591
π§ͺ Testing
β Pre-approval checklist
β Pre-merge Checklist
Squash and merge
button.β Post-merge Checklist