The Center for Internet Security declares all 89 of its Google Workspace recommendations manual. All of them. Without exception. In other words, the official framework holds that auditing Google Workspace is done by hand, screen by screen. Tenovia nevertheless automates the whole CIS Google Workspace coverage.
CIS Google Workspace coverage, in plain terms
The CIS Google Workspace Foundations Benchmark v1.3.0 contains 89 hardening recommendations. They span the whole admin console. In total, the document runs to 296 pages, and 241 of those are recommendations proper.
| Domain | Recommendations |
|---|---|
| Apps: Gmail, Drive, Calendar, third-party apps | 56 |
| Security: authentication, sessions, access | 19 |
| Rules and alerts | 8 |
| Directory | 4 |
| Reporting and logging | 2 |
| Total | 89 |
| Level | Count | Scope |
|---|---|---|
| Level 1 | 73 | Baseline measures, with no material impact on usage |
| Level 2 | 16 | Advanced hardening, which may restrict certain features |
Why Google Workspace audits are so poor
The framework offers no automated method. As a result, market practice has stayed declarative. A consultant opens the console, walks the screens, notes what they see, and then fills in a spreadsheet.
Anyone who has commissioned one therefore knows the consequences:
- count it in weeks, not days
- the result depends on the auditor; two consultants do not produce the same finding
- nothing is verifiable by a third party, since no raw data survives
- doing it again next year costs the same, with no reliable basis for comparison
What Tenovia does
A control declared manual is not therefore impossible to automate. In reality, it only means CIS documented no programmatic method.
Google does expose a domain’s configuration state through application interfaces. Tenovia builds on that, read-only, and never writes. The CIS Google Workspace coverage rests entirely on that reading.
- No script run on your estate. Your teams install nothing and run nothing.
- No ability to modify. Access therefore stays strictly read-only.
- A dated, replayable finding. Tenovia retains every setting with its value and collection date.
- Comparable across audits. The second run reads as a difference: fixed, regressed, unchanged.
The same core as Microsoft 365
Google Workspace collection produces exactly the same evidence format as Microsoft 365 collection. You therefore find the control identifier, the object, the property, the value and the date. Moreover, the same rule engine assesses both platforms, and the same document reports them.
For a group running both environments, or a firm auditing both, that consequently means one console, one format, one method.
What you receive
- An audit report by domain, with the compliance score and the original wording of each CIS control
- The technical evidence behind every finding, time-stamped
- A prioritised remediation plan ranked by severity, effort and gain
- Finally, the regulatory mapping of every gap to NIS2, DORA, ISO/IEC 27001 or the GDPR
A configuration audit observes settings at a given date. It does not, however, look for compromise, does not test resistance to intrusion, and does not amount to an attestation of compliance. Instead, it provides the technical evidence your compliance programme requires.