TENOVIA
Book a demo

CIS coverage

CIS coverage for Google Workspace

The Center for Internet Security declares all 89 of its Google Workspace recommendations manual. All of them. Without exception. In other words, the official framework holds that auditing Google Workspace is done by hand, screen by screen. Tenovia nevertheless automates the whole CIS Google Workspace coverage.

CIS Google Workspace coverage, in plain terms

The CIS Google Workspace Foundations Benchmark v1.3.0 contains 89 hardening recommendations. They span the whole admin console. In total, the document runs to 296 pages, and 241 of those are recommendations proper.

Domain Recommendations
Apps: Gmail, Drive, Calendar, third-party apps 56
Security: authentication, sessions, access 19
Rules and alerts 8
Directory 4
Reporting and logging 2
Total 89
Level Count Scope
Level 1 73 Baseline measures, with no material impact on usage
Level 2 16 Advanced hardening, which may restrict certain features

Why Google Workspace audits are so poor

The framework offers no automated method. As a result, market practice has stayed declarative. A consultant opens the console, walks the screens, notes what they see, and then fills in a spreadsheet.

Anyone who has commissioned one therefore knows the consequences:

  • count it in weeks, not days
  • the result depends on the auditor; two consultants do not produce the same finding
  • nothing is verifiable by a third party, since no raw data survives
  • doing it again next year costs the same, with no reliable basis for comparison

What Tenovia does

A control declared manual is not therefore impossible to automate. In reality, it only means CIS documented no programmatic method.

Google does expose a domain’s configuration state through application interfaces. Tenovia builds on that, read-only, and never writes. The CIS Google Workspace coverage rests entirely on that reading.

  • No script run on your estate. Your teams install nothing and run nothing.
  • No ability to modify. Access therefore stays strictly read-only.
  • A dated, replayable finding. Tenovia retains every setting with its value and collection date.
  • Comparable across audits. The second run reads as a difference: fixed, regressed, unchanged.

The same core as Microsoft 365

Google Workspace collection produces exactly the same evidence format as Microsoft 365 collection. You therefore find the control identifier, the object, the property, the value and the date. Moreover, the same rule engine assesses both platforms, and the same document reports them.

For a group running both environments, or a firm auditing both, that consequently means one console, one format, one method.

What you receive

  • An audit report by domain, with the compliance score and the original wording of each CIS control
  • The technical evidence behind every finding, time-stamped
  • A prioritised remediation plan ranked by severity, effort and gain
  • Finally, the regulatory mapping of every gap to NIS2, DORA, ISO/IEC 27001 or the GDPR

A configuration audit observes settings at a given date. It does not, however, look for compromise, does not test resistance to intrusion, and does not amount to an attestation of compliance. Instead, it provides the technical evidence your compliance programme requires.