Key Settings One-Pager
The essential goal, the features that carry it, the mistake to avoid, and the proof to keep — for each of the ten Brilliant at the Basics requirements. A quick reference to pin up, not a substitute for the full step-by-step guide. Confirm every setting against Google Workspace’s own documentation.
Handling CUI in Workspace requires Assured Controls and careful scoping. Confirm an authorization path before you store CUI.
Phishing-Resistant Multi-Factor Authentication
Make a stolen password useless on its own.
Register at least two keys per admin (one primary, one backup) so a lost key never locks you out of the whole tenant.
2-Step Verification enrollment report · Screenshot of 'Only security key' policy on Admins OU · List of issued security keys/passkeys
Least-Privilege Access Control
Give each person only the access their job needs — and no more.
Never use a Super Admin account for daily email or browsing; keep it separate and use it only when a task truly requires it.
List of admin role assignments · Custom role definitions with privileges · Quarterly access review record
Asset & Account Inventory
Keep a live list of every device, identity, and app you defend.
Set third-party app access to 'blocked by default' and only allow apps you've reviewed, so shadow apps can't quietly connect.
Exported device inventory (dated) · User account list · Connected/third-party app report
Logging, Monitoring & Audit
Record important events and watch for trouble.
Enterprise-tier features unlock the full Security Center and Investigation tool; confirm your edition before promising an auditor those capabilities.
BigQuery log export configuration · Alert center rules and history · Weekly log-review records
Network Segmentation & Boundary Protection
Keep one compromised thing from reaching everything else.
Test in monitor mode first; enforcing an IP or device rule cold can lock you out of your own Admin console.
Context-Aware Access level definitions · App assignment screenshots · Blocked-access log entries
Vulnerability & Patch Management
Find weak spots and fix the risky ones first.
Don't pin devices to an old Chrome version 'for stability'; that leaves known security holes open far longer than any bug is worth.
Chrome/ChromeOS update policy settings · Managed browser version report · Security health page results
Data Protection & Encryption
Scramble sensitive data so only the right people can read it.
You control the CSE keys, so guard the key service carefully; if you lose those keys, the encrypted data is gone for good.
CSE key service configuration · List of OUs/apps with CSE enabled · Sample encrypted Drive file
Backup & Recovery
Be able to restore your data after an attack or outage.
Vault retention is not the same as a true backup; keep an independent copy so a compromised admin can't destroy both the data and its history.
Vault retention rule configuration · Successful test export record · Multi-party approval setting screenshot
Secure Configuration Baseline
Start every service from a known-good, hardened setting.
Save your baseline as a dated document; 'it was set correctly' means nothing to an auditor without proof of what 'correct' is.
Security health page screenshot · Written configuration baseline document · Change/drift alert settings
Secure AI Adoption & Data Loss Prevention
Use AI and share files without leaking sensitive information.
Start DLP rules in audit mode to avoid blocking legitimate work; only flip to enforce after you've reviewed and tuned the false positives.
DLP rule definitions for Drive and Gmail · Gemini data-access configuration · DLP incident/audit report