Ensure allow users to add and use incoming webhooks is disabled (Manual)
Description
Allow users to configure incoming webhooks and developers to call incoming webhooks to post content. Incoming webhooks let you send asynchronous messages into Google Chat from applications that aren't Chat apps.
Rationale
Webhook usage should be carefully controlled (vetted and approved) since a malicious application could send bogus information to exposed webhooks and ultimately these users.
Impact
By default users will have exposed webhooks.
Audit Procedure
Using Google Workspace Admin Console
- Log in to https://admin.google.com as an administrator
- Select
Apps - Select
Google Chat and classic Hangouts - Select
Chat apps - Under
Chat apps access settings, verifyAllow users to add and use incoming webhooksis OFF
Expected Result
Allow users to add and use incoming webhooks should be OFF.
Remediation
Using Google Workspace Admin Console
- Log in to https://admin.google.com as an administrator
- Select
Apps - Select
Google Chat and classic Hangouts - Select
Chat apps - Under
Chat apps access settings, setAllow users to add and use incoming webhooksto OFF
Default Value
Allow users to add and use incoming webhooks is ON
CIS Controls
This control does not have explicit CIS Controls mappings in the PDF.
Profile
Level 1