U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Google Workspace Classroom 1.0.1 Checklist Details (Checklist Revisions)

Supporting Resources:

Target:

Target CPE Name
Google Workspace (GWS) cpe:/a:google:workspace:- (View CVEs)

Checklist Highlights

Checklist Name:
Google Workspace Classroom
Checklist ID:
1356
Version:
1.0.1
Type:
Compliance
Review Status:
Candidate
Authority:
Governmental Authority: Cybersecurity and Infrastructure Security Agency (CISA)
Original Publication Date:
07/27/2026

Checklist Summary:

Google Classroom is a service in Google Workspace (GWS) to streamline assignments, boost collaboration, and foster communication. This service allows for the creation of classes, creating and grading assignments, student collaboration, communication with teachers and students, and integration with other Google products.

Checklist Role:

  • Business Productivity Application

Known Issues:

None

Target Audience:

Not required for Federal agencies. Google Classroom is designed and intended for implementation in educational institutions. Google Classroom is available with the Google Workspace (GWS) for Education Edition and is included with all tiers of GWS for Education including Fundamentals, Standard, and Plus. CISA's Secure Configuration Baseline (SCB) Google Classroom policies and guidance are written to correspond with the Plus edition. The CISA SCuBA SCBs for GWS help secure federal information assets stored within GWS cloud business application environments through consistent, effective, and manageable security configurations. CISA created baselines tailored to the federal government's threats and risk tolerance. Organizations outside of the federal government may also find these baselines to be useful references to help reduce risks even if such organizations have different risk tolerances or face different threats.

Target Operational Environment:

  • Legacy
  • Managed
  • Sector-Specific Environment

Testing Information:

Internal and external testing completed with each release.

Regulatory Compliance:

n/a

Comments/Warnings/Miscellaneous:

n/a

Disclaimer:

For non-federal users, the information in this document is being provided "as is" for INFORMATIONAL PURPOSES ONLY. CISA does not endorse any commercial product or service, including any subjects of analysis. Any reference to specific commercial entities or commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoritism by CISA. Without limiting the generality of the foregoing, some controls and settings are not available in all products. CISA has no control over vendor changes to products offerings or features. Accordingly, these SCuBA SCBs for GWS may not be applicable to the products available to you. This document does not address, ensure compliance with, or supersede any law, regulation, or other authority. Entities are responsible for complying with any recordkeeping, privacy, and other laws that may apply to the use of technology. This document is not intended to, and does not, create any right or benefit for anyone against the United States, its departments, agencies, or entities, its officers, employees, or agents, or any other person.

Product Support:

Users are encourage to use the GitHub https://github.com/cisagov/ScubaGoggles and look in the issues tab for comprehensive Q&A. For support past that we urge users to reach SCuBA at [email protected]

Point of Contact:

[email protected]

Sponsor:

Cybersecurity and Infrastructure Security Agency's (CISA)

Licensing:

https://github.com/cisagov/ScubaGoggles/blob/main/LICENSE For non-federal users, the information in this document is being provided "as is" for INFORMATIONAL PURPOSES ONLY. CISA does not endorse any commercial product or service, including any subjects of analysis. Any reference to specific commercial entities or commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoritism by CISA. Without limiting the generality of the foregoing, some controls and settings are not available in all products. CISA has no control over vendor changes to products offerings or features. Accordingly, these SCuBA SCBs for GWS may not be applicable to the products available to you. This document does not address, ensure compliance with, or supersede any law, regulation, or other authority. Entities are responsible for complying with any recordkeeping, privacy, and other laws that may apply to the use of technology. This document is not intended to, and does not, create any right or benefit for anyone against the United States, its departments, agencies, or entities, its officers, employees, or agents, or any other person.

Change History:



					

Dependency/Requirements:

URL Description

References:

Reference URL Description
https://github.com/cisagov/ScubaGoggles/blob/main/scubagoggles/baselines/classroom.md Location of SCB on Github

NIST checklist record last modified on 08/05/2026


* This checklist is still undergoing review for inclusion into the NCP.