Skip to content
Community previewValidate controls against current Google documentation.Report a gap

NIST/FedRAMP Controls Testing Guide

This comprehensive guide provides practical testing methodologies and checklists for evaluating NIST and FedRAMP security controls in Google Cloud Platform (GCP) and Google Workspace environments. Whether you’re preparing for a FedRAMP assessment, conducting internal audits, or implementing NIST controls, these resources will help ensure thorough compliance validation.

  • Standardized Testing: Provide consistent methodologies for testing NIST/FedRAMP controls
  • Google-Specific Guidance: Focus on GCP and Google Workspace implementation details
  • Practical Tools: Include CLI commands, automation scripts, and assessment checklists
  • Evidence Collection: Guide assessors in gathering appropriate documentation and artifacts
Control family Scope Guide
Access Control (AC) User access, permissions, and authentication mechanisms GCP Access Control Testing
Configuration Management (CM) Baselines, change control, and security settings GCP Configuration Management
Identification & Authentication (IA) Identity management, MFA, and credential policy GCP Identity & Authentication
System & Communications Protection (SC) Network security, encryption, and data protection GCP Communications Protection
System & Information Integrity (SI) Monitoring, vulnerability management, and integrity GCP System Integrity

Workspace-specific control-testing guides are on the project roadmap. Until those are complete, use the general Workspace security guides and record product-specific evidence and inheritance assumptions explicitly.

  • Step-by-step verification procedures
  • Required evidence documentation
  • Common implementation patterns
  • gcloud CLI commands for evidence collection
  • API queries for automated testing
  • Security Command Center integration
  • Pre-configured compliance reports
  • Evidence collection templates
  • Finding documentation formats
  • Policy-as-Code examples
  • Continuous compliance monitoring
  • Integration with GCP native tools
  1. Identify Your Baseline: Determine which FedRAMP baseline (Low, Moderate, High) or NIST framework applies
  2. Review Control Families: Navigate to relevant control family guides
  3. Execute Testing: Follow the checklists and use provided commands
  4. Document Findings: Use templates to record evidence and observations
  5. Remediate Issues: Address any identified gaps or deficiencies
  • ✅ GCP Access Control (AC) Testing Guide
  • ✅ GCP Configuration Management (CM) Testing Guide
  • ✅ GCP Identification & Authentication (IA) Testing Guide
  • ✅ GCP System & Communications Protection (SC) Testing Guide
  • ✅ GCP System & Information Integrity (SI) Testing Guide
  • 🚧 Google Workspace Access Control Testing Guide
  • 🚧 Google Workspace Data Protection Guide
  • 🚧 Automated Compliance Scanning Tools
  • 🚧 Integration with Security Command Center
  • 🚧 Continuous Compliance Monitoring Playbooks

We welcome contributions to improve and expand these testing guides. Please see our Contributing Guidelines for more information.

For questions, corrections, or support regarding these testing guides, open a GitHub issue.

Page provenance

Community-maintained guidance. Use the edit link below to propose a sourced correction.

Contributors

Was this page useful?

Help us prioritize the next improvement.