ADMIN-010: Groups Settings and External Membership
- Platform
- Google Workspace
- Category
- Admin & User Management
- Severity
- High
- Zero Trust pillar
- Governance (weight 2)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
Google Groups that allow external members can expose internal communications and data to unauthorized parties
Recommended value
External group membership disabled or restricted to specific groups with documented justification
Remediation
Admin Console > Apps > Google Workspace > Groups for Business > Sharing settings > Restrict external membership
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| no-data | Not Assessed |
Framework mappings
- NIST SP 800-53
- AC-3, AC-4
- CIS Benchmark
- 4.10
- MITRE ATT&CK
- T1530, T1213.003