ADMIN-021: Additional Google services without individual control restricted (GWS.COMMONCONTROLS.16.1)

Platform
Google Workspace
Category
Admin & User Management
Severity
Medium
Zero Trust pillar
Applications & Workloads (weight 1)
Golden fixtures
3
Branch coverage
Declared verdict paths, each proven by a fixture
Provenance
baseline

What it checks

SCuBA GWS.COMMONCONTROLS.16.1 recommends that Google services which do not have their own individual admin control be turned OFF for everyone. Google models this with inverted semantics: the enterprise_service_restrictions service must be ENABLED for those additional services to be restricted (blocked). This check reads the enterprise_service_restrictions.service_status Cloud Identity policy and flags any organizational unit where serviceState is not ENABLED, meaning users can still reach unconfigured additional services.

Recommended value

enterprise_service_restrictions serviceState set to ENABLED (additional services restricted) in all organizational units.

Remediation

In the Google Admin console, under Apps > Additional Google services, set the access setting for services without an individual control to OFF for everyone. This enables the enterprise service restriction so users cannot access those additional services.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for ADMIN-021
ScenarioExpected verdict
cleanPASS
known-badWARN
not-assessedNot Assessed

Framework mappings

CISA SCuBA
GWS.COMMONCONTROLS.16.1v1
NIST SP 800-53
CM-7, AC-6