ADMIN-021: Additional Google services without individual control restricted (GWS.COMMONCONTROLS.16.1)
- Platform
- Google Workspace
- Category
- Admin & User Management
- Severity
- Medium
- Zero Trust pillar
- Applications & Workloads (weight 1)
- Golden fixtures
- 3
- Branch coverage
- Declared verdict paths, each proven by a fixture
- Provenance
- baseline
What it checks
SCuBA GWS.COMMONCONTROLS.16.1 recommends that Google services which do not have their own individual admin control be turned OFF for everyone. Google models this with inverted semantics: the enterprise_service_restrictions service must be ENABLED for those additional services to be restricted (blocked). This check reads the enterprise_service_restrictions.service_status Cloud Identity policy and flags any organizational unit where serviceState is not ENABLED, meaning users can still reach unconfigured additional services.
Recommended value
enterprise_service_restrictions serviceState set to ENABLED (additional services restricted) in all organizational units.
Remediation
In the Google Admin console, under Apps > Additional Google services, set the access setting for services without an individual control to OFF for everyone. This enables the enterprise service restriction so users cannot access those additional services.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | WARN |
| not-assessed | Not Assessed |
Framework mappings
- CISA SCuBA
- GWS.COMMONCONTROLS.16.1v1
- NIST SP 800-53
- CM-7, AC-6