COLLAB-017: Calendar external interoperability managed (GWS.CALENDAR.3.1)
- Platform
- Google Workspace
- Category
- Collaboration
- Severity
- Low
- Zero Trust pillar
- Governance (weight 1)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
SCuBA GWS.CALENDAR.3.1 requires that Calendar Interop (sharing free/busy and calendar data with an external system such as Microsoft Exchange) be off unless it is deliberately managed. Interop bridges calendar data to an outside platform. This check reads calendar.interoperability and warns any organizational unit where enableInteroperability is on.
Recommended value
Calendar interoperability disabled unless deliberately managed
Remediation
In the Admin console under Apps > Google Workspace > Calendar > Calendar Interop management, disable interoperability unless a reviewed integration requires it.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| no-data | Not Assessed |
| warn | WARN |
Framework mappings
- CISA SCuBA
- GWS.CALENDAR.3.1v1
- NIST SP 800-53
- AC-4, SC-7