COLLAB-017: Calendar external interoperability managed (GWS.CALENDAR.3.1)

Platform
Google Workspace
Category
Collaboration
Severity
Low
Zero Trust pillar
Governance (weight 1)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA GWS.CALENDAR.3.1 requires that Calendar Interop (sharing free/busy and calendar data with an external system such as Microsoft Exchange) be off unless it is deliberately managed. Interop bridges calendar data to an outside platform. This check reads calendar.interoperability and warns any organizational unit where enableInteroperability is on.

Recommended value

Calendar interoperability disabled unless deliberately managed

Remediation

In the Admin console under Apps > Google Workspace > Calendar > Calendar Interop management, disable interoperability unless a reviewed integration requires it.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for COLLAB-017
ScenarioExpected verdict
cleanPASS
no-dataNot Assessed
warnWARN

Framework mappings

CISA SCuBA
GWS.CALENDAR.3.1v1
NIST SP 800-53
AC-4, SC-7