DRIVE-010: Drive DLP Rules Audit

Platform
Google Workspace
Category
Drive Security & Data Protection
Severity
Medium
Zero Trust pillar
Data (weight 1)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Data Loss Prevention rules should be configured to detect and prevent sharing of sensitive data through Google Drive

Recommended value

DLP rules configured for sensitive data types (PII, financial, health data)

Remediation

Admin Console > Security > Data protection > Manage rules > Create rules for sensitive data types in Drive

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for DRIVE-010
ScenarioExpected verdict
cleanPASS
known-badWARN
no-dataNot Assessed

Framework mappings

NIST SP 800-53
SC-7, SI-4
CIS Benchmark
2.10
MITRE ATT&CK
T1567, T1048