DRIVE-012: Drive Add-ons Settings

Platform
Google Workspace
Category
Drive Security & Data Protection
Severity
Low
Zero Trust pillar
Data (weight 1)
Golden fixtures
1
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Drive add-ons can access file content and should be controlled to prevent data exposure through untrusted extensions

Recommended value

Drive add-on installation restricted to admin-approved add-ons

Remediation

Admin Console > Apps > Google Workspace > Drive and Docs > Features and Applications > Add-ons > Configure installation restrictions

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for DRIVE-012
ScenarioExpected verdict
always-warnWARN

Framework mappings

NIST SP 800-53
CM-7, CM-11
CIS Benchmark
2.12
MITRE ATT&CK
T1195.002