DRIVE-014: Drive SDK API access disabled (GWS.DRIVEDOCS.4.1)

Platform
Google Workspace
Category
Drive Security & Data Protection
Severity
High
Zero Trust pillar
Data (weight 3)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA GWS.DRIVEDOCS.4.1: the Drive SDK lets third-party apps read and write Drive content via API, a direct data-exfiltration channel when broadly enabled. Reads drive_and_docs.drive_sdk; fails where enableDriveSdkApiAccess is on.

Recommended value

Drive SDK API access disabled

Remediation

In Admin console > Apps > Google Workspace > Drive and Docs > Features and Applications, disable Drive SDK unless specific reviewed integrations require it.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for DRIVE-014
ScenarioExpected verdict
badFAIL
cleanPASS
no-dataNot Assessed

Framework mappings

CISA SCuBA
GWS.DRIVEDOCS.4.1v1
NIST SP 800-53
AC-4, AC-3, SC-7