DRIVE-014: Drive SDK API access disabled (GWS.DRIVEDOCS.4.1)
- Platform
- Google Workspace
- Category
- Drive Security & Data Protection
- Severity
- High
- Zero Trust pillar
- Data (weight 3)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
SCuBA GWS.DRIVEDOCS.4.1: the Drive SDK lets third-party apps read and write Drive content via API, a direct data-exfiltration channel when broadly enabled. Reads drive_and_docs.drive_sdk; fails where enableDriveSdkApiAccess is on.
Recommended value
Drive SDK API access disabled
Remediation
In Admin console > Apps > Google Workspace > Drive and Docs > Features and Applications, disable Drive SDK unless specific reviewed integrations require it.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| bad | FAIL |
| clean | PASS |
| no-data | Not Assessed |
Framework mappings
- CISA SCuBA
- GWS.DRIVEDOCS.4.1v1
- NIST SP 800-53
- AC-4, AC-3, SC-7