DRIVE-016: Drive file security update enforced (GWS.DRIVEDOCS.3.1)
- Platform
- Google Workspace
- Category
- Drive Security & Data Protection
- Severity
- Medium
- Zero Trust pillar
- Data (weight 2)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
SCuBA GWS.DRIVEDOCS.3.1: the file security update tightens link-sharing on affected files; letting users remove it re-opens access. Reads drive_and_docs.file_security_update; warns where users are allowed to remove/manage the security update.
Recommended value
Security update applied and users cannot remove it
Remediation
In Drive settings, apply the file security update and do not allow users to remove it from files they own.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| bad | WARN |
| clean | PASS |
| no-data | Not Assessed |
Framework mappings
- CISA SCuBA
- GWS.DRIVEDOCS.3.1v1
- NIST SP 800-53
- AC-3, CM-6