DRIVE-017: Default file access set to private to owner (GWS.DRIVEDOCS.1.8)
- Platform
- Google Workspace
- Category
- Drive Security & Data Protection
- Severity
- Medium
- Zero Trust pillar
- Data (weight 2)
- Golden fixtures
- 3
- Branch coverage
- Declared verdict paths, each proven by a fixture
- Provenance
- baseline
What it checks
SCuBA GWS.DRIVEDOCS.1.8 requires that 'Private to owner' be the default access level for newly created Drive items, so files are not shared more broadly than intended at creation time. This check reads the drive_and_docs.general_access_default Cloud Identity policy and flags any organizational unit where the default file access is not PRIVATE_TO_OWNER.
Recommended value
Default access level for new files set to PRIVATE_TO_OWNER (defaultFileAccess) in all organizational units.
Remediation
In the Google Admin console, under Apps > Google Workspace > Drive and Docs > Sharing settings > General access default, set the default to 'Private to owner' so newly created files start private and are shared only by deliberate action.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| not-assessed | Not Assessed |
Framework mappings
- CISA SCuBA
- GWS.DRIVEDOCS.1.8v1
- NIST SP 800-53
- AC-3, AC-6