DRIVE-017: Default file access set to private to owner (GWS.DRIVEDOCS.1.8)

Platform
Google Workspace
Category
Drive Security & Data Protection
Severity
Medium
Zero Trust pillar
Data (weight 2)
Golden fixtures
3
Branch coverage
Declared verdict paths, each proven by a fixture
Provenance
baseline

What it checks

SCuBA GWS.DRIVEDOCS.1.8 requires that 'Private to owner' be the default access level for newly created Drive items, so files are not shared more broadly than intended at creation time. This check reads the drive_and_docs.general_access_default Cloud Identity policy and flags any organizational unit where the default file access is not PRIVATE_TO_OWNER.

Recommended value

Default access level for new files set to PRIVATE_TO_OWNER (defaultFileAccess) in all organizational units.

Remediation

In the Google Admin console, under Apps > Google Workspace > Drive and Docs > Sharing settings > General access default, set the default to 'Private to owner' so newly created files start private and are shared only by deliberate action.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for DRIVE-017
ScenarioExpected verdict
cleanPASS
known-badFAIL
not-assessedNot Assessed

Framework mappings

CISA SCuBA
GWS.DRIVEDOCS.1.8v1
NIST SP 800-53
AC-3, AC-6