DRIVE-023: Drive for Desktop limited to authorized devices (GWS.DRIVEDOCS.5.1)

Platform
Google Workspace
Category
Drive Security & Data Protection
Severity
High
Zero Trust pillar
Devices (weight 3)
Golden fixtures
5
Branch coverage
Declared verdict paths, each proven by a fixture
Provenance
baseline

What it checks

SCuBA GWS.DRIVEDOCS.5.1: Drive for Desktop synchronizes organizational files onto local disks, so allowing it on unmanaged hardware places a full local copy of Drive content on machines the organization cannot wipe, encrypt or inspect. Reads drive_and_docs.drive_for_desktop and fails where allowDriveForDesktop is on while restrictToAuthorizedDevices is not enforced. Drive for Desktop being off entirely is compliant and the check reports that rather than a bare pass.

Recommended value

Drive for Desktop is disabled, or restricted to company-owned authorized devices

Remediation

Admin console > Apps > Google Workspace > Drive and Docs > Features and Applications > Google Drive for Desktop. Either turn it off, or leave it on and enable 'Only allow Google Drive for Desktop on authorized devices'.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for DRIVE-023
ScenarioExpected verdict
clean-disabledPASS
clean-restrictedPASS
field-missingNot Assessed
known-badFAIL
not-assessedNot Assessed

Framework mappings

CISA SCuBA
GWS.DRIVEDOCS.5.1v1
NIST SP 800-53
AC-19, SC-28, MP-7
MITRE ATT&CK
T1005, T1025