GROUP-002: Group owners cannot add external members (GWS.GROUPS.1.2)

Platform
Google Workspace
Category
Collaboration
Severity
Medium
Zero Trust pillar
Data (weight 2)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA GWS.GROUPS.1.2 requires that group owners not be permitted to add members from outside the organization. External members gain access to everything shared with the group. This check flags organizational units where owners can allow external members (ownersCanAllowExternalMembers is enabled).

Recommended value

Group owners cannot allow external members (ownersCanAllowExternalMembers disabled)

Remediation

In Groups for Business sharing settings, disable the option that lets group owners add members from outside the organization, so external membership requires administrative action.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for GROUP-002
ScenarioExpected verdict
cleanPASS
known-badFAIL
no-dataNot Assessed

Framework mappings

CISA SCuBA
GWS.GROUPS.1.2v1
NIST SP 800-53
AC-2, AC-3, SC-7