GROUP-002: Group owners cannot add external members (GWS.GROUPS.1.2)
- Platform
- Google Workspace
- Category
- Collaboration
- Severity
- Medium
- Zero Trust pillar
- Data (weight 2)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
SCuBA GWS.GROUPS.1.2 requires that group owners not be permitted to add members from outside the organization. External members gain access to everything shared with the group. This check flags organizational units where owners can allow external members (ownersCanAllowExternalMembers is enabled).
Recommended value
Group owners cannot allow external members (ownersCanAllowExternalMembers disabled)
Remediation
In Groups for Business sharing settings, disable the option that lets group owners add members from outside the organization, so external membership requires administrative action.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| no-data | Not Assessed |
Framework mappings
- CISA SCuBA
- GWS.GROUPS.1.2v1
- NIST SP 800-53
- AC-2, AC-3, SC-7