GROUP-005: Group conversation visibility defaults to members (GWS.GROUPS.3.1)

Platform
Google Workspace
Category
Collaboration
Severity
Low
Zero Trust pillar
Data (weight 2)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA GWS.GROUPS.3.1 requires that the default permission for viewing group conversations be restricted to group members rather than the whole domain or the public. Overly-open conversation visibility exposes discussion archives — which can contain sensitive student and staff information. This check reads viewTopicsDefaultAccessLevel from the groups_for_business.groups_sharing policy and warns where the default is broader than group members.

Recommended value

Default conversation view access set to GROUP_MEMBERS

Remediation

In Groups for Business settings, set the default 'who can view conversations' permission to group members.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for GROUP-005
ScenarioExpected verdict
cleanPASS
not-assessedNot Assessed
warnWARN

Framework mappings

CISA SCuBA
GWS.GROUPS.3.1v1
NIST SP 800-53
AC-3, AC-22