GWS-CLASS-004: Classroom Roster Import Disabled

Platform
Google Workspace
Category
Gemini for Workspace
Severity
Low
Zero Trust pillar
Applications & Workloads (weight 1)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Roster import via third-party integration should be turned off so that class rosters are not synced from external systems without explicit governance.

Recommended value

Roster import turned OFF

Remediation

Admin Console > Apps > Additional Google services > Classroom > Roster import > Select OFF.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for GWS-CLASS-004
ScenarioExpected verdict
cleanPASS
known-badWARN
no-dataNot Assessed

Framework mappings

CISA SCuBA
GWS.CLASSROOM.3.1v1
NIST SP 800-53
CM-7, AC-4
MITRE ATT&CK
T1195.002