GWS-K12-001: Student OU Sharing Not Inherited From Staff

Platform
Google Workspace
Category
K12 Baseline
Severity
Medium
Zero Trust pillar
Data (weight 1)
Golden fixtures
8
Branch coverage
Declared verdict paths, each proven by a fixture
Provenance
original
Scope
OU-scoped: requires the -StudentOU input (or the Student OUs field in Show-Guerrilla). Without it, this check reports Not Assessed.

Guerrilla K12 Baseline (candidate)

This check assesses control K12-DATA-001 of the K12 Secure Configuration Baseline, version 0.1.0, a candidate community baseline authored by Guerrilla. It is openly published and open for comment; it is not a consensus standard, and this block is deliberately separate from the external framework mappings below.

Read the K12 Baseline

What it checks

Districts commonly configure Drive external sharing for staff needs and let student OUs inherit that configuration. Inheritance is invisible in day-to-day administration: the student OU shows a value, but nobody chose it for students. External-sharing configuration on student OUs should be an explicit local decision, or an inherited value that is fully disabled.

Recommended value

Drive external-sharing configuration is applied locally on each student OU, or the inherited value is DISALLOWED

Remediation

Admin Console > Apps > Google Workspace > Drive and Docs > Sharing settings. Select the student organizational unit in the left panel and set 'Sharing outside of your organization' explicitly for that OU (the setting shows 'Locally applied' when it is a local decision, 'Inherited' otherwise).

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for GWS-K12-001
ScenarioExpected verdict
cleanPASS
inherited-cleanPASS
inherited-warnWARN
known-badFAIL
no-policyWARN
no-scopeNot Assessed
not-assessedNot Assessed
ou-absentNot Assessed

Framework mappings

NIST SP 800-53
CM-6
MITRE ATT&CK
T1567