GWS-K12-002: Student External Drive Sharing Restricted

Platform
Google Workspace
Category
K12 Baseline
Severity
High
Zero Trust pillar
Data (weight 2)
Golden fixtures
8
Branch coverage
Declared verdict paths, each proven by a fixture
Provenance
original
Scope
OU-scoped: requires the -StudentOU input (or the Student OUs field in Show-Guerrilla). Without it, this check reports Not Assessed.

Guerrilla K12 Baseline (candidate)

This check assesses control K12-DATA-002 of the K12 Secure Configuration Baseline, version 0.1.0, a candidate community baseline authored by Guerrilla. It is openly published and open for comment; it is not a consensus standard, and this block is deliberately separate from the external framework mappings below.

Read the K12 Baseline

What it checks

Whatever the staff posture, student OUs should not permit unrestricted silent sharing outside the organization. Defensible student postures range from fully disabled to allowlisted domains; sharing that is on with a warning prompt is the weakest acceptable floor and should be a deliberate district decision for the age band.

Recommended value

Student OU external Drive sharing is DISALLOWED or restricted to allowlisted domains; if ALLOWED, the external-sharing warning is enabled and the choice is documented

Remediation

Admin Console > Apps > Google Workspace > Drive and Docs > Sharing settings. Select the student organizational unit and set 'Sharing outside of your organization' to Off or Allowlisted domains. If the district deliberately permits external sharing for a student OU, enable 'Warn when files owned by users in your organization are shared outside' at minimum.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for GWS-K12-002
ScenarioExpected verdict
allowlistedPASS
cleanPASS
known-badFAIL
no-policyWARN
no-scopeNot Assessed
not-assessedNot Assessed
ou-absentNot Assessed
warn-on-externalWARN

Framework mappings

NIST SP 800-53
AC-3, AC-4
MITRE ATT&CK
T1567, T1537