GWS-K12-007: Guardian Access Integrity

Platform
Google Workspace
Category
K12 Baseline
Severity
Medium
Zero Trust pillar
Identity (weight 1)
Golden fixtures
7
Branch coverage
Declared verdict paths, each proven by a fixture
Provenance
original
Scope
OU-scoped: requires the -StudentOU input (or the Student OUs field in Show-Guerrilla). Without it, this check reports Not Assessed.

Guerrilla K12 Baseline (candidate)

This check assesses control K12-SAFE-002 of the K12 Secure Configuration Baseline, version 0.1.0, a candidate community baseline authored by Guerrilla. It is openly published and open for comment; it is not a consensus standard, and this block is deliberately separate from the external framework mappings below.

Read the K12 Baseline

What it checks

Guardian email summaries exist so parents see their own student's activity. The integrity property that is machine-assessable is who can register and remove guardians: domain admins only is the narrow surface; verified teachers widen it and require a documented identity-check procedure. How the district verifies a guardian's identity before inviting them is a policy review item this check cannot read. Findings describe configuration posture, not incidents.

Recommended value

If guardian access is enabled, guardian management is restricted to domain admins, or a documented teacher-side verification procedure exists

Remediation

Admin Console > Apps > Google Workspace > Classroom > Guardian access. Select the student organizational unit. If guardian summaries are in use, set 'Who can manage guardians' to domain admins only, or document the verification procedure teachers must follow before inviting a guardian.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for GWS-K12-007
ScenarioExpected verdict
cleanPASS
disabledPASS
no-policyWARN
no-scopeNot Assessed
not-assessedNot Assessed
ou-absentNot Assessed
teacher-managedWARN

Framework mappings

NIST SP 800-53
AC-2