GWS-K12-009: Departed Student Account Disposition

Platform
Google Workspace
Category
K12 Baseline
Severity
Medium
Zero Trust pillar
Identity (weight 2)
Golden fixtures
6
Branch coverage
Declared verdict paths, each proven by a fixture
Provenance
original
Scope
OU-scoped: requires the -StudentOU input (or the Student OUs field in Show-Guerrilla). Without it, this check reports Not Assessed.

Guerrilla K12 Baseline (candidate)

This check assesses control K12-LIFE-001 of the K12 Secure Configuration Baseline, version 0.1.0, a candidate community baseline authored by Guerrilla. It is openly published and open for comment; it is not a consensus standard, and this block is deliberately separate from the external framework mappings below.

Read the K12 Baseline

What it checks

Graduation and withdrawal produce accounts nobody owns. An active account belonging to a departed student is an unwatched identity that still receives mail and still holds data. This check surfaces accounts in the student OUs that are active but have not signed in for a year or more, and reminds the district that suspended accounts still hold Drive data whose ownership should be resolved before deletion.

Recommended value

Departed students are suspended or archived on departure; no student account stays active with a year of no sign-ins

Remediation

Admin Console > Directory > Users. Filter to the student organizational unit and sort by Last sign-in. Suspend or archive accounts belonging to withdrawn or graduated students. Before deleting suspended accounts, transfer Drive ownership (Admin Console > Directory > Users > select user > Delete > transfer content) or export via Takeout/Vault as your retention policy requires.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for GWS-K12-009
ScenarioExpected verdict
cleanPASS
empty-ouWARN
known-badWARN
no-scopeNot Assessed
not-assessedNot Assessed
ou-absentNot Assessed

Framework mappings

NIST SP 800-53
AC-2
MITRE ATT&CK
T1078.004