GWS-K12-011: Student Auto-Forwarding Disabled

Platform
Google Workspace
Category
K12 Baseline
Severity
Medium
Zero Trust pillar
Data (weight 1)
Golden fixtures
6
Branch coverage
Declared verdict paths, each proven by a fixture
Provenance
original
Scope
OU-scoped: requires the -StudentOU input (or the Student OUs field in Show-Guerrilla). Without it, this check reports Not Assessed.

Guerrilla K12 Baseline (candidate)

This check assesses control K12-DATA-004 of the K12 Secure Configuration Baseline, version 0.1.0, a candidate community baseline authored by Guerrilla. It is openly published and open for comment; it is not a consensus standard, and this block is deliberately separate from the external framework mappings below.

Read the K12 Baseline

What it checks

A single Gmail auto-forwarding rule silently copies every future message to an external address, and it survives a password reset because it is a setting, not a session. Staff occasionally have a legitimate need; a student OU does not, and leaving the capability on is a standing exfiltration and account-persistence path. This check resolves the Gmail automatic-forwarding end-user setting for each student OU.

Recommended value

Automatic email forwarding is disabled for student OUs

Remediation

Admin Console > Apps > Google Workspace > Gmail > End User Access. Select the student organizational unit and turn off 'Automatic forwarding' so users in the OU cannot configure forwarding rules. Apply the same to any staff OU with no business need.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for GWS-K12-011
ScenarioExpected verdict
cleanPASS
known-badFAIL
no-policyWARN
no-scopeNot Assessed
not-assessedNot Assessed
ou-absentNot Assessed

Framework mappings

NIST SP 800-53
AC-4
MITRE ATT&CK
T1114.003