GWS-K12-011: Student Auto-Forwarding Disabled
- Platform
- Google Workspace
- Category
- K12 Baseline
- Severity
- Medium
- Zero Trust pillar
- Data (weight 1)
- Golden fixtures
- 6
- Branch coverage
- Declared verdict paths, each proven by a fixture
- Provenance
- original
- Scope
- OU-scoped: requires the -StudentOU input (or the Student OUs field in Show-Guerrilla). Without it, this check reports Not Assessed.
Guerrilla K12 Baseline (candidate)
This check assesses control K12-DATA-004 of the K12 Secure Configuration Baseline, version 0.1.0, a candidate community baseline authored by Guerrilla. It is openly published and open for comment; it is not a consensus standard, and this block is deliberately separate from the external framework mappings below.
What it checks
A single Gmail auto-forwarding rule silently copies every future message to an external address, and it survives a password reset because it is a setting, not a session. Staff occasionally have a legitimate need; a student OU does not, and leaving the capability on is a standing exfiltration and account-persistence path. This check resolves the Gmail automatic-forwarding end-user setting for each student OU.
Recommended value
Automatic email forwarding is disabled for student OUs
Remediation
Admin Console > Apps > Google Workspace > Gmail > End User Access. Select the student organizational unit and turn off 'Automatic forwarding' so users in the OU cannot configure forwarding rules. Apply the same to any staff OU with no business need.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| no-policy | WARN |
| no-scope | Not Assessed |
| not-assessed | Not Assessed |
| ou-absent | Not Assessed |
Framework mappings
- NIST SP 800-53
- AC-4
- MITRE ATT&CK
- T1114.003