GWS-K12-012: Student Data Export (Takeout) Disabled
- Platform
- Google Workspace
- Category
- K12 Baseline
- Severity
- Medium
- Zero Trust pillar
- Data (weight 1)
- Golden fixtures
- 1
- Branch coverage
- Declared verdict paths, each proven by a fixture
- Provenance
- original
- Scope
- Tenant-wide: assessed across the whole tenant, no student OU input required.
Guerrilla K12 Baseline (candidate)
This check assesses control K12-DATA-005 of the K12 Secure Configuration Baseline, version 0.1.0, a candidate community baseline authored by Guerrilla. It is openly published and open for comment; it is not a consensus standard, and this block is deliberately separate from the external framework mappings below.
What it checks
Google Takeout is a supported one-click export of a user's whole Drive and Gmail; on the way out the door, or in the hands of a compromised account, it is a bulk exfiltration tool. Takeout is configurable per OU in the Admin console, but no Cloud Identity policy surface currently exposes its state for automated reading, so this control is a documented manual-review item: the check reports Not Assessed and directs a manual confirmation rather than assuming a value it cannot read.
Recommended value
Google Takeout is turned off for student OUs (verify manually; no config API exposes this today)
Remediation
Admin Console > Account > Account settings > Takeout. Select the student organizational unit and turn Takeout off so a one-click bulk export of Drive and Gmail is not available to students. No Cloud Identity policy surface exposes this state, so confirm it by hand.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| manual-review | Not Assessed |
Framework mappings
- NIST SP 800-53
- AC-4
- MITRE ATT&CK
- T1567