GWS-K12-012: Student Data Export (Takeout) Disabled

Platform
Google Workspace
Category
K12 Baseline
Severity
Medium
Zero Trust pillar
Data (weight 1)
Golden fixtures
1
Branch coverage
Declared verdict paths, each proven by a fixture
Provenance
original
Scope
Tenant-wide: assessed across the whole tenant, no student OU input required.

Guerrilla K12 Baseline (candidate)

This check assesses control K12-DATA-005 of the K12 Secure Configuration Baseline, version 0.1.0, a candidate community baseline authored by Guerrilla. It is openly published and open for comment; it is not a consensus standard, and this block is deliberately separate from the external framework mappings below.

Read the K12 Baseline

What it checks

Google Takeout is a supported one-click export of a user's whole Drive and Gmail; on the way out the door, or in the hands of a compromised account, it is a bulk exfiltration tool. Takeout is configurable per OU in the Admin console, but no Cloud Identity policy surface currently exposes its state for automated reading, so this control is a documented manual-review item: the check reports Not Assessed and directs a manual confirmation rather than assuming a value it cannot read.

Recommended value

Google Takeout is turned off for student OUs (verify manually; no config API exposes this today)

Remediation

Admin Console > Account > Account settings > Takeout. Select the student organizational unit and turn Takeout off so a one-click bulk export of Drive and Gmail is not available to students. No Cloud Identity policy surface exposes this state, so confirm it by hand.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for GWS-K12-012
ScenarioExpected verdict
manual-reviewNot Assessed

Framework mappings

NIST SP 800-53
AC-4
MITRE ATT&CK
T1567