GWS-K12-014: Vault Export And Retention Privileges Restricted
- Platform
- Google Workspace
- Category
- K12 Baseline
- Severity
- High
- Zero Trust pillar
- Identity (weight 2)
- Golden fixtures
- 3
- Branch coverage
- Declared verdict paths, each proven by a fixture
- Provenance
- original
- Scope
- Tenant-wide: assessed across the whole tenant, no student OU input required.
Guerrilla K12 Baseline (candidate)
This check assesses control K12-IDENT-004 of the K12 Secure Configuration Baseline, version 0.1.0, a candidate community baseline authored by Guerrilla. It is openly published and open for comment; it is not a consensus standard, and this block is deliberately separate from the external framework mappings below.
What it checks
Google Vault is administrative reach over the whole tenant. 'Manage Exports' can download any user's mailbox and Drive at any time; 'Manage Retention Rules' can permanently delete records a misconfigured rule sweeps up. These privileges ride on admin roles and accumulate the way delegated-admin roles do. This check surfaces admin role assignments whose privileges match Vault export, retention, hold, matter, or eDiscovery management; whether each holder is legitimate is the district's determination, so it reports a review list rather than a hard failure. The retention rules themselves are reviewed in Vault directly.
Recommended value
Every Vault export or retention privilege maps to a known, current administrator who needs it
Remediation
Admin Console > Account > Admin roles. For each role flagged as carrying a Vault export, retention, hold, matter, or eDiscovery privilege, confirm the holder needs it; remove the privilege or the assignment where they do not. Review current retention rules in Vault directly (vault.google.com > Retention).
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | WARN |
| not-assessed | Not Assessed |
Framework mappings
- NIST SP 800-53
- AC-6, AU-9
- MITRE ATT&CK
- T1114, T1530