GWS-K12-014: Vault Export And Retention Privileges Restricted

Platform
Google Workspace
Category
K12 Baseline
Severity
High
Zero Trust pillar
Identity (weight 2)
Golden fixtures
3
Branch coverage
Declared verdict paths, each proven by a fixture
Provenance
original
Scope
Tenant-wide: assessed across the whole tenant, no student OU input required.

Guerrilla K12 Baseline (candidate)

This check assesses control K12-IDENT-004 of the K12 Secure Configuration Baseline, version 0.1.0, a candidate community baseline authored by Guerrilla. It is openly published and open for comment; it is not a consensus standard, and this block is deliberately separate from the external framework mappings below.

Read the K12 Baseline

What it checks

Google Vault is administrative reach over the whole tenant. 'Manage Exports' can download any user's mailbox and Drive at any time; 'Manage Retention Rules' can permanently delete records a misconfigured rule sweeps up. These privileges ride on admin roles and accumulate the way delegated-admin roles do. This check surfaces admin role assignments whose privileges match Vault export, retention, hold, matter, or eDiscovery management; whether each holder is legitimate is the district's determination, so it reports a review list rather than a hard failure. The retention rules themselves are reviewed in Vault directly.

Recommended value

Every Vault export or retention privilege maps to a known, current administrator who needs it

Remediation

Admin Console > Account > Admin roles. For each role flagged as carrying a Vault export, retention, hold, matter, or eDiscovery privilege, confirm the holder needs it; remove the privilege or the assignment where they do not. Review current retention rules in Vault directly (vault.google.com > Retention).

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for GWS-K12-014
ScenarioExpected verdict
cleanPASS
known-badWARN
not-assessedNot Assessed

Framework mappings

NIST SP 800-53
AC-6, AU-9
MITRE ATT&CK
T1114, T1530