GWS-K12-015: Audit Logging License Coverage
- Platform
- Google Workspace
- Category
- K12 Baseline
- Severity
- Medium
- Zero Trust pillar
- Visibility & Analytics (weight 2)
- Golden fixtures
- 1
- Branch coverage
- Declared verdict paths, each proven by a fixture
- Provenance
- original
- Scope
- Tenant-wide: assessed across the whole tenant, no student OU input required.
Guerrilla K12 Baseline (candidate)
This check assesses control K12-AUDIT-001 of the K12 Secure Configuration Baseline, version 0.1.0, a candidate community baseline authored by Guerrilla. It is openly published and open for comment; it is not a consensus standard, and this block is deliberately separate from the external framework mappings below.
What it checks
Workspace audit logs answer the questions every account incident raises, but researchers found that without a paid license assigned to a user, actions in that user's private Drive can generate no log records, leaving the organization blind to exfiltration. Google called it intended behavior, which makes a license assignment a security control. Assessing it requires each user's Workspace edition/SKU, which the collector does not populate yet, so this control is a documented manual-review item: the check reports Not Assessed and directs a manual confirmation.
Recommended value
Every active user holds a paid license so private-Drive actions are logged (verify manually; edition/SKU not collected yet)
Remediation
Admin Console > Billing > Licenses. Confirm every active user is assigned a paid Workspace license so private-Drive actions generate audit records. Assessment needs each user's edition/SKU, which the collector does not populate yet, so verify coverage by hand.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| manual-review | Not Assessed |
Framework mappings
- NIST SP 800-53
- AU-12
- MITRE ATT&CK
- T1562.008