Línea base K12 Línea base comunitaria candidata

Los tenants escolares contienen adultos y menores en un mismo tenant, con deberes legales distintos hacia cada grupo, y la frontera entre ellos es un subárbol de unidades organizativas, no el tenant. Ninguna línea base de consenso evalúa hoy esa frontera. Esta línea base propone controles que sí lo hacen. Todo en esta página se deriva del documento de la línea base en el repositorio del módulo y de las comprobaciones que reclaman sus controles; la compilación falla si no coinciden.

Versión 0.1.0 (Candidate). 10 de 12 controles se evalúan mediante 10 comprobaciones; el resto lo dice honestamente más abajo. El documento de la línea base es la fuente de verdad; gobierna la versión del repositorio del módulo.

¿Busca la cobertura de estándares de consenso (CISA SCuBA, EIDSCA, CIS, NIST)? Está en la tabla cruzada de líneas base, que es un tipo de página distinto sobre un tipo de autoridad distinto. Tabla cruzada de líneas base

Data protection and sharing

K12-DATA-001 Student OUs do not inherit staff external-sharing defaults

Por unidad organizativa Machine-assessable Estándar (semántica PASS/FAIL)

Se evalúa contra el subárbol de OU de estudiantes. Requiere el parámetro -StudentOU (o el campo Student OUs en Show-Guerrilla); sin él, la comprobación informa No evaluado en lugar de evaluar todo el tenant como si fuera la población estudiantil.

Justificación
Districts commonly configure Drive external sharing for the needs of staff (vendors, parents, other districts) and let student OUs inherit that configuration. Inheritance is invisible in day-to-day administration: the student OU shows a value, but nobody chose it for students. This control requires that external-sharing configuration on student OUs be an explicit, local decision rather than an inherited staff default.
Amenaza abordada
Student documents shared outside the district without any deliberate decision that students should be able to do that. Exposure of student work, names, and metadata to arbitrary external accounts.
Ajustes evaluados
Drive and Docs sharing settings on each student OU (Admin console: Apps > Google Workspace > Drive and Docs > Sharing settings), specifically whether the external-sharing configuration on the student OU is locally applied or inherited from a parent OU whose population is staff.
Evaluado por
GWS-K12-001

K12-DATA-002 Student external Drive sharing is disabled or restricted

Por unidad organizativa Machine-assessable Estándar (semántica PASS/FAIL)

Se evalúa contra el subárbol de OU de estudiantes. Requiere el parámetro -StudentOU (o el campo Student OUs en Show-Guerrilla); sin él, la comprobación informa No evaluado en lugar de evaluar todo el tenant como si fuera la población estudiantil.

Justificación
Whatever the staff posture, student OUs should not permit unrestricted sharing outside the organization. Reasonable district positions range from fully disabled to allowlisted-domains to warn-on-external for older students; unrestricted silent external sharing is not a defensible student default at any age band.
Amenaza abordada
Deliberate or accidental exfiltration of student documents to external accounts; students sharing personal information with unknown external parties through Drive.
Ajustes evaluados
Drive and Docs external-sharing mode on each student OU (off, allowlisted domains, or on), and whether the warn-on-external-sharing prompt is enabled when sharing is not fully disabled.
Evaluado por
GWS-K12-002

K12-DATA-003 Student data is not excluded from retention

Todo el tenant Machine-assisted + policy review Dependiente del contexto (elementos de revisión contra la política de su distrito, no fallos duros)

Justificación
Student mail and Drive content is frequently the record of an incident: bullying, threats, grooming attempts, self-harm signals. Districts that exclude student OUs from retention (or never license or configure Vault for students) discover this during an investigation, when it is too late. Retention duration is a district policy decision; having student data covered by some deliberate retention decision is the control.
Amenaza abordada
Inability to reconstruct communications during a safeguarding, legal, or disciplinary investigation because student data was never retained.
Ajustes evaluados
Vault licensing and default retention rules as they apply to student OUs; whether student mail and Drive are excluded from retention coverage. ---
Evaluado por
Aún sin cobertura: ninguna comprobación evalúa este control todavía. El trabajo de recolección necesario está registrado en las propuestas del módulo.

Identity and third-party access

K12-IDENT-001 Students cannot authorize third-party OAuth applications

Por unidad organizativa Machine-assessable Estándar (semántica PASS/FAIL)

Se evalúa contra el subárbol de OU de estudiantes. Requiere el parámetro -StudentOU (o el campo Student OUs en Show-Guerrilla); sin él, la comprobación informa No evaluado en lugar de evaluar todo el tenant como si fuera la población estudiantil.

Justificación
A student clicking "Sign in with Google" on an arbitrary website can grant that site access to their school account data unless the district restricts third-party API access. Staff may need broad OAuth access; students need either no third-party access or a district-curated allowlist. This is one of the highest-leverage single settings in a school tenant.
Amenaza abordada
Data harvesting from student accounts by non-vetted applications; phishing-style consent grants against minors; ed-tech apps acquiring student data without district review, contrary to COPPA/FERPA obligations.
Ajustes evaluados
Google Workspace API access controls for the student OUs (Admin console: Security > API controls > App access control): whether third-party app access is unrestricted for students, or restricted/blocked with a configured allowlist.
Evaluado por
GWS-K12-003

K12-IDENT-002 Vendor delegated access is scoped, current, and reviewed

Todo el tenant Machine-assisted + policy review Dependiente del contexto (elementos de revisión contra la política de su distrito, no fallos duros)

Justificación
SIS platforms, rostering tools, and EdTech vendors accumulate domain-wide delegation grants and OAuth authorizations over years. Vendors get replaced; their grants rarely do. Each stale grant is standing access to student data held by a party with no current contract or duty of care.
Amenaza abordada
Standing access to student data by former vendors; breach of a defunct vendor cascading into the district tenant; domain-wide delegation grants with scopes far beyond the vendor's function.
Ajustes evaluados
Domain-wide delegation client list and granted scopes; tenant OAuth token grants aggregated by application; age and last-use where available. Which vendors are legitimate is a district determination, so findings are review items rather than hard failures.
Evaluado por
GWS-K12-004

K12-IDENT-003 Non-IT staff admin roles are least-privilege

Todo el tenant Machine-assisted + policy review Dependiente del contexto (elementos de revisión contra la política de su distrito, no fallos duros)

Justificación
Districts routinely give counselors, secretaries, and building administrators delegated admin roles for legitimate tasks (password resets, class group changes) using roles far broader than the task: user-management over the whole domain, or Super Admin because it was easiest. Every over-privileged non-IT account is an account whose compromise reaches all student data.
Amenaza abordada
Compromise of a non-technical staff account escalating to bulk student-data access or security-setting changes; well-meaning staff making tenant-wide changes they did not intend.
Ajustes evaluados
Admin role assignments: which accounts hold which delegated admin roles, the privileges in each role, and whether custom roles scope user-management privileges to specific OUs rather than the whole domain. Whether a given secretary should hold a given role is a district determination; the machine-assessable part is surfacing scope-of-privilege versus scope-of-duty mismatches for review. ---
Evaluado por
GWS-K12-005

Child safety

K12-SAFE-001 Student communication boundaries are configured

Por unidad organizativa Machine-assessable Estándar (semántica PASS/FAIL)

Se evalúa contra el subárbol de OU de estudiantes. Requiere el parámetro -StudentOU (o el campo Student OUs en Show-Guerrilla); sin él, la comprobación informa No evaluado en lugar de evaluar todo el tenant como si fuera la población estudiantil.

Justificación
Google Chat, Meet, and Gmail each have independent settings governing whether accounts can communicate with people outside the organization. For staff these are productivity settings. For student OUs they are a safety boundary: they determine whether an external adult can initiate contact with a student through district-provided tools. The district should make this boundary an explicit decision per service, per student OU.
Amenaza abordada
Unsolicited contact with students by external parties through district-managed communication channels; students initiating contact with unknown external accounts from school identities.
Ajustes evaluados
Per student OU: Chat external-chat settings (whether students can send or receive external direct messages and spaces), Meet settings for who can join meetings and whether external participants can interact with students, and Gmail external mail restrictions if the district uses them for student OUs.
Evaluado por
GWS-K12-006

K12-SAFE-002 Guardian access is configured with integrity

Por unidad organizativa Machine-assisted + policy review Dependiente del contexto (elementos de revisión contra la política de su distrito, no fallos duros)

Se evalúa contra el subárbol de OU de estudiantes. Requiere el parámetro -StudentOU (o el campo Student OUs en Show-Guerrilla); sin él, la comprobación informa No evaluado en lugar de evaluar todo el tenant como si fuera la población estudiantil.

Justificación
Guardian email summaries and guardian access exist so parents see their own student's activity. The integrity properties that matter: the district, not the student, controls who is registered as a guardian; a student cannot approve or self-manage guardian invitations; and a guardian relationship never exposes another student's data. Districts should also know whether guardian features are in use at all, since an unused-but-enabled feature is unowned surface.
Amenaza abordada
A non-guardian adult obtaining guardian-level visibility into a student's activity; guardian relationships created without district verification; cross-student data exposure through mis-scoped guardian access.
Ajustes evaluados
Classroom guardian-summary settings per student OU (whether guardian management is admin-controlled or teacher/student- controlled), and, where collectable, the guardian invitation flow configuration. Verifying the district's guardian-verification procedure is a policy review item. ---
Evaluado por
GWS-K12-007

Device and endpoint

K12-DEVICE-001 Student Chromebook posture is managed

Por unidad organizativa Machine-assessable Estándar (semántica PASS/FAIL)

Se evalúa contra el subárbol de OU de estudiantes. Requiere el parámetro -StudentOU (o el campo Student OUs en Show-Guerrilla); sin él, la comprobación informa No evaluado en lugar de evaluar todo el tenant como si fuera la población estudiantil.

Justificación
Student Chromebooks are the district's largest fleet and its most hostile-user environment, in the affectionate sense: students probe boundaries as a hobby. The posture that keeps the fleet assessable: devices must be enrolled (forced re-enrollment on wipe), student OUs carry an extension allow/blocklist policy, and force-installed extensions on student OUs are a reviewed list rather than an accumulation.
Amenaza abordada
Students unenrolling devices to escape management; malicious or data-harvesting browser extensions on student devices; force-installed extensions with broad permissions that nobody has reviewed.
Ajustes evaluados
Per student OU: forced re-enrollment setting, extension allow/blocklist configuration mode, sideloading and developer-mode controls, and the force-install extension list for review. ---
Evaluado por
GWS-K12-008

Lifecycle

K12-LIFE-001 Departed students are offboarded

Por unidad organizativa Machine-assisted + policy review Dependiente del contexto (elementos de revisión contra la política de su distrito, no fallos duros)

Se evalúa contra el subárbol de OU de estudiantes. Requiere el parámetro -StudentOU (o el campo Student OUs en Show-Guerrilla); sin él, la comprobación informa No evaluado en lugar de evaluar todo el tenant como si fuera la población estudiantil.

Justificación
Graduation and withdrawal produce accounts nobody owns. An active account belonging to a departed student is an unwatched identity with access to whatever the student OU permits, often still receiving mail and still holding Drive data the district may be obligated to retain or return. Districts need a disposition pipeline: suspend or archive on departure, and a deliberate answer for Drive ownership before deletion.
Amenaza abordada
Credential compromise of unmonitored departed-student accounts; departed students retaining access to current-student spaces; data loss when accounts are eventually bulk-deleted without ownership transfer.
Ajustes evaluados
Within student OUs (or a designated departed/alumni OU): accounts with no sign-in activity beyond a threshold that remain active rather than suspended, and suspended accounts holding Drive data with no ownership transfer, surfaced as a review list. The departure roster itself lives in the SIS, so verdicts are posture heuristics plus review items rather than a roster reconciliation. ---
Evaluado por
GWS-K12-009

Audit and recoverability

K12-AUDIT-001 Audit-log durability supports investigations

Todo el tenant Machine-assisted + policy review Dependiente del contexto (elementos de revisión contra la política de su distrito, no fallos duros)

Justificación
When a student account incident is suspected, the questions are always the same: who signed in, from where, what was shared, what was deleted. Workspace audit logs answer them only within their retention window (six months for most Workspace editions, and not configurable upward without export). A district that needs longer reconstruction capability must export logs (BigQuery, SIEM, or scheduled Reports API pulls). The control: the district knows its reconstruction window and has made a deliberate decision that it is sufficient.
Amenaza abordada
Inability to reconstruct account activity during a safeguarding or legal investigation because logs aged out; discovering the retention window during the incident.
Ajustes evaluados
Workspace edition and applicable log retention window; whether a log-export pipeline (BigQuery export or equivalent) is configured. Whether the resulting window satisfies the district's legal and safeguarding obligations is a policy determination. ---
Evaluado por
Aún sin cobertura: ninguna comprobación evalúa este control todavía. El trabajo de recolección necesario está registrado en las propuestas del módulo.

Account hygiene

K12-ACCT-001 Student account security floor matches the age band

Por unidad organizativa Machine-assisted + policy review Dependiente del contexto (elementos de revisión contra la política de su distrito, no fallos duros)

Se evalúa contra el subárbol de OU de estudiantes. Requiere el parámetro -StudentOU (o el campo Student OUs en Show-Guerrilla); sin él, la comprobación informa No evaluado en lugar de evaluar todo el tenant como si fuera la población estudiantil.

Justificación
Consensus baselines demand 2SV enforcement for all users. For a third grader with no phone, that demand is not just impractical; enforcing it produces workarounds worse than the absence. An honest student security floor is age-banded: strong password policy and admin-controlled recovery everywhere; sign-in challenges where supported; 2SV enforcement for OUs serving students old enough to hold a second factor. The control is that each student OU has a deliberate floor matched to its age band, not that every OU meets the staff bar.
Amenaza abordada
Bulk student-account compromise through weak or shared passwords; account takeover via student-controlled recovery channels; the false-comfort failure where a tool reports students FAIL 2SV forever and the district learns to ignore the finding.
Ajustes evaluados
Per student OU: password length and strength policy, recovery options configuration (whether student-controlled recovery is disabled), sign-in challenge posture, and 2SV enforcement state, evaluated against the age band the district declares for that OU rather than against a single tenant-wide bar. ---
Evaluado por
GWS-K12-010

Distritos: revisen y co-firmen

Esta línea base mejora cuando la lee gente que administra tenants escolares. No hace falta PowerShell: lea un control y diga "esto coincide con lo que necesitan distritos como el mío" o "esto está mal, y este es el motivo". Abra un issue sobre el documento de la línea base o comente uno existente. Los controles pasan de candidato a adoptado exactamente mediante este tipo de revisión.

Cómo contribuir