COLLAB-015: Meeting join restricted to the organization (GWS.MEET.2.1)
- Plataforma
- Google Workspace
- Categoría
- Collaboration
- Severidad
- High
- Pilar de Zero Trust
- Identity (peso 3)
- Fixtures de referencia
- 3
- Cobertura de ramas
- Observada: los fixtures prueban los veredictos que ejercitan
- Procedencia
- baseline
Qué comprueba
SCuBA GWS.MEET.2.1 requires that access to meetings be restricted so only users in the organization (or trusted Workspace organizations) can join. Leaving meetings open to anyone lets external and unauthenticated parties into sessions that may involve students. This check reads meet.safety_access and fails any organizational unit where meetingsAllowedToJoin is broader than SAME_ORGANIZATION_ONLY / ANY_WORKSPACE_ORGANIZATION.
Valor recomendado
meetingsAllowedToJoin set to SAME_ORGANIZATION_ONLY (or ANY_WORKSPACE_ORGANIZATION)
Remediación
In Google Meet safety settings, restrict who can join meetings to users in your organization, so external/unauthenticated participants cannot join by default.
Veredictos probados con fixtures
Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.
| Escenario | Veredicto esperado |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| no-data | Not Assessed |
Mapeos a marcos de referencia
- CISA SCuBA
- GWS.MEET.2.1v1
- NIST SP 800-53
- AC-3, AC-14, SC-7