cisagov / ScubaGoggles

SCuBA Security Configuration Baselines and assessment tool for Google Workspace
https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project
Creative Commons Zero v1.0 Universal
128 stars 13 forks source link

GWS.DRIVEDOCS.1.6v0.1 clarification needed #302

Open adhilto opened 1 month ago

adhilto commented 1 month ago

The current baseline reads as: "Agencies SHALL enable access checking for file sharing outside of Docs or Drive."

However, this setting isn't an enable/disabled setting. In fact, it can't be disabled, so additional clarification is needed. See screenshot below for the options presented: image

It seems like the important bit is that access check not allow sharing to the public. As such, I'd recommend rewording the baseline statement to something along the lines of: "Agencies SHALL NOT allow Access Checker to share files with the public."