Cybersecurity and Infrastructure Security Agency Logo

Light mode

Google Drive and Docs Baseline Report

Customer Name Customer Domain Customer ID Report Date Baseline Version Tool Version
Cool Example Org example.org ABCDEFG 07/20/2026 12:43:08 PDT 1 v1.0.0
Policy Indicators:

DRIVEDOCS-1 Sharing Outside the Organization

Control ID Requirement Result Criticality Details
GWS.DRIVEDOCS.1.1v1 External sharing SHALL be restricted to allowlisted domains.
BOD 25-01 Requirement Automated Check
Warning Should The following OUs are non-compliant:
  • Christopher Thompson's OU: Files owned by users or shared drives can be shared with Google accounts in compatible allowlisted domains
  • Cool Example Org: Files owned by users or shared drives can be shared with Google accounts in compatible allowlisted domains
GWS.DRIVEDOCS.1.2v1 Receiving files from non-allowlisted domains SHOULD be disabled.
Automated Check
Warning Should The following OUs are non-compliant:
  • Christopher Thompson's OU: File sharing with allowlisted domains, receiving files permitted.
  • Cool Example Org: File sharing with allowlisted domains, receiving files permitted.
GWS.DRIVEDOCS.1.3v1 Warnings SHALL be enabled when a user is attempting to share with someone in a non-allowlisted domain.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.
GWS.DRIVEDOCS.1.4v1 If sharing outside of the organization, agencies SHOULD disable sharing of files with individuals who are not using a Google account.
Automated Check
Fail Shall The following OUs are non-compliant:
  • Christopher Thompson's OU: File sharing with allowlisted domains, with non-Google users.
  • Cool Example Org: File sharing with allowlisted domains, with non-Google users.
GWS.DRIVEDOCS.1.5v1 Any Organizational Units that allow external sharing SHOULD disable content availability to "anyone with the link."
Automated Check
Fail Shall The following OUs are non-compliant:
  • Christopher Thompson's OU: Published web content can be made visible to anyone with a link
  • Cool Example Org: Published web content can be made visible to anyone with a link
GWS.DRIVEDOCS.1.6v1 Agencies SHALL set access checking to "recipients only."
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • Jeffrey Rodriguez's OU: Access Checker allows users to share files to recipients only, suggested target audience, or public (no Google account required)
  • Cool Example Org: Access Checker allows users to share files to recipients only, suggested target audience, or public (no Google account required)
GWS.DRIVEDOCS.1.7v1 Users SHOULD NOT be allowed to upload or move content to shared drives owned by another organization.
Automated Check
Fail Shall The following OUs are non-compliant:
  • Christopher Thompson's OU: Anyone can distribute content outside of the organization
GWS.DRIVEDOCS.1.8v1 "Private to owner" SHALL be the default access level for newly created items.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • Jeffrey Rodriguez's OU: When users create items, the default access is set to: the primary target audience can search and find the item.
GWS.DRIVEDOCS.1.9v1 Out-of-Domain file-level warnings SHALL be enabled.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.
GWS.DRIVEDOCS.1.10v1 If external sharing is not allowed, then forms owned by users within the organization SHOULD NOT be able to accept responses from anyone accessing the link from outside the organization.
Manual
N/A Should/Not-Implemented Currently not able to be tested automatically; please manually check.
GWS.DRIVEDOCS.1.11v1 If receiving external files is not allowed, then users in the organization SHOULD NOT be able to submit responses to forms from users or shared drives outside of the organization.
Manual
N/A Should/Not-Implemented Currently not able to be tested automatically; please manually check.

DRIVEDOCS-2 Shared Drive Creation

Control ID Requirement Result Criticality Details
GWS.DRIVEDOCS.2.1v1 Agencies SHOULD NOT allow members with manager access to override shared Google Drive creation settings.
Automated Check
Warning Should The following OUs are non-compliant:
  • Christopher Thompson's OU: Members with manager access can override shared drive settings.
GWS.DRIVEDOCS.2.2v1 Agencies SHALL allow users who are not members of a shared Google Drive to be added to files.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • Christopher Thompson's OU: Users who aren't shared drive members are not allowed to be added to files.

DRIVEDOCS-3 Security Updates for Files

Control ID Requirement Result Criticality Details
GWS.DRIVEDOCS.3.1v1 Agencies SHALL enable the security update for Google Drive files.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • Cool Example Org: Users are allowed to remove/apply the security update for files they own or manage.

DRIVEDOCS-4 Drive SDK

Control ID Requirement Result Criticality Details
GWS.DRIVEDOCS.4.1v1 Agencies SHOULD disable Google Drive SDK access.
Automated Check
Pass Should Requirement met.

DRIVEDOCS-5 Drive for Desktop

Control ID Requirement Result Criticality Details
GWS.DRIVEDOCS.5.1v1 Google Drive for Desktop SHALL be enabled for authorized devices only.
BOD 25-01 Requirement Automated Check
Warning Should The following OUs are non-compliant:
  • Cool Example Org (group salinassean@example.org): Drive for Desktop is enabled and can be used on any device.
  • Cool Example Org (group salinassean@example.org): Drive for Desktop is enabled and can be used on any device.
  • Cool Example Org (group salinassean@example.org): Drive for Desktop is enabled and can be used on any device.
GWS.DRIVEDOCS.5.2v1 Monitoring for potential ransomware corruption SHALL be enabled.
Manual
N/A Shall/Not-Implemented Currently not able to be tested automatically; please manually check.