# Cis Gworkspace 3.1.2.1.1.2

> Ensure users cannot publish files to the web or make visible to the world as public or unlisted

- Skill: `cyberstrikeus/cis-gworkspace-3-1-2-1-1-2` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-gworkspace-3-1-2-1-1-2`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-gworkspace-3-1-2-1-1-2/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-gworkspace-3-1-2-1-1-2

---


# 3.1.2.1.1.2 Ensure users cannot publish files to the web or make visible to the world as public or unlisted

## Level

L1

## Profile Applicability

- Enterprise Level 1

## Type

Manual

## Description

You should control the publishing of documents to the web or making them visable to the world as public or unlisted.

## Rationale

Attackers will often attempt to expose sensitive information to external entities through sharing, and restricting the methods that your users can share documents with will reduce that surface area.

This setting is only applicable if `ON - Files owned by users in <Company> can be shared outside of <Company>. This applies to files in all shared drives as well` is `selected`, but should be configured as described below to prevent unintentional document publishing.

## Impact

Enabling this feature will prevent users from publishing documents on the web or making them visible to the world as public or unlisted files.

## Audit

To verify this setting via the Google Workspace Admin Console:

1. Log in to `https://admin.google.com` as an administrator
2. Select `Apps`
3. Select `Google Workspace`
4. Select `Drive and Docs`
5. Under `Sharing settings`, select `Sharing options`
6. Under `Sharing outside of <Company>` - `ON - Files owned by users in <Company> can be shared outside of <Company>. This applies to files in all shared drives as well`, ensure `When sharing outside of <Company> is allowed, users in <Company> can make files and published web content visible to anyone with the link` is `unchecked`

## Remediation

To configure this setting via the Google Workspace Admin Console:

1. Log in to `https://admin.google.com` as an administrator
2. Select `Apps`
3. Select `Google Workspace`
4. Select `Drive and Docs`
5. Under `Sharing settings`, select `Sharing options`
6. Under `Sharing outside of <Company>` - `ON - Files owned by users in <Company> can be shared outside of <Company>. This applies to files in all shared drives as well`, set `When sharing outside of <Company> is allowed, users in <Company> can make files and published web content visible to anyone with the link` to `unchecked`
7. Select `Save`

## Default Value

`When sharing outside of <Company> is allowed, users in <Company> can make files and published web content visible to anyone with the link` is `Checked`

## CIS Controls

| Controls Version | Control                                               | IG 1 | IG 2 | IG 3 |
| ---------------- | ----------------------------------------------------- | ---- | ---- | ---- |
| v8               | 3.3 Configure Data Access Control Lists               | x    | x    | x    |
| v7               | 14.6 Protect Information through Access Control Lists | x    | x    | x    |

