← All controls

48 Reading-room enclave (SCIF port, incl. data-copy minimization)

draft

An enclave OU and shared drive in which approved readers can view crown-jewel documents and do nothing else with them: no external sharing, no non-member access, and no download, copy or print for viewers and commenters — the data-copy minimization half of the control. Enclave content carries a Restricted label so a DLP rule can block and alert on any attempt to share, download or attach it, and Drive access for the enclave OU is bound to a Context-Aware Access level requiring a managed device on the reading-room network.

Caveats

Setup steps

  1. open ↗

    Apps › Google Workspace › Drive and Docs › Manage shared drives

    Allow people who aren't shared drive members to be added to files = OFF; Allow viewers and commenters to download, print, and copy files = OFF; Allow users outside your organization to access files in shared drives = OFF

Ongoing maintenance

How to verify

  1. As an authorised test user inside the enclave, attempt to download, print, and copy from a protected document — every path must be refused; then attempt access from outside the enclave context — it must be denied entirely.

draft v0.0.3 Prevent edition Ent Std+ policy #28 · #15, #26 ↗