Drive Access Review for ISO 27001 and SOC 2

8apps Team·

What an ISO 27001 or SOC 2 auditor expects from a Google Drive access review: scope, reviewer, findings, decisions, next date – not a Drive log screenshot.

The line on the evidence request list

The auditor's request list arrives and one line reads something like "evidence of periodic review of access to file-sharing platforms (Google Drive)". You have a Drive log, a vague memory of looking at it in March, and nothing that says what you found or did.

The reassuring part: the auditor is not asking whether Google is certified, or whether any tool you use is. They are asking whether your organisation looked, decided, and will look again – and whether you can prove it. That is a paperwork problem with a repeatable answer.

Three working files carry that answer: a quarterly checklist, an external-sharing report – one row per exposed file, with a decision and a name against each – and an evidence log, one row per review. This post is about the evidence log.

What an access review has to show

ISO/IEC 27001 is the standard for information security management systems; it defines requirements a management system must meet. A SOC 2 report is an AICPA examination of a service organisation's controls relevant to security, availability, processing integrity, confidentiality or privacy. Neither prescribes a Google-specific format for a review of Drive sharing. The auditor tests whether the control you described – "we review external access to Drive periodically" – actually operates, and whether the evidence shows it.

In practice, auditors typically ask an access review to show five things:

  1. Scope – which systems, data and window. "All Google Drive files shared outside the domain, 1 April to 30 June" is scope. "Drive" is not.
  2. Who reviewed – a named person, plus whoever signed off on decisions if that is someone else.
  3. What was found – counts and a list: public links, external shares, shares to domains you no longer work with.
  4. What was decided – kept with a justification, restricted, or transferred, and by whom.
  5. When it happens next – a date and an owner.

Produce those five for each quarter of the audit period and you have a review. Produce only the first and third and you have a report. Produce none and you have a log.

Why a screenshot of the Drive log is not a review

The instinct is to open Menu → Reporting → Audit and investigation → Drive log events, filter on the Visibility change attribute, screenshot the result and attach it. That is evidence something exists, not evidence of a review, for four reasons.

The log is activity history, not a permissions map. It shows that a file's visibility changed inside the window; a file already public or external before the window generates no event, so the log cannot describe the current state of exposure.

The log is time-limited. The default view is the last 7 days and Drive log events are retained for 6 months. An auditor looking at twelve months cannot be shown Q1 from the log in Q4 – see the retention post.

The log has blind spots by design: external users appear as anonymous unless the item was shared with them individually or through a specific group.

And a screenshot contains no decisions. Nobody's name is on it; nothing says "kept, client needs it" or "restricted 3 July". Missing decisions are what an auditor notices first.

The three artefacts that make a review reproducible

Reproducible means a second person, given the same inputs, would reach the same findings and could check the same decisions. Three files do that.

The evidence log is the index. One row per review: audit date, window, owner, edition, files reviewed, public, external and legacy found, restricted, justified, incidents, next audit date, next owner. Four rows cover a year; hand it over first.

The report export is the findings and decisions behind each row: every exposed file, its owner, location, exposure type, who it is shared with, the decision, who decided and when it was done. The report template post walks the columns. Export it on the day, dated, and keep it with the log.

A point-in-time state artefact is what the log cannot give you: what was exposed on the day of the review, whenever it became exposed. Where it comes from depends on your edition. On Enterprise Standard and Plus, Education Standard and Plus, Frontline Plus, Enterprise Essentials Plus and Cloud Identity Premium, the Drive inventory export writes file metadata, including who each file is shared with, to BigQuery – each export overwrites the previous one, so save a dated copy. On Business editions the native route is shared-drive member lists from Manage shared drives plus per-user sharedwith:external owner:me searches, which the admin cannot run for anyone else. An org-wide scan export – every user's My Drive and every Shared Drive, dated – fills that slot for Business-edition admins, and is what the report template's Found by = scan value points to.

The quarterly checklist puts the three artefacts in order; the flagship guide to auditing Drive access across the organisation is the long-form version.

Cadence, ownership and the leaver rule

Auditors typically ask how often, and whether that held. Quarterly by default; monthly if you are regulated or a customer contract says so; always after a leaver, because suspension does not touch the shares that person created – collaborators who were granted access to shared documents keep it. Suspended is not gone explains that gap.

Write the cadence down next to the evidence log, so reviewer and schedule are one document. The name in "next owner" is the control operating; an empty cell is the control not operating.

What to hand over

One folder per quarter: the evidence log row, the dated report export, the dated state artefact, and one screenshot that is legitimately state rather than history – Sharing settings under Menu → Apps → Google Workspace → Drive and Docs, showing the domain default and any per-organisational-unit differences. That folder is the review. Nothing in it needs a certification of any tool; it needs your name, your date and your decisions.

Sources