--- names: full: "Google GCE Instance is configured to use the Default Service Account" contextual: "Instance is configured to use the Default Service Account" description: "It is recommended to configure your instance to not use the default Compute Engine \ service account because it has the Editor role on the project." type: COMPLIANCE_POLICY categories: - "SECURITY" frameworkMappings: - /frameworks/cis-gcp-v4.0.0/04/01 - /frameworks/cloudaware/resource-security/secure-access - /frameworks/nist-sp-800-53-r5/ia/05 - /frameworks/pci-dss-v4.0/02/02/02 - /frameworks/pci-dss-v4.0/02/03/01 - /frameworks/iso-iec-27001-2022/08/02 - /frameworks/iso-iec-27001-2022/08/09 - /frameworks/nist-csf-v1.1/pr-ac/01 - /frameworks/soc-2/cc6/03/01 - /frameworks/soc-2/cc6/03/02 - /frameworks/soc-2/cc6/03/03 similarPolicies: cloudConformity: - url: "https://www.trendmicro.com/cloudoneconformity-staging/knowledge-base/gcp/ComputeEngine/default-service-accounts-in-use.html" name: "Check for Instances Associated with Default Service Accounts"