--- names: full: "Google IAM Users are assigned the Service Account User or Service Account Token Creator roles at Project level" contextual: "IAM Users are assigned the Service Account User or Service Account Token Creator roles at Project level" description: "It is recommended to assign the Service Account User (iam.serviceAccountUser) and \ Service Account Token Creator (iam.serviceAccountTokenCreator) roles to a user \ for a specific service account rather than assigning the role to a user at project level." type: COMPLIANCE_POLICY categories: - "SECURITY" frameworkMappings: - /frameworks/cis-gcp-v4.0.0/01/06 - /frameworks/cloudaware/identity-and-access-governance/rbac-management - /frameworks/nist-sp-800-53-r4/ac/06 - /frameworks/nist-sp-800-53-r5/ac/03 - /frameworks/nist-sp-800-53-r5/ac/05 - /frameworks/nist-sp-800-53-r5/ac/06 - /frameworks/nist-sp-800-53-r5/mp/02 - /frameworks/pci-dss-v3.2.1/07/02/01 - /frameworks/pci-dss-v4.0/01/03/01 - /frameworks/iso-iec-27001-2013/09/02/03 - /frameworks/iso-iec-27001-2022/05/10 - /frameworks/iso-iec-27001-2022/05/15 - /frameworks/iso-iec-27001-2022/08/03 - /frameworks/iso-iec-27001-2022/08/04 - /frameworks/nist-csf-v1.1/pr-ac/04 - /frameworks/soc-2/cc5/02/03 - /frameworks/soc-2/cc6/01/03 - /frameworks/soc-2/cc6/01/07 similarPolicies: cloudConformity: - url: "https://www.trendmicro.com/cloudoneconformity/knowledge-base/gcp/CloudIAM/check-for-iam-users-with-service-roles.html" name: "Check for IAM Members with Service Roles at the Project Level"