Skip to main content

πŸ“ Google Cloud Asset Inventory API is not enabled 🟒

  • Contextual name: πŸ“ Asset Inventory API is not enabled 🟒
  • ID: /ce/ca/google/api/cloud-asset-inventory
  • Located in: πŸ“ Google API & Services

Flags​

Our Metadata​

  • Policy Type: COMPLIANCE_POLICY
  • Policy Category:
    • RELIABILITY

Similar Policies​

Logic​

Description​

Open File

Description​

GCP Cloud Asset Inventory is services that provides a historical view of GCP resources and IAM policies through a time-series database. The information recorded includes metadata on Google Cloud resources, metadata on policies set on Google Cloud projects or resources, and runtime information gathered within a Google Cloud resource.

Cloud Asset Inventory Service (CAIS) API enablement is not required for operation of the service, but rather enables the mechanism for searching/exporting CAIS asset data directly.

Rationale​

The GCP resources and IAM policies captured by GCP Cloud Asset Inventory enables security analysis, resource change tracking, and compliance auditing.

It is recommended GCP Cloud Asset Inventory be enabled for all GCP projects.

Audit​

From Google Cloud Console​

Ensure that the Cloud Asset API is enabled:

  1. Go to API & Services/Library by visiting https://console.cloud.google.com/apis/library
  2. Search for Cloud Asset API and select the result for Cloud Asset API
  3. Ensure that API Enabled is displayed.

... see more

Remediation​

Open File

Remediation​

From Google Cloud Console​

Enable the Cloud Asset API:

  1. Go to API & Services/Library by visiting https://console.cloud.google.com/apis/library
  2. Search for Cloud Asset API and select the result for Cloud Asset API
  3. Click the ENABLE button.

From Google Cloud CLI​

Enable the Cloud Asset API:

  1. Enable the Cloud Asset API through the services interface:

         gcloud services enable cloudasset.googleapis.com

policy.yaml​

Open File

Linked Framework Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό CIS GCP v3.0.0 β†’ πŸ’Ό 2.13 Ensure Cloud Asset Inventory Is Enabled - Level 1 (Automated)1
πŸ’Ό Cloudaware Framework β†’ πŸ’Ό System Configuration24