๐ก๏ธ Google Access Approval is not enabled๐ข
- Contextual name: ๐ก๏ธ Access Approval is not enabled๐ข
- ID:
/ce/ca/google/iam/access-approval-settings - Tags:
- ๐ข Policy with categories
- ๐ข Policy with type
- ๐ข Production policy
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY
Logicโ
- ๐ง prod.logic.yaml๐ข
Similar Policiesโ
- Cloud Conformity: Enable Access Approval
Descriptionโ
Descriptionโ
GCP Access Approval enables you to require your organizations' explicit approval whenever Google support try to access your projects. You can then select users within your organization who can approve these requests through giving them a security role in IAM. All access requests display which Google Employee requested them in an email or Pub/Sub message that you can choose to Approve. This adds an additional control and logging of who in your organization approved/denied these requests.
Rationaleโ
Controlling access to your information is one of the foundations of information security. Google Employees do have access to your organizations' projects for support reasons. With Access Approval, organizations can then be certain that their information is accessed by only approved Google Personnel.
Impactโ
To use Access Approval your organization will need have enabled Access Transparency and have at one of the following support level: Enhanced or Premium. There will be subscription costs associated with these support levels, as well as increased storage costs for storing the logs. You will also not be able to turn the Access Transparency which Access Approval depends on, off yourself. To do so you will need to submit a service request to Google Cloud Support. There will also be additional overhead in managing user permissions. There may also be a potential delay in support times as Google Personnel will have to wait for their access to be approved.
... see more
Remediationโ
Remediationโ
From Google Cloud Consoleโ
- From the Google Cloud Home, within the project you wish to enable, click on the Navigation hamburger menu in the top left. Hover over the
SecurityMenu. SelectAccess Approvalin the middle of the column that opens.- The status will be displayed here. On this screen, there is an option to click
Enroll. If it is greyed out and you see an error bar at the top of the screen that saysAccess Transparency is not enabledplease view the corresponding reference within this section to enable it.- In the second screen click
Enroll.Grant an IAM Group or User the role with permissions to Add Users to be Access Approval message Recipientsโ
- From the Google Cloud Home, within the project you wish to enable, click on the Navigation hamburger menu in the top left. Hover over the
IAM and Admin. SelectIAMin the middle of the column that opens.- Click the blue button the says
+ ADDat the top of the screen.- In the
principalsfield, select a user or group by typing in their associated email address.... see more
policy.yamlโ
Linked Framework Sectionsโ
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| ๐ผ CIS GCP v1.3.0 โ ๐ผ 2.15 Ensure 'Access Approval' is 'Enabled' - Level 2 (Automated) | 1 | no data | |||
| ๐ผ CIS GCP v2.0.0 โ ๐ผ 2.15 Ensure 'Access Approval' is 'Enabled' - Level 2 (Automated) | 1 | no data | |||
| ๐ผ CIS GCP v3.0.0 โ ๐ผ 2.15 Ensure 'Access Approval' is 'Enabled' - Level 2 (Automated) | 1 | no data | |||
| ๐ผ Cloudaware Framework โ ๐ผ Secure Access | 57 | no data |