Skip to main content

πŸ“ Google Organization Administrator Security Key Enforcement is not enabled 🟒

  • Contextual name: πŸ“ Organization Administrator Security Key Enforcement is not enabled 🟒
  • ID: /ce/ca/google/iam/security-key-enforcement
  • Located in: πŸ“ Google IAM

Flags​

Our Metadata​

  • Policy Type: COMPLIANCE_POLICY
  • Policy Category:
    • SECURITY

Similar Policies​

Description​

Open File

Description​

Setup Security Key Enforcement for Google Cloud Platform admin accounts.

Rationale​

Google Cloud Platform users with Organization Administrator roles have the highest level of privilege in the organization. These accounts should be protected with the strongest form of two-factor authentication: Security Key Enforcement. Ensure that admins use Security Keys to log in instead of weaker second factors like SMS or one-time passwords (OTP). Security Keys are actual physical keys used to access Google Organization Administrator Accounts. They send an encrypted signature rather than a code, ensuring that logins cannot be phished.

Impact​

If an organization administrator loses access to their security key, the user could lose access to their account. For this reason, it is important to set up backup security keys.

Audit​

  1. Identify users with Organization Administrator privileges:

    gcloud organizations get-iam-policy ORGANIZATION_ID

Look for members granted the role roles/resourcemanager.organizationAdmin.

... see more

Remediation​

Open File

Remediation​

  1. Identify users with the Organization Administrator role.
  2. Setup Security Key Enforcement for each account.

Learn more at: https://cloud.google.com/security-key/

policy.yaml​

Open File

Linked Framework Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό CIS GCP v3.0.0 β†’ πŸ’Ό 1.3 Ensure that Security Key Enforcement is Enabled for All Admin Accounts - Level 2 (Manual)1
πŸ’Ό Cloudaware Framework β†’ πŸ’Ό Multi-Factor Authentication (MFA) Implementation16