Skip to main content

๐Ÿ›ก๏ธ Google Workspace and Cloud Identity Data Sharing with Google Cloud is not enabled๐ŸŸขโšช

  • Contextual name: ๐Ÿ›ก๏ธ Workspace and Cloud Identity Data Sharing with Google Cloud is not enabled๐ŸŸขโšช
  • ID: /ce/ca/google/logging/workspace-cloud-identity-data-sharing
  • Tags:
  • Policy Type: COMPLIANCE_POLICY
  • Policy Categories: SECURITY

Descriptionโ€‹

Open File

Descriptionโ€‹

Google Workspace and Cloud Identity can share administrative audit log data with Google Cloud. Enable this setting so user, password, and security configuration changes from the identity provider are available in Cloud Logging.

Rationaleโ€‹

Centralized identity audit logs help security teams correlate Workspace or Cloud Identity administrative events with Google Cloud resource activity. Without this setting, important identity events remain only in the Admin Console, which limits monitoring, alerting, retention, and incident investigation.

Impactโ€‹

Enabling the setting sends additional audit log data to Google Cloud. Organizations should confirm that log retention, access controls, and monitoring rules are configured for the resulting Cloud Logging data.

Auditโ€‹

From Google Admin Consoleโ€‹
  1. Sign in to the Google Admin Console as a Super Admin.
  2. Go to Account > Account settings.
  3. Open Legal and compliance.
  4. Locate Sharing options > Google Cloud Platform Sharing Options.
  5. Verify that the setting is Enabled.

... see more

Remediationโ€‹

Open File

Remediationโ€‹

From Google Admin Consoleโ€‹

  1. Sign in to the Google Admin Console as a Super Admin.
  2. Go to Account > Account settings.
  3. Open Legal and compliance.
  4. Locate Sharing options > Google Cloud Platform Sharing Options.
  5. Set the option to Enabled and click Save.
  6. In Google Cloud, use Logs Explorer to confirm that Admin audit log events are arriving in Cloud Logging.

policy.yamlโ€‹

Open File

Linked Framework Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
๐Ÿ’ผ CIS GCP v5.0.0 โ†’ ๐Ÿ’ผ 2.2 Ensure Google Workspace/Cloud Identity Data Sharing with Google Cloud is Enabled for Admin Audit Logging - Level 1 (Manual)1no data
๐Ÿ’ผ Cloudaware Framework โ†’ ๐Ÿ’ผ Logging and Monitoring Configuration79no data