Skip to main content

πŸ›‘οΈ Google Cloud folders are not structured by environment and sensitivity🟒βšͺ

  • Contextual name: πŸ›‘οΈ Folders are not structured by environment and sensitivity🟒βšͺ
  • ID: /ce/ca/google/project/folders-structured-by-environment-and-sensitivity
  • Tags:
  • Policy Type: COMPLIANCE_POLICY
  • Policy Categories: SECURITY

Description​

Open File

Description​

Google Cloud Resource Manager folders should be structured primarily by environment, such as production, non-production, and sandbox, and by sensitivity, such as security, logging, shared services, or regulated workloads.

Rationale​

Folders provide a hierarchy for inherited IAM policies, organization policies, and other guardrails. A folder structure aligned to environment and sensitivity helps apply consistent controls to projects with similar risk profiles. Ad hoc or organization-chart-based structures can make policy inheritance harder to reason about and can mix workloads with different security requirements.

Impact​

Changing folder structure can affect inherited IAM permissions, organization policies, automation, and operational ownership. Plan and test project moves before applying changes to production workloads.

Audit​

From Google Cloud Console​
  1. Open the Google Cloud Console at https://console.cloud.google.com.
  2. Select the organization.
  3. Go to IAM & Admin > Manage resources.
  4. Review the folder hierarchy.

... see more

Remediation​

Open File

Remediation​

From Google Cloud Console​

  1. Define the target folder hierarchy based on environment and sensitivity.
  2. Create folders for major environments and sensitive workload groupings.
  3. Apply organization policies, IAM policies, and guardrails at the appropriate folder levels.
  4. Move projects into the correct folders after validating inherited policy and permission changes.
  5. Review the folder hierarchy periodically as projects and compliance requirements change.

policy.yaml​

Open File

Linked Framework Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
πŸ’Ό CIS GCP v5.0.0 β†’ πŸ’Ό 1.1.3 Ensure Folders Are Structured By Environment And Sensitivity - Level 2 (Manual)1no data
πŸ’Ό Cloudaware Framework β†’ πŸ’Ό General Access Controls23no data