Skip to main content

💼 CIS GCP v1.1.0

  • ID: /frameworks/cis-gcp-v1.1.0

Stats​

not available

Description​

Empty...

Similar​

  • Internal
    • ID: dec-a-7c3c4498

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 1 Identity and Access Management1511no data
 💼 1.1 Ensure that corporate login credentials are used11no data
 💼 1.2 Ensure that multi-factor authentication is enabled for all non-service accountsno data
 💼 1.3 Ensure that Security Key Enforcement is enabled for all admin accountsno data
 💼 1.4 Ensure that there are only GCP-managed service account keys for each service accountno data
 💼 1.5 Ensure that Service Account has no Admin privilegesno data
 💼 1.6 Ensure that IAM users are not assigned the Service Account User or Service Account Token Creator roles at project levelno data
 💼 1.7 Ensure user-managed/external keys for service accounts are rotated every 90 days or lessno data
 💼 1.8 Ensure that Separation of duties is enforced while assigning service account related roles to usersno data
 💼 1.9 Ensure that Cloud KMS cryptokeys are not anonymously or publicly accessibleno data
 💼 1.10 Ensure KMS encryption keys are rotated within a period of 90 daysno data
 💼 1.11 Ensure that Separation of duties is enforced while assigning KMS related roles to usersno data
 💼 1.12 Ensure API keys are not created for a projectno data
 💼 1.13 Ensure API keys are restricted to use by only specified Hosts and Appsno data
 💼 1.14 Ensure API keys are restricted to only APIs that application needs accessno data
 💼 1.15 Ensure API keys are rotated every 90 daysno data
💼 2 Logging and Monitoring11no data
 💼 2.1 Ensure that Cloud Audit Logging is configured properly across all services and all users from a projectno data
 💼 2.2 Ensure that sinks are configured for all log entriesno data
 💼 2.3 Ensure that retention policies on log buckets are configured using Bucket Lockno data
 💼 2.4 Ensure log metric filter and alerts exist for project ownership assignments/changesno data
 💼 2.5 Ensure that the log metric filter and alerts exist for Audit Configuration changesno data
 💼 2.6 Ensure that the log metric filter and alerts exist for Custom Role changesno data
 💼 2.7 Ensure that the log metric filter and alerts exist for VPC Network Firewall rule changesno data
 💼 2.8 Ensure that the log metric filter and alerts exist for VPC network route changesno data
 💼 2.9 Ensure that the log metric filter and alerts exist for VPC network changesno data
 💼 2.10 Ensure that the log metric filter and alerts exist for Cloud Storage IAM permission changesno data
 💼 2.11 Ensure that the log metric filter and alerts exist for SQL instance configuration changesno data
💼 3 Networking9no data
 💼 3.1 Ensure that the default network does not exist in a projectno data
 💼 3.2 Ensure legacy networks do not exist for a projectno data
 💼 3.3 Ensure that DNSSEC is enabled for Cloud DNSno data
 💼 3.4 Ensure that RSASHA1 is not used for the key-signing key in Cloud DNS DNSSECno data
 💼 3.5 Ensure that RSASHA1 is not used for the zone-signing key in Cloud DNS DNSSECno data
 💼 3.6 Ensure that SSH access is restricted from the internetno data
 💼 3.7 Ensure that RDP access is restricted from the Internetno data
 💼 3.8 Ensure that VPC Flow Logs is enabled for every subnet in a VPC Networkno data
 💼 3.9 Ensure no HTTPS or SSL proxy load balancers permit SSL policies with weak cipher suitesno data
💼 4 Virtual Machines10no data
 💼 4.1 Ensure that instances are not configured to use the default service accountno data
 💼 4.2 Ensure that instances are not configured to use the default service account with full access to all Cloud APIsno data
 💼 4.3 Ensure 'Block Project-wide SSH keys' is enabled for VM instancesno data
 💼 4.4 Ensure oslogin is enabled for a Projectno data
 💼 4.5 Ensure 'Enable connecting to serial ports' is not enabled for VM Instanceno data
 💼 4.6 Ensure that IP forwarding is not enabled on Instancesno data
 💼 4.7 Ensure VM disks for critical VMs are encrypted with Customer-Supplied Encryption Keys (CSEK)no data
 💼 4.8 Ensure Compute instances are launched with Shielded VM enabledno data
 💼 4.9 Ensure that Compute instances do not have public IP addressesno data
 💼 4.10 Ensure that App Engine applications enforce HTTPS connectionsno data
💼 5 Storage2no data
 💼 5.1 Ensure that Cloud Storage bucket is not anonymously or publicly accessibleno data
 💼 5.2 Ensure that Cloud Storage buckets have uniform bucket-level access enabledno data
💼 6 Cloud SQL Database Services7no data
 💼 6.1 MySQL Database2no data
  💼 6.1.1 Ensure that a MySQL database instance does not allow anyone to connect with administrative privilegesno data
  💼 6.1.2 Ensure that the 'local_infile' database flag for a Cloud SQL Mysql instance is set to 'off'no data
 💼 6.2 PostgreSQL Database7no data
  💼 6.2.1 Ensure that the 'log_checkpoints' database flag for Cloud SQL PostgreSQL instance is set to 'on'no data
  💼 6.2.2 Ensure that the 'log_connections' database flag for Cloud SQL PostgreSQL instance is set to 'on'no data
  💼 6.2.3 Ensure that the 'log_disconnections' database flag for Cloud SQL PostgreSQL instance is set to 'on'no data
  💼 6.2.4 Ensure that the 'log_lock_waits' database flag for Cloud SQL PostgreSQL instance is set to 'on'no data
  💼 6.2.5 Ensure that the 'log_min_messages' database flag for Cloud SQL PostgreSQL instance is set appropriatelyno data
  💼 6.2.6 Ensure that the 'log_temp_files' database flag for Cloud SQL PostgreSQL instance is set to '0' (on)no data
  💼 6.2.7 Ensure that the 'log_min_duration_statement' database flag for Cloud SQL PostgreSQL instance is set to '-1' (disabled)no data
 💼 6.3 SQL Server2no data
  💼 6.3.1 Ensure that the 'cross db ownership chaining' database flag for Cloud SQL SQL Server instance is set to 'off'no data
  💼 6.3.2 Ensure that the 'contained database authentication' database flag for Cloud SQL on the SQL Server instance is set to 'off'no data
 💼 6.4 Ensure that the Cloud SQL database instance requires all incoming connections to use SSLno data
 💼 6.5 Ensure that Cloud SQL database instances are not open to the worldno data
 💼 6.6 Ensure that Cloud SQL database instances do not have public IPsno data
 💼 6.7 Ensure that Cloud SQL database instances are configured with automated backupsno data
💼 7 BigQuery1no data
 💼 7.1 Ensure that BigQuery datasets are not anonymously or publicly accessibleno data