Skip to main content

๐Ÿ’ผ 1 Identity and Access Management

  • Contextual name: ๐Ÿ’ผ 1 Identity and Access Management
  • ID: /frameworks/cis-gcp-v1.1.0/01
  • Located in: ๐Ÿ’ผ CIS GCP v1.1.0

Descriptionโ€‹

This section covers recommendations addressing Identity and Access Management on Google Cloud Platform.

Similarโ€‹

  • Internal
    • ID: dec-b-6f73b741

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ 1.1 Ensure that corporate login credentials are used11
๐Ÿ’ผ 1.2 Ensure that multi-factor authentication is enabled for all non-service accounts
๐Ÿ’ผ 1.3 Ensure that Security Key Enforcement is enabled for all admin accounts
๐Ÿ’ผ 1.4 Ensure that there are only GCP-managed service account keys for each service account
๐Ÿ’ผ 1.5 Ensure that Service Account has no Admin privileges
๐Ÿ’ผ 1.6 Ensure that IAM users are not assigned the Service Account User or Service Account Token Creator roles at project level
๐Ÿ’ผ 1.7 Ensure user-managed/external keys for service accounts are rotated every 90 days or less
๐Ÿ’ผ 1.8 Ensure that Separation of duties is enforced while assigning service account related roles to users
๐Ÿ’ผ 1.9 Ensure that Cloud KMS cryptokeys are not anonymously or publicly accessible
๐Ÿ’ผ 1.10 Ensure KMS encryption keys are rotated within a period of 90 days
๐Ÿ’ผ 1.11 Ensure that Separation of duties is enforced while assigning KMS related roles to users
๐Ÿ’ผ 1.12 Ensure API keys are not created for a project
๐Ÿ’ผ 1.13 Ensure API keys are restricted to use by only specified Hosts and Apps
๐Ÿ’ผ 1.14 Ensure API keys are restricted to only APIs that application needs access
๐Ÿ’ผ 1.15 Ensure API keys are rotated every 90 days