Skip to main content

๐Ÿ’ผ 4 Virtual Machines

  • Contextual name: ๐Ÿ’ผ 4 Virtual Machines
  • ID: /frameworks/cis-gcp-v1.2.0/04
  • Located in: ๐Ÿ’ผ CIS GCP v1.2.0

Descriptionโ€‹

This section covers recommendations addressing virtual machines on Google Cloud Platform.

Similarโ€‹

  • Internal
    • ID: dec-b-e8215080

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ 4.1 Ensure that instances are not configured to use the default service account - Level 1 (Automated)
๐Ÿ’ผ 4.2 Ensure that instances are not configured to use the default service account with full access to all Cloud APIs - Level 1 (Automated)
๐Ÿ’ผ 4.3 Ensure "Block Project-wide SSH keys" is enabled for VM instances - Level 1 (Automated)
๐Ÿ’ผ 4.4 Ensure oslogin is enabled for a Project - Level 1 (Automated)
๐Ÿ’ผ 4.5 Ensure 'Enable connecting to serial ports' is not enabled for VM Instance - Level 1 (Automated)
๐Ÿ’ผ 4.6 Ensure that IP forwarding is not enabled on Instances - Level 1 (Automated)
๐Ÿ’ผ 4.7 Ensure VM disks for critical VMs are encrypted with Customer-Supplied Encryption Keys (CSEK) - Level 2 (Automated)
๐Ÿ’ผ 4.8 Ensure Compute instances are launched with Shielded VM enabled - Level 2 (Automated)
๐Ÿ’ผ 4.9 Ensure that Compute instances do not have public IP addresses - Level 2 (Automated)
๐Ÿ’ผ 4.10 Ensure that App Engine applications enforce HTTPS connections - Level 2 (Manual _ Not supported, requires a manual assessment)
๐Ÿ’ผ 4.11 Ensure that Compute instances have Confidential Computing enabled - Level 2 (Automated)