Skip to main content

💼 1.14 Ensure API Keys Are Restricted to Only APIs That Application Needs Access - Level 2 (Automated)

  • ID: /frameworks/cis-gcp-v2.0.0/01/14

Description

API Keys should only be used for services in cases where other authentication methods are unavailable. API keys are always at risk because they can be viewed publicly, such as from within a browser, or they can be accessed on a device where the key resides. It is recommended to restrict API keys to use (call) only APIs required by an application.

Similar

  • Sections
    • /frameworks/cis-gcp-v3.0.0/01/14
    • /frameworks/cis-gcp-v1.3.0/01/14
  • Internal
    • ID: dec-c-07ba5987

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 CIS GCP v1.3.0 → 💼 1.14 Ensure API Keys Are Restricted to Only APIs That Application Needs Access - Level 1 (Manual)1no data
💼 CIS GCP v3.0.0 → 💼 1.14 Ensure API Keys Are Restricted to Only APIs That Application Needs Access - Level 2 (Automated)1no data

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 CIS GCP v1.3.0 → 💼 1.14 Ensure API Keys Are Restricted to Only APIs That Application Needs Access - Level 1 (Manual)1no data
💼 CIS GCP v3.0.0 → 💼 1.14 Ensure API Keys Are Restricted to Only APIs That Application Needs Access - Level 2 (Automated)1no data

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance

Policies (1)

PolicyLogic CountFlagsCompliance
🛡️ Google API Key is not restricted for unused APIs🟢1🟢 x6no data