GCP Knowledge Bases

3.10 Use Identity-Aware Proxy (IAP) to Restrict Access to Google IP Addresses Only (Manual)
Profile Applicability: Level 2 Description: Identity-Aware Proxy (IAP) authenticates user requests to applications using Google Single Sign-On (SSO). You...
Wed, 12 Feb, 2025 at 11:15 AM
4.1 Ensure Instances Are Not Configured To Use the Default Service Account (Automated)
Profile Applicability: Level 1 Description: Instances should not use the default Compute Engine service account as it has broad permissions with the Edit...
Wed, 12 Feb, 2025 at 11:20 AM
4.2 Ensure Instances Are Not Configured to Use the Default Service Account With Full Access to All Cloud APIs (Automated)
Profile Applicability: Level 1 Description: Instances should not be configured to use the default Compute Engine service account with the scope set to &q...
Wed, 12 Feb, 2025 at 11:26 AM
4.3 Ensure “Block Project-Wide SSH Keys” Is Enabled for VM Instances (Automated)
Profile Applicability: Level 1 Description: Enabling Block Project-Wide SSH Keys for VM instances ensures that only instance-specific SSH keys are used f...
Wed, 12 Feb, 2025 at 11:33 AM
4.4 Ensure OS Login Is Enabled for a Project (Automated)
Profile Applicability: Level 1 Description: OS Login binds SSH certificates to IAM users, enabling centralized and automated SSH key management, which si...
Wed, 12 Feb, 2025 at 11:38 AM
4.5 Ensure 'Enable Connecting to Serial Ports' Is Not Enabled for VM Instances (Automated)
Profile Applicability: Level 1 Description: The serial console allows text-based interaction with a virtual machine (VM) instance. However, enabling seri...
Wed, 12 Feb, 2025 at 11:42 AM
4.6 Ensure That IP Forwarding Is Not Enabled on Instances (Automated)
Profile Applicability: Level 1 Description: Google Compute Engine instances are restricted from forwarding packets unless the source and destination IP a...
Wed, 12 Feb, 2025 at 11:46 AM
4.7 Ensure VM Disks for Critical VMs Are Encrypted With Customer-Supplied Encryption Keys (CSEK) (Automated)
Profile Applicability: Level 2 Description: Google Cloud enables customers to encrypt VM disks using Customer-Supplied Encryption Keys (CSEK). These keys...
Wed, 12 Feb, 2025 at 11:52 AM
4.8 Ensure Compute Instances Are Launched With Shielded VM Enabled (Automated)
Profile Applicability: Level 2 Description: Shielded VM is a hardened virtual machine configuration on Google Cloud that defends against rootkits and boo...
Wed, 12 Feb, 2025 at 12:03 PM
4.9 Ensure Compute Instances Do Not Have Public IP Addresses (Automated)
Profile Applicability: Level 2 Description: Compute instances should not have external (public) IP addresses to reduce exposure to the internet. Instead,...
Wed, 12 Feb, 2025 at 12:06 PM