GCP Knowledge Bases

6.3.5 Ensure 'remote access' Database Flag for Cloud SQL SQL Server Instance Is Set to 'off' (Automated)
Profile Applicability: Level 1 Description: The remote access database flag for Cloud SQL SQL Server instances should be set to off. This flag controls...
Thu, 20 Mar, 2025 at 1:58 AM
6.3.6 Ensure '3625 (Trace Flag)' Database Flag for All Cloud SQL Server Instances Is Set to 'On' (Automated)
Profile Applicability: Level 1 Description: It is recommended to set the 3625 (trace flag) database flag for Cloud SQL SQL Server instances to on. Rat...
Thu, 20 Mar, 2025 at 1:56 AM
6.3.7 Ensure 'Contained Database Authentication' Database Flag for Cloud SQL SQL Server Instances Is Not Set to 'On' (Automated)
Profile Applicability: Level 1 Description: It is recommended to ensure that the contained database authentication database flag for Cloud SQL SQL Serv...
Thu, 20 Mar, 2025 at 1:49 AM
6.4 Ensure All Incoming Connections to Cloud SQL Database Instances Require SSL (Automated)
Profile Applicability: Level 1 Description: It is recommended to enforce SSL encryption for all incoming connections to Cloud SQL database instances to...
Thu, 20 Mar, 2025 at 1:47 AM
6.5 Ensure Cloud SQL Database Instances Do Not Whitelist All Public IP Addresses (Automated)
Profile Applicability: Level 1 Description: Cloud SQL database instances should restrict connections to trusted networks or IP addresses, avoiding acce...
Thu, 20 Mar, 2025 at 1:44 AM
6.6 Ensure That Cloud SQL Database Instances Do Not Have Public IPs (Automated)
Profile Applicability: Level 2 Description: Cloud SQL database instances should use private IPs instead of public IPs to enhance network security and r...
Thu, 20 Mar, 2025 at 1:40 AM
6.7 Ensure That Cloud SQL Database Instances Are Configured With Automated Backups (Automated)
Profile Applicability: Level 1 Description: It is recommended to enable automated backups for all Cloud SQL database instances to safeguard data agains...
Thu, 20 Mar, 2025 at 1:37 AM
7.1 Ensure BigQuery Datasets Are Not Anonymously or Publicly Accessible (Automated)
Profile Applicability: Level 1 Description: It is recommended to ensure that the IAM policy for BigQuery datasets does not grant permissions to anonymo...
Thu, 20 Mar, 2025 at 1:34 AM
7.2 Ensure All BigQuery Tables Are Encrypted With Customer-Managed Encryption Key (CMEK) (Automated)
Profile Applicability Level 2 Description: BigQuery automatically encrypts data at rest using Envelope Encryption with Google-managed cryptographic key...
Thu, 20 Mar, 2025 at 1:29 AM
7.3 Ensure a Default Customer-Managed Encryption Key (CMEK) Is Specified for All BigQuery Datasets (Automated)
Profile Applicability Level 2 Description: By default, BigQuery uses Envelope Encryption with Google-managed cryptographic keys to encrypt data at rest...
Thu, 20 Mar, 2025 at 1:25 AM