GCP Knowledge Bases

7.4 Ensure All Data in BigQuery Is Classified (Manual)
Profile Applicability Level 2 Description: BigQuery tables may store sensitive data that requires classification for security and compliance purposes. ...
Thu, 20 Mar, 2025 at 1:21 AM
8.1 Ensure Dataproc Clusters Are Encrypted Using Customer-Managed Encryption Keys (CMEK) (Automated)
Profile Applicability Level 2 Description: Dataproc clusters store data on Persistent Disks (PDs) associated with Compute Engine VMs and in a Cloud Sto...
Thu, 20 Mar, 2025 at 1:15 AM
1.17 Ensure Secrets Are Not Stored in Cloud Functions Environment Variables by Using Secret Manager (Manual)
Profile Applicability: Level 1 Description: Google Cloud Functions provide a serverless environment for running code in response to events. While environ...
Wed, 19 Mar, 2025 at 2:14 AM
1.10 Ensure KMS Encryption Keys Are Rotated Within a Period of 90 Days (Automated)
Profile Applicability: Level 1 Description: Google Cloud Key Management Service (KMS) stores cryptographic keys in a hierarchical structure, allowing eff...
Fri, 21 Feb, 2025 at 3:31 AM
Ensure GKE Clusters Are Not Running Using the Compute Engine Default Service Account
Profile Applicability: Level 2 Description: Google Kubernetes Engine (GKE) clusters should not use the default Compute Engine service account, as it ...
Wed, 28 May, 2025 at 3:34 AM
Ensure Image Vulnerability Scanning Using GCR Container Scanning or a Third-Party Provider
Profile Applicability: Level 2 Description: Container images deployed in Google Cloud environments should be scanned for vulnerabilities to ensure th...
Wed, 28 May, 2025 at 3:58 AM
Ensure Image Vulnerability Analysis Using AR Container Analysis or a Third-Party Provider
Profile Applicability: Level 2 Description: Container images deployed in Google Cloud or any other cloud environment should be analyzed for vulnerabi...
Wed, 28 May, 2025 at 4:12 AM
Ensure Any Public Addresses Are Listed in Shodan (Using Shodan API)
Profile Applicability: Level 2 Description: Public IP addresses assigned to your cloud infrastructure should be regularly checked against Shodan, a p...
Wed, 28 May, 2025 at 6:47 AM
Ensure Instance IP Assignment Is Set to Private
Profile Applicability: Level 1 Description: Cloud instances should be configured to use private IP addresses instead of public IPs whenever possible....
Wed, 28 May, 2025 at 6:57 AM