Ensure that App Engine applications enforce HTTPS connections Details In order to maintain the highest level of security all connections to an application should be secure by default....
Ensure that Cloud SQL database instances do not have public IPs Details It is recommended to configure Second Generation Sql instance to use private IPs instead of public IPs. Rationale: To...
Ensure that Cloud Storage buckets have uniform bucket-level access enabled Details It is recommended that uniform bucket-level access is enabled on Cloud Storage buckets. Rationale: It is recommended to use...
Ensure that Compute instances do not have public IP addresses Details Compute instances should not be configured to have external IP addresses. Rationale: To reduce your attack surface, Compute instances...
Ensure that Compute instances have Confidential Computing enabled Details Google Cloud encrypts data at-rest and in-transit, but customer data must be decrypted for processing. Confidential Computing is a...
Ensure that RDP access is restricted from the Internet Details GCP Firewall Rules are specific to a VPC Network. Each rule either allows or denies traffic when its conditions...
Ensure that Security Key Enforcement is enabled for all admin accounts Details Setup Security Key Enforcement for Google Cloud Platform admin accounts. Rationale: Google Cloud Platform users with Organization Administrator roles...
Ensure that Separation of duties is enforced while assigning KMS related roles to users Details It is recommended that the principle of ‘Separation of Duties’ is enforced while assigning KMS related roles to users....
Ensure that Separation of duties is enforced while assigning service account related roles to users Details It is recommended that the principle of ‘Separation of Duties’ is enforced while assigning service-account related roles to users....
Ensure that SSH access is restricted from the internet Details GCP Firewall Rules are specific to a VPC Network. Each rule either allows or denies traffic when its conditions...