Mods
GCP

Policy: GCP > CIS v1 > 1 Identity and Access Management > 1.10 Ensure API keys are not created for a project (Not Scored)

Configures auditing against a CIS Benchmark item.

Level: 2 (Not Scored)

Keys are insecure because they can be viewed publicly, such as from within a browser, or they can be accessed on a device where the key resides. It is recommended to use standard authentication flow instead.

Resource Types

This policy targets the following resource types:

Primary Policy

This policy is used with the following primary policy:

Controls

Policy Specification

Schema Type
string
Default
Per GCP > CIS v1 using attestation
Valid Values [YAML]
  • Per GCP > CIS v1 using attestation
    
  • Skip
    
  • Check: Level 2 (Not Scored) using attestation
    

Category

In Your Workspace

Developers