Policy Settings
The GCP CIS v2.0.0 - Section 1 - Identity and Access Management policy pack has 19 policy settings:
Policy | Setting | Note |
---|---|---|
GCP > Dataproc > Cluster > Approved | Check: Approved | GCP CIS v2.0.0 - Control: 1.17 |
GCP > Dataproc > Cluster > Approved > Custom | Calculated | GCP CIS v2.0.0 - Control: 1.17 |
GCP > IAM > API Key > Active | Check: Active | GCP CIS v2.0.0 - Control: 1.15 |
GCP > IAM > API Key > Active > Age | Force inactive if age > 90 days | GCP CIS v2.0.0 - Control: 1.15 |
GCP > IAM > API Key > Approved | Check: Approved | GCP CIS v2.0.0 - Control: 1.12, 1.13, 1.14 |
GCP > IAM > API Key > Approved > Custom | Calculated | GCP CIS v2.0.0 - Control: 1.12, 1.13 and 1.14 |
GCP > IAM > Project User > Approved | Check: Approved | GCP CIS v2.0.0 - Control: 1.6, 1.8 and 1.11 |
GCP > IAM > Project User > Approved > Custom | Calculated | GCP CIS v2.0.0 - Control: 1.6, 1.8 and 1.11 |
GCP > IAM > Service Account > Approved | Check: Approved | GCP CIS v2.0.0 - Control: 1.5 |
GCP > IAM > Service Account > Approved > Custom | Calculated | GCP CIS v2.0.0 - Control: 1.5 |
GCP > IAM > Service Account Key > Active | Check: Active | GCP CIS v2.0.0 - Control: 1.7 |
GCP > IAM > Service Account Key > Active > Age | Force inactive if age > 90 days | GCP CIS v2.0.0 - Control: 1.7 |
GCP > IAM > Service Account Key > Approved | Check: Approved | GCP CIS v2.0.0 - Control: 1.4 |
GCP > IAM > Service Account Key > Approved > Custom | Calculated | GCP CIS v2.0.0 - Control: 1.4 |
GCP > KMS > Crypto Key > Approved | Check: Approved | GCP CIS v2.0.0 - Control: 1.10 |
GCP > KMS > Crypto Key > Approved > Custom | Calculated | GCP CIS v2.0.0 - Control: 1.10 |
GCP > KMS > Crypto Key > Policy > Trusted Access | Check: Trusted Access > * | GCP CIS v2.0.0 - Control: 1.9 |
GCP > KMS > Crypto Key > Policy > Trusted Access > All Authenticated | Do not allow allAuthenticatedUsers | GCP CIS v2.0.0 - Control: 1.9 |
GCP > KMS > Crypto Key > Policy > Trusted Access > All Users | Do not allow allUsers | GCP CIS v2.0.0 - Control: 1.9 |