Turbot Guardrails Hub 
Hub
  • Mods
  • Policy Packs
  • Docs
  • Home
ModsPolicy PacksDocsHome
Policy Packs
GCP CIS v2.0.0 - Section 4 - Virtual Machines
  • GCP > Compute Engine > Disk > Approved
  • GCP > Compute Engine > Disk > Approved > Encryption at Rest
  • GCP > Compute Engine > Instance > Approved
  • GCP > Compute Engine > Instance > Approved > Custom
  • GCP > Compute Engine > Instance > Approved > IP Forwarding
  • GCP > Compute Engine > Instance > Block Project Wide SSH Keys
  • GCP > Compute Engine > Instance > External IP Addresses
  • GCP > Compute Engine > Instance > Serial Port Access
  • GCP > Compute Engine > Instance > Shielded Instance Configuration
  • GCP > Compute Engine > Instance > Shielded Instance Configuration > Integrity Monitoring
  • GCP > Compute Engine > Instance > Shielded Instance Configuration > vTPM
  • GCP > Compute Engine > Project > OS Login Enabled

Policy Settings

The GCP CIS v2.0.0 - Section 4 - Virtual Machines policy pack has 12 policy settings:

PolicySettingNote
GCP > Compute Engine > Disk > ApprovedCheck: ApprovedGCP CIS v2.0.0 - Control: 4.7
GCP > Compute Engine > Disk > Approved > Encryption at RestCustomer supplied keyGCP CIS v2.0.0 - Control: 4.7
GCP > Compute Engine > Instance > ApprovedCheck: ApprovedGCP CIS v2.0.0 - Control: 4.1, 4.2, 4.6 and 4.11
GCP > Compute Engine > Instance > Approved > CustomCalculatedGCP CIS v2.0.0 - Control: 4.1, 4.2 and 4.11
GCP > Compute Engine > Instance > Approved > IP ForwardingApproved if disabledGCP CIS v2.0.0 - Control: 4.6
GCP > Compute Engine > Instance > Block Project Wide SSH KeysCheck: EnabledGCP CIS v2.0.0 - Control: 4.3
GCP > Compute Engine > Instance > External IP AddressesCheck: NoneGCP CIS v2.0.0 - Control: 4.9
GCP > Compute Engine > Instance > Serial Port AccessCheck: DisabledGCP CIS v2.0.0 - Control: 4.5
GCP > Compute Engine > Instance > Shielded Instance ConfigurationCheck: Enabled per `Shielded Instance Configuration > *`GCP CIS v2.0.0 - Control: 4.8
GCP > Compute Engine > Instance > Shielded Instance Configuration > Integrity MonitoringEnabledGCP CIS v2.0.0 - Control: 4.8
GCP > Compute Engine > Instance > Shielded Instance Configuration > vTPMEnabledGCP CIS v2.0.0 - Control: 4.8
GCP > Compute Engine > Project > OS Login EnabledCheck: EnabledGCP CIS v2.0.0 - Control: 4.4
Guardrails
Guardrails Hub
  • Hub
  • Docs
  • Blog
  • Changelog
Products
  • GuardrailsGuardrails
  • PipesPipes
  • SteampipeSteampipe
  • PowerpipePowerpipe
  • FlowpipeFlowpipe
  • TailpipeTailpipe
Turbot
  • Home
  • About us
  • We're hiring!
  • Contact us
Community

Our community of practitioners love to discuss cloud governance & security.

Slack logoJoin us on Slack →

System StatusLegalSecurity
Terms of UseSecurityPrivacy