Assured Workloads frameworks
This page provides reference content for the built-in frameworks that are included in Assured Workloads and Audit Manager.
Google Recommended AI Essentials - Gemini Enterprise Agent Platform
Supported cloud provider: Google Cloud
This framework outlines Google recommended security best practices for Gemini Enterprise Agent Platform workloads, providing a prescriptive collection of essential preventative and detective policies. When you acctivate AI Protection within the Security Command Center, a detailed security compliance assessment against this framework is automatically displayed on the Agent Platform Security dashboard.
This framework includes the following cloud controls:
- Block Default VPC Network for Agent Platform Workbench Instances
- Block File Downloading in JupyterLab Console
- Block Internet Access for Runtime Templates in Agent Platform Colab Enterprise
- Block Internet Access for Runtime Templates in Agent Platform Colab Enterprise
- Block Public IP Address for Agent Platform Workbench Instances
- Block Root Access on Agent Platform Workbench Instances
- Define Secret Manager Replication Policy
- Enable Audit Logging for Agent Platform
- Enable Automatic Upgrades for Agent Platform WorkBench Instances
- Enable CMEK for Agent Platform Custom Jobs
- Enable CMEK for Agent Platform Datasets
- Enable CMEK for Agent Platform Feature Store
- Enable CMEK for Agent Platform Hyperparameter Tuning Jobs
- Enable CMEK for Agent Platform instances
- Enable CMEK for Agent Platform Metadata Stores
- Enable CMEK for Agent Platform Model Endpoints
- Enable CMEK for Agent Platform Models
- Enable CMEK for Agent Platform TensorBoard
- Enable CMEK for Agent Platform Training Pipelines
- Enable CMEK for Agent Platform Workbench Instance Disks
- Enable CMEK for Runtime Templates in Agent Platform Colab Enterprise
- Enable Delete to Trash Feature for Agent Platform Workbench Instances
- Enable Integrity Monitoring for Agent Platform Workbench Instances
- Enable Model Armor
- Enable Secure Boot for Agent Platform Workbench Instances
- Enable Secure Boot for Runtime Templates in Agent Platform Colab Enterprise
- Enable vTPM on Agent Platform Workbench Instances
- Restrict the Use of Default Service Account for Agent Platform Workbench Instances
- Use labels for Agent Platform agents
CIS GCP Foundations Benchmark v3.0
Supported cloud provider: Google Cloud
Prescriptive guidance for establishing a secure baseline configuration for Google Cloud Platform. This benchmark provides technical best practices for hardening foundational services like IAM, Logging, Networking, and Storage.
This framework includes the following cloud controls:
- Avoid RSASHA1 for DNSSEC Signing
- Block Generic Access to RDP Ports
- Block Generic Access to SSH Ports
- Block Project-Wide SSH Keys on Compute Engine Instances
- Block Public IP Addresses for Cloud SQL Instances
- Block Serial Ports for Compute Engine Instances
- Define Essential Contacts
- Don't Use User Connections Flag for SQL Server
- Don't Use User Options Flag for SQL Server
- Enable 3625 Trace Database Flag for SQL Server
- Enable Automatic Backups for Cloud SQL Databases
- Enable Cloud Asset Inventory Service
- Enable CMEK for BigQuery Datasets
- Enable CMEK for BigQuery Tables
- Enable Confidential Computing for Compute Engine Instances
- Enable CSEK On Compute Engine Persistent Disks
- Enable DNSSEC for Cloud DNS
- Enable Flow Logs for VPC Subnet
- Enable Load Balancer Logging
- Enable Log Connections Flag for PostgreSQL
- Enable Log Disconnections Flag for PostgreSQL
- Enable Log Error Verbosity Flag for PostgreSQL
- Enable Log Min Error Statement Flag for PostgreSQL
- Enable Log Min Messages Flag for PostgreSQL
- Enable Log Statement Flag for PostgreSQL
- Enable Shielded VM for Compute Engine Instances
- Enable Skip Show Database Flag for MySQL
- Enable Uniform Bucket-Level Access on Cloud Storage Buckets
- Lock Storage Bucket Retention Policies
- Prevent IP Forwarding on Compute Engine Instances
- Require CMEK on Dataproc Clusters
- Require Rotation of API Key
- Require Service Account Key Rotation
- Restrict API Access to Google Cloud APIs for Compute Engine Instances
- Restrict API Keys for Required APIs Only
- Restrict Insecure SSL Policies for Compute Engine Instances
- Restrict Public Access to BigQuery Datasets
- Restrict Public Access to Cloud SQL Database Instances
- Restrict Public Access to Cloud Storage Buckets
- Restrict Public IP Addresses to Compute Engine Instances
- Restrict User Managed Service Account Keys
- Set Application Restriction on API Keys
- Turn Off Contained Database Authentication Flag for SQL Server
- Turn Off Cross Database Ownership Chaining Flag for SQL Server
- Turn Off External Scripts Flag for SQL Server
- Turn Off Local Infile Flag for MySQL
- Turn Off Log Min Duration Statement Flag for PostgreSQL
- Turn Off Remote Access Flag for SQL Server
- Use Custom Service Accounts for Compute Engine Instances
- Use Custom VPC Networks
CIS GKE 1.7
Supported cloud provider: Google Cloud
The CIS GKE Benchmark is a set of security recommendations and best practices specifically tailored for Google Kubernetes Engine (GKE) clusters. The benchmark aims to enhance the security posture of GKE environments.
This framework includes the following cloud controls:
- Block Legacy Authorization on GKE Clusters
- Disable Alpha Features on GKE Clusters
- Disable Client Certificate Authentication for GKE
- Disable Legacy Metadata Server Endpoints on Compute Engine
- Don't Use Kubernetes Web UI
- Enable Auto Repair for GKE Clusters
- Enable Auto Upgrade on GKE Clusters
- Enable Cloud Logging on GKE Clusters
- Enable Cloud Monitoring on GKE Clusters
- Enable CMEK on GKE Node Pool Boot Disks
- Enable Control Plane Authorized Networks on GKE Clusters
- Enable Encryption on GKE Clusters
- Enable Integrity Monitoring on GKE Clusters
- Enable Intranode Visibility for GKE Clusters
- Enable IP Alias Range for GKE Clusters
- Enable Network Policy on GKE Clusters
- Enable PodSecurityPolicies for GKE Clusters
- Enable Private Clusters for GKE
- Enable Secure Boot for Shielded GKE Nodes
- Enable Shielded GKE Nodes on a Cluster
- Enable Workload Identity Federation for GKE on clusters
- Require Container-Optimized OS for a GKE Cluster
- Require GKE Sandbox for GKE clusters
- Require Private Nodes in GKE Clusters
- Require Workload Identity Federation for GKE and the GKE Metadata Server
- Subscribe a GKE Cluster to a Release Channel
- Use Google Groups for Kubernetes RBAC
- Use Least Privilege Service Accounts for GKE Clusters
CIS Critical Security Controls v8
Supported cloud provider: Google Cloud
A prioritized set of safeguards to protect against prevalent cyber threats. It offers a practical approach to cyber defense, tiered into Implementation Groups (IG1, IG2, IG3) to suit organizations of varying maturity.
This framework includes the cloud control groups and cloud controls in the following sections.
cis-controls-1-1
Establish and maintain an accurate, detailed, and up-to-date inventory of all enterprise assets with the potential to store or process data, to include: end-user devices (including portable and mobile), network devices, non-computing/IoT devices, and servers. Ensure the inventory records the network address (if static), hardware address, machine name, enterprise asset owner, department for each asset, and whether the asset has been approved to connect to the network. For mobile end-user devices, MDM type tools can support this process, where appropriate. This inventory includes assets connected to the infrastructure physically, virtually, remotely, and those within cloud environments. Additionally, it includes assets that are regularly connected to the enterprise’s network infrastructure, even if they are not under control of the enterprise. Review and update the inventory of all enterprise assets bi-annually, or more frequently.
- Create and Manage Asymmetric Keys
- Define Set Storage Class Lifestyle Action on Bucket
- Enable Cloud Asset Inventory Service
cis-controls-10-2
Configure automatic updates for anti-malware signature files on all enterprise assets.
- Enable Object Versioning on Buckets
- Enable Subnet Flow Logs
- Enable VPC Flow Logs for Compute Engine Instances
cis-controls-10-3
Disable autorun and autoplay auto-execute functionality for removable media.
cis-controls-10-6
Centrally manage anti-malware software.
- Enable Log Locks Wait Flag for PostgreSQL instance
- Enable Subnet Flow Logs
- Enable VPC Flow Logs for Compute Engine Instances
cis-controls-11-1
Establish and maintain a documented data recovery process that includes detailed backup procedures. In the process, address the scope of data recovery activities, recovery prioritization, and the security of backup data. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
- Enable AlloyDB Automated Backups on Cluster
- Enable AlloyDB Backups on Cluster
- Enable Auto Repair for GKE Clusters
cis-controls-11-2
Perform automated backups of in-scope enterprise assets. Run backups weekly, or more frequently, based on the sensitivity of the data.
- Enable AlloyDB Automated Backups on Cluster
- Enable AlloyDB Backups on Cluster
- Enable Automatic Backups for Cloud SQL Databases
cis-controls-11-3
Protect recovery data with equivalent controls to the original data. Reference encryption or data separation, based on requirements.
- Enable AlloyDB Automated Backups on Cluster
- Enable AlloyDB Backups on Cluster
- Enable SSL Encryption On AlloyDB Instances
cis-controls-11-4
Establish and maintain an isolated instance of recovery data. Example implementations include, version controlling backup destinations through offline, cloud, or off-site systems or services.
cis-controls-11-5
Test backup recovery quarterly, or more frequently, for a sampling of in-scope enterprise assets.
cis-controls-12-2
Design and maintain a secure network architecture. A secure network architecture must address segmentation, least privilege, and availability, at a minimum. Example implementations may include documentation, policy, and design components.
- Block Generic Access to DNS Ports from All IP Addresses
- Block Generic Access to Elasticsearch Ports from All IP Addresses
- Block Generic Access to FTP Ports
- Block Generic Access to HTTP Ports
- Block Generic Access to LDAP Ports
- Block Generic Access to Memcached Ports
- Block Generic Access to MongoDB Ports
- Block Generic Access to MySQL Ports
- Block Generic Access to NetBIOS Ports from All IP Addresses
- Block Generic Access to Oracle Database Ports
- Block Generic Access to POP3 Server Ports
- Block Generic Access to PostgreSQL Server Ports from All IP Addresses
- Block Generic Access to Redis Server Ports from All IP Addresses
- Block Generic Access to SMTP Server Ports
- Block Generic Access to Telnet Servers
- Block Overly Permissive Firewall Rules
- Configure Access Controls for the Network Boundary
- Configure the Allowed Ingress Settings for Cloud Run Organization Policy Constraint
- Configure the Allowed VPC Egress Settings for Cloud Run Organization Policy Constraint
- Configure the Disable VPC Internal IPv6 Usage Organization Policy
- Enable Control Plane Authorized Networks on GKE Clusters
- Enable IP Alias Range for GKE Clusters
- Enable Private Clusters for GKE
- Enable Private Google Access on an instance
cis-controls-12-3
Securely manage network infrastructure. Example implementations include version-controlled Infrastructure-as-Code (IaC), and the use of secure network protocols, such as SSH and HTTPS.
- Block Service Account Key Creation
- Block Service Account Key Uploads
- Configure Access Controls for the Network Boundary
- Configure the Disable VPC Internal IPv6 Usage Organization Policy
- Define a Security Policy to Mitigate for DDoS Events
- Enable Network Policy on GKE Clusters
cis-controls-12-5
Centralize network AAA.
- Set Log Min Error Statement Flag for AlloyDB Instances
- Set Log Min Messages Flag for AlloyDB Instances
cis-controls-12-6
Adopt secure network management protocols (e.g., 802.1X) and secure communication protocols (e.g., Wi-Fi Protected Access 2 (WPA2) Enterprise or more secure alternatives).
cis-controls-12-7
Require users to authenticate to enterprise-managed VPN and authentication services prior to accessing enterprise resources on end-user devices.
- Define Secret Manager Rotation Schedule
- Set Log Min Error Statement Flag for AlloyDB Instances
- Set Log Min Messages Flag for AlloyDB Instances
cis-controls-13-1
Centralize security event alerting across enterprise assets for log correlation and analysis. Best practice implementation requires the use of a SIEM, which includes vendor-defined event correlation alerts. A log analytics platform configured with security-relevant correlation alerts also satisfies this Safeguard.
cis-controls-13-2
Deploy a host-based intrusion detection solution on enterprise assets, where appropriate and/or supported.
cis-controls-13-3
Deploy a network intrusion detection solution on enterprise assets, where appropriate. Example implementations include the use of a Network Intrusion Detection System (NIDS) or equivalent cloud service provider (CSP) service.
- Enable Intranode Visibility for GKE Clusters
- Prevent Nested Virtualization for Compute Engine VMs
- Restrict Public IP Addresses on Agent Platform Workbench Notebooks and Instances
cis-controls-13-4
Perform traffic filtering between network segments, where appropriate.
- Block Generic Access to DNS Ports from All IP Addresses
- Block Generic Access to Elasticsearch Ports from All IP Addresses
- Block Generic Access to FTP Ports
- Block Generic Access to HTTP Ports
- Block Generic Access to LDAP Ports
- Block Generic Access to Memcached Ports
- Block Generic Access to MongoDB Ports
- Block Generic Access to MySQL Ports
- Block Generic Access to NetBIOS Ports from All IP Addresses
- Block Generic Access to Oracle Database Ports
- Block Generic Access to POP3 Server Ports
- Block Generic Access to PostgreSQL Server Ports from All IP Addresses
- Block Generic Access to Redis Server Ports from All IP Addresses
- Block Generic Access to SMTP Server Ports
- Block Generic Access to Telnet Servers
- Block Overly Permissive Firewall Rules
- Configure the Allowed Ingress Settings for Cloud Run Organization Policy Constraint
- Configure the Disable VPC Internal IPv6 Usage Organization Policy
- Define a Security Policy to Mitigate for DDoS Events
- Implement Continuous Network Traffic Monitoring
cis-controls-13-5
Manage access control for assets remotely connecting to enterprise resources. Determine amount of access to enterprise resources based on: up-to-date anti-malware software installed, configuration compliance with the enterprise’s secure configuration process, and ensuring the operating system and applications are up-to-date.
- Block Generic Access to DNS Ports from All IP Addresses
- Block Generic Access to Elasticsearch Ports from All IP Addresses
- Block Generic Access to FTP Ports
- Block Generic Access to HTTP Ports
- Block Generic Access to LDAP Ports
- Block Generic Access to Memcached Ports
- Block Generic Access to MongoDB Ports
- Block Generic Access to MySQL Ports
- Block Generic Access to NetBIOS Ports from All IP Addresses
- Block Generic Access to Oracle Database Ports
- Block Generic Access to POP3 Server Ports
- Block Generic Access to PostgreSQL Server Ports from All IP Addresses
- Block Generic Access to Redis Server Ports from All IP Addresses
- Block Generic Access to SMTP Server Ports
- Block Generic Access to Telnet Servers
- Block Overly Permissive Firewall Rules
- Define Set Storage Class Lifestyle Action on Bucket
cis-controls-13-6
Collect network traffic flow logs and/or network traffic to review and alert upon from network devices.
- Block Generic Access to DNS Ports from All IP Addresses
- Block Generic Access to Elasticsearch Ports from All IP Addresses
- Block Generic Access to FTP Ports
- Block Generic Access to HTTP Ports
- Block Generic Access to LDAP Ports
- Block Generic Access to Memcached Ports
- Block Generic Access to MongoDB Ports
- Block Generic Access to MySQL Ports
- Block Generic Access to NetBIOS Ports from All IP Addresses
- Block Generic Access to Oracle Database Ports
- Block Generic Access to POP3 Server Ports
- Block Generic Access to PostgreSQL Server Ports from All IP Addresses
- Block Generic Access to Redis Server Ports from All IP Addresses
- Block Generic Access to SMTP Server Ports
- Block Generic Access to Telnet Servers
- Block Overly Permissive Firewall Rules
- Configure the Allowed VPC Egress Settings for Cloud Run Organization Policy Constraint
- Enable Control Plane Authorized Networks on GKE Clusters
- Enable IP Alias Range for GKE Clusters
cis-controls-13-7
Deploy a host-based intrusion prevention solution on enterprise assets, where appropriate and/or supported. Example implementations include use of an Endpoint Detection and Response (EDR) client or host-based IPS agent.
- Configure the Allowed Ingress Settings for Cloud Run Organization Policy Constraint
- Implement Continuous Network Traffic Monitoring
cis-controls-13-8
Deploy a network intrusion prevention solution, where appropriate. Example implementations include the use of a Network Intrusion Prevention System (NIPS) or equivalent CSP service.
- Prevent Nested Virtualization for Compute Engine VMs
- Restrict Public IP Addresses on Agent Platform Workbench Notebooks and Instances
cis-controls-13-9
Deploy port-level access control. Port-level access control utilizes 802.1x, or similar network access control protocols, such as certificates, and may incorporate user and/or device authentication.
- Block Generic Access to DNS Ports from All IP Addresses
- Block Generic Access to Elasticsearch Ports from All IP Addresses
- Block Generic Access to FTP Ports
- Block Generic Access to HTTP Ports
- Block Generic Access to LDAP Ports
- Block Generic Access to Memcached Ports
- Block Generic Access to MongoDB Ports
- Block Generic Access to MySQL Ports
- Block Generic Access to NetBIOS Ports from All IP Addresses
- Block Generic Access to Oracle Database Ports
- Block Generic Access to POP3 Server Ports
- Block Generic Access to PostgreSQL Server Ports from All IP Addresses
- Block Generic Access to Redis Server Ports from All IP Addresses
- Block Generic Access to SMTP Server Ports
- Block Generic Access to Telnet Servers
- Block Overly Permissive Firewall Rules
- Configure the Allowed VPC Egress Settings for Cloud Run Organization Policy Constraint
- Enable Control Plane Authorized Networks on GKE Clusters
- Enable IP Alias Range for GKE Clusters
- Enable Private Google Access on an instance
cis-controls-14-1
Establish and maintain a security awareness program. The purpose of a security awareness program is to educate the enterprise’s workforce on how to interact with enterprise assets and data in a secure manner. Conduct training at hire and, at a minimum, annually. Review and update content annually, or when significant enterprise changes occur that could impact this Safeguard.
cis-controls-14-3
Train workforce members on authentication best practices. Example topics include MFA, password composition, and credential management.
cis-controls-14-5
Train workforce members to be aware of causes for unintentional data exposure. Example topics include mis-delivery of sensitive data, losing a portable end-user device, or publishing data to unintended audiences.
cis-controls-16-1
Establish and maintain a secure application development process. In the process, address such items as: secure application design standards, secure coding practices, developer training, vulnerability management, security of third-party code, and application security testing procedures. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
- Enable Artifact Analysis Vulnerability Scanning
- Require Rotation of API Key
- Restrict API Keys for Required APIs Only
- Set Application Restriction on API Keys
cis-controls-16-11
Leverage vetted modules or services for application security components, such as identity management, encryption, auditing, and logging. Using platform features in critical security functions will reduce developers’ workload and minimize the likelihood of design or implementation errors. Modern operating systems provide effective mechanisms for identification, authentication, and authorization and make those mechanisms available to applications. Use only standardized, currently accepted, and extensively reviewed encryption algorithms. Operating systems also provide mechanisms to create and maintain secure audit logs.
- Configure the Allowed Ingress Settings for Cloud Run Organization Policy Constraint
- Enable CMEK for Cloud SQL Databases
- Enable SSL Encryption On AlloyDB Instances
- Encrypt Pub/Sub topic with CMEK
- Restrict Insecure SSL Policies for Compute Engine Instances
cis-controls-16-12
Apply static and dynamic analysis tools within the application life cycle to verify that secure coding practices are being followed.
cis-controls-16-2
Establish and maintain a process to accept and address reports of software vulnerabilities, including providing a means for external entities to report. The process is to include such items as: a vulnerability handling policy that identifies reporting process, responsible party for handling vulnerability reports, and a process for intake, assignment, remediation, and remediation testing. As part of the process, use a vulnerability tracking system that includes severity ratings and metrics for measuring timing for identification, analysis, and remediation of vulnerabilities. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard. Third-party application developers need to consider this an externally-facing policy that helps to set expectations for outside stakeholders.
cis-controls-16-3
Perform root cause analysis on security vulnerabilities. When reviewing vulnerabilities, root cause analysis is the task of evaluating underlying issues that create vulnerabilities in code, and allows development teams to move beyond just fixing individual vulnerabilities as they arise.
cis-controls-16-7
Use standard, industry-recommended hardening configuration templates for application infrastructure components. This includes underlying servers, databases, and web servers, and applies to cloud containers, Platform as a Service (PaaS) components, and SaaS components. Do not allow in-house developed software to weaken configuration hardening.
- Set Log Min Messages Flag for AlloyDB Instances
- Turn Off Local Infile Flag for MySQL
- Turn off Log Parser Stats Flag for PostgreSQL
- Turn off Log Planner Stats Flag for PostgreSQL
cis-controls-17-2
Establish and maintain contact information for parties that need to be informed of security incidents. Contacts may include internal staff, service providers, law enforcement, cyber insurance providers, relevant government agencies, Information Sharing and Analysis Center (ISAC) partners, or other stakeholders. Verify contacts annually to ensure that information is up-to-date.
cis-controls-17-4
Establish and maintain a documented incident response process that addresses roles and responsibilities, compliance requirements, and a communication plan. Review annually, or when significant enterprise changes occur that could impact this Safeguard.
- Define Agent Platform Workbench Instance Access Mode
- Enable Log Locks Wait Flag for PostgreSQL instance
- Set Log Min Messages Flag for AlloyDB Instances
cis-controls-17-9
Establish and maintain security incident thresholds, including, at a minimum, differentiating between an incident and an event. Examples can include: abnormal activity, security vulnerability, security weakness, data breach, privacy incident, etc. Review annually, or when significant enterprise changes occur that could impact this Safeguard.
cis-controls-18-1
Establish and maintain a penetration testing program appropriate to the size, complexity, industry, and maturity of the enterprise. Penetration testing program characteristics include scope, such as network, web application, Application Programming Interface (API), hosted services, and physical premise controls; frequency; limitations, such as acceptable hours, and excluded attack types; point of contact information; remediation, such as how findings will be routed internally; and retrospective requirements.
- Enable the Restrict Authorized Networks on Cloud SQL Instances Organization Policy Constraint
- Use Latest Image Versions on Dataproc Clusters
cis-controls-18-2
Perform periodic external penetration tests based on program requirements, no less than annually. External penetration testing must include enterprise and environmental reconnaissance to detect exploitable information. Penetration testing requires specialized skills and experience and must be conducted through a qualified party. The testing may be clear box or opaque box.
- Define a Security Policy to Mitigate for DDoS Events
- Enable the Restrict Authorized Networks on Cloud SQL Instances Organization Policy Constraint
- Use Latest Image Versions on Dataproc Clusters
cis-controls-18-5
Perform periodic internal penetration tests based on program requirements, no less than annually. The testing may be clear box or opaque box.
cis-controls-2-7
Use technical controls, such as digital signatures and version control, to ensure that only authorized scripts, such as specific .ps1 and .py files, are allowed to execute. Block unauthorized scripts from executing. Reassess bi-annually, or more frequently.
cis-controls-3-1
Establish and maintain a documented data management process. In the process, address data sensitivity, data owner, handling of data, data retention limits, and disposal requirements, based on sensitivity and retention standards for the enterprise. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
- Block Generic Access to DNS Ports from All IP Addresses
- Block Generic Access to Elasticsearch Ports from All IP Addresses
- Block Generic Access to FTP Ports
- Block Generic Access to HTTP Ports
- Block Generic Access to LDAP Ports
- Block Generic Access to Memcached Ports
- Block Generic Access to MongoDB Ports
- Block Generic Access to MySQL Ports
- Block Generic Access to NetBIOS Ports from All IP Addresses
- Block Generic Access to Oracle Database Ports
- Block Generic Access to POP3 Server Ports
- Block Generic Access to PostgreSQL Server Ports from All IP Addresses
- Block Generic Access to Redis Server Ports from All IP Addresses
- Block Generic Access to SMTP Server Ports
- Block Generic Access to Telnet Servers
- Block Overly Permissive Firewall Rules
- Block Project-Wide SSH Keys on Compute Engine Instances
- Configure the Allowed VPC Egress Settings for Cloud Run Organization Policy Constraint
- Create and Manage Asymmetric Keys
- Enable Artifact Analysis Vulnerability Scanning
- Enable Control Plane Authorized Networks on GKE Clusters
- Enable IP Alias Range for GKE Clusters
- Enable Private Google Access on an instance
- Enable SSL Encryption On AlloyDB Instances
- Encrypt Data at Rest with CMEK
- Enforce CMEK
- Enforce Public Access Prevention
- Enforce SSL for all Incoming Database Connections
cis-controls-3-11
Encrypt sensitive data at rest on servers, applications, and databases. Storage-layer encryption, also known as server-side encryption, meets the minimum requirement of this Safeguard. Additional encryption methods may include application-layer encryption, also known as client-side encryption, where access to the data storage device(s) does not permit access to the plain-text data.
- Create and Manage Asymmetric Keys
- Enable CMEK for AlloyDB Clusters
- Enable CMEK for BigQuery Datasets
- Enable CMEK for BigQuery Tables
- Enable CMEK on Compute Engine Persistent Disks
- Enable CMEK on GKE Node Pool Boot Disks
- Enable Confidential Computing for Compute Engine Instances
- Enable CSEK On Compute Engine Persistent Disks
- Enable Encryption on GKE Clusters
- Enable SSL Encryption On AlloyDB Instances
- Encrypt Data at Rest with CMEK
- Enforce CMEK
- Require CMEK on Dataproc Clusters
- Restrict Non CMEK Services
cis-controls-3-14
Log sensitive data access, including modification and disposal.
cis-controls-3-2
Establish and maintain a data inventory based on the enterprise’s data management process. Inventory sensitive data, at a minimum. Review and update inventory annually, at a minimum, with a priority on sensitive data.
cis-controls-3-3
Configure data access control lists based on a user’s need to know. Apply data access control lists, also known as access permissions, to local and remote file systems, databases, and applications.
- Block Generic Access to Cassandra Ports
- Block Public IP Addresses for AlloyDB Cluster Instances
- Block Public IP Addresses for Cloud SQL Instances
- Configure the Disable VM Serial Port Logging to Stackdriver Organization Policy
- Define Storage Class Lifestyle Action
- Enable Control Plane Authorized Networks on GKE Clusters
- Enable IP Alias Range for GKE Clusters
- Enable Object Versioning on Buckets
- Enable OS Login
- Enable Private Google Access on an instance
- Enable Skip Show Database Flag for MySQL
- Enable the Restrict Authorized Networks on Cloud SQL Instances Organization Policy Constraint
- Enable Uniform Bucket-Level Access on Cloud Storage Buckets
- Enforce Public Access Prevention
- Restrict Public Access to BigQuery Datasets
- Restrict Public Access to Cloud SQL Database Instances
- Restrict Public Access to Cloud Storage Buckets
- Restrict Public IP Addresses to Compute Engine Instances
- Set Uniform Bucket Level Access for Cloud Storage Buckets
- Turn Off Contained Database Authentication Flag for SQL Server
- Turn Off Cross Database Ownership Chaining Flag for SQL Server
cis-controls-3-4
Retain data according to the enterprise’s documented data management process. Data retention must include both minimum and maximum timelines.
- Define Retention Period for Cloud Storage Buckets
- Disable File Downloads on Agent Platform Workbench Instances
- Lock Storage Bucket Retention Policies
- Require Object Versioning for Cloud Storage Buckets
cis-controls-3-5
Securely dispose of data as outlined in the enterprise’s documented data management process. Ensure the disposal process and method are commensurate with the data sensitivity.
- Define Retention Period for Cloud Storage Buckets
- Define Storage Class Lifestyle Action
- Require Object Versioning for Cloud Storage Buckets
cis-controls-3-6
Encrypt data on end-user devices containing sensitive data. Example implementations can include: Windows BitLocker®, Apple FileVault®, Linux® dm-crypt.
- Don't Use Kubernetes Web UI
- Enable Object Versioning on Buckets
- Enable Secure Boot on Compute Engine Instances
- Enable SSL Encryption On AlloyDB Instances
cis-controls-3-7
Establish and maintain an overall data classification scheme for the enterprise. Enterprises may use labels, such as “Sensitive,” “Confidential,” and “Public,” and classify their data according to those labels. Review and update the classification scheme annually, or when significant enterprise changes occur that could impact this Safeguard.
- Define Cloud KMS Crypto Keys Protection Level
- Define Cloud KMS Crypto Keys Purpose
- Enforce CMEK for Supported Services
- Verify Cloud KMS Key Version Algorithm
cis-controls-3-8
Document data flows. Data flow documentation includes service provider data flows and should be based on the enterprise’s data management process. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
- Block Generic Access to DNS Ports from All IP Addresses
- Block Generic Access to Elasticsearch Ports from All IP Addresses
- Block Generic Access to FTP Ports
- Block Generic Access to HTTP Ports
- Block Generic Access to LDAP Ports
- Block Generic Access to Memcached Ports
- Block Generic Access to MongoDB Ports
- Block Generic Access to MySQL Ports
- Block Generic Access to NetBIOS Ports from All IP Addresses
- Block Generic Access to Oracle Database Ports
- Block Generic Access to POP3 Server Ports
- Block Generic Access to PostgreSQL Server Ports from All IP Addresses
- Block Generic Access to Redis Server Ports from All IP Addresses
- Block Generic Access to SMTP Server Ports
- Block Generic Access to Telnet Servers
- Block Overly Permissive Firewall Rules
- Configure the Allowed VPC Egress Settings for Cloud Run Organization Policy Constraint
- Enable Control Plane Authorized Networks on GKE Clusters
- Enable IP Alias Range for GKE Clusters
- Enable Private Google Access on an instance
cis-controls-3-9
Encrypt data on removable media.
- Create and Manage Asymmetric Keys
- Enable Encryption on GKE Clusters
- Encrypt Data at Rest with CMEK
- Enforce CMEK
- Restrict Non CMEK Services
cis-controls-4-1
Establish and maintain a documented secure configuration process for enterprise assets (end-user devices, including portable and mobile, non-computing/IoT devices, and servers) and software (operating systems and applications). Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
- Configure Access Controls for the Network Boundary
- Configure the Allowed Ingress Settings for Cloud Run Organization Policy Constraint
- Configure the Disable VM Serial Port Logging to Stackdriver Organization Policy
- Configure the Disable VPC Internal IPv6 Usage Organization Policy
- Create and Manage Asymmetric Keys
- Define a Security Policy to Mitigate for DDoS Events
- Define Cloud KMS Crypto Keys Protection Level
- Define Cloud KMS Crypto Keys Purpose
- Define Retention Period for Cloud Storage Buckets
- Define Storage Class Lifestyle Action
- Don't Use Kubernetes Web UI
- Don't Use User Connections Flag for SQL Server
- Don't Use User Options Flag for SQL Server
- Enable 3625 Trace Database Flag for SQL Server
- Enable Control Plane Authorized Networks on GKE Clusters
- Enable IP Alias Range for GKE Clusters
- Enable Log Checkpoints Flag for PostgreSQL
- Enable Log Duration Flag for PostgreSQL instance
- Enable Log Temp Files Flag for PostgreSQL instance
- Enable OS Login
- Enable Private Google Access on an instance
- Enable Secure Boot on Compute Engine Instances
- Encrypt Data at Rest with CMEK
- Enforce CMEK
- Enforce CMEK for Supported Services
- Ensure Minimum TLS 1.2 Version
- Restrict Legacy TLS Versions
- Terminate Network Connections
- Turn Off Log Executor Stats Flag for PostgreSQL
- Turn off Log Hostname Flag for PostgreSQL
- Turn off Log Statement Stats Flag for PostgreSQL
- Use TLS 1.2 or Higher
- Verify Cloud KMS Key Version Algorithm
cis-controls-4-2
Establish and maintain a documented secure configuration process for network devices. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
- Avoid RSASHA1 for DNSSEC Signing
- Configure the Allowed Ingress Settings for Cloud Run Organization Policy Constraint
- Configure the Disable VM Serial Port Logging to Stackdriver Organization Policy
- Don't Use Legacy Networks
- Enable Control Plane Authorized Networks on GKE Clusters
- Enable DNSSEC for Cloud DNS
- Enable IP Alias Range for GKE Clusters
- Enable Log Checkpoints Flag for PostgreSQL
- Enable Log Duration Flag for PostgreSQL instance
- Enable Log Temp Files Flag for PostgreSQL instance
- Enable Private Google Access on an instance
- Encrypt Data at Rest with CMEK
- Ensure Minimum TLS 1.2 Version
- Restrict Legacy TLS Versions
- Terminate Network Connections
- Turn Off Log Executor Stats Flag for PostgreSQL
- Turn off Log Hostname Flag for PostgreSQL
- Turn off Log Statement Stats Flag for PostgreSQL
- Use Custom VPC Networks
cis-controls-4-3
Configure automatic session locking on enterprise assets after a defined period of inactivity. For general purpose operating systems, the period must not exceed 15 minutes. For mobile end-user devices, the period must not exceed 2 minutes.
cis-controls-4-4
Implement and manage a firewall on servers, where supported. Example implementations include a virtual firewall, operating system firewall, or a third-party firewall agent.
- Block Generic Access to CiscoSecure/WebSM Ports
- Block Generic Access to FTP Ports
- Block Generic Access to HTTP Ports
- Block Generic Access to LDAP Ports
- Block Generic Access to Memcached Ports
- Block Generic Access to MongoDB Ports
- Block Generic Access to MySQL Ports
- Block Generic Access to NetBIOS Ports from All IP Addresses
- Block Generic Access to Oracle Database Ports
- Block Generic Access to POP3 Server Ports
- Block Generic Access to PostgreSQL Server Ports from All IP Addresses
- Block Generic Access to RDP Ports
- Block Generic Access to Redis Server Ports from All IP Addresses
- Block Generic Access to SMTP Server Ports
- Block Generic Access to SSH Ports
- Block Generic Access to Telnet Servers
- Block Legacy Authorization on GKE Clusters
- Block Overly Permissive Firewall Rules
- Disable Alpha Features on GKE Clusters
- Enable Private Google Access for VPC Subnets
- Enable Secure Boot for Shielded GKE Nodes
- Enable Shielded GKE Nodes on a Cluster
- Prevent IP Forwarding on Compute Engine Instances
- Require Container-Optimized OS for a GKE Cluster
cis-controls-4-5
Implement and manage a host-based firewall or port-filtering tool on end-user devices, with a default-deny rule that drops all traffic except those services and ports that are explicitly allowed.
- Block Generic Access to CiscoSecure/WebSM Ports
- Block Generic Access to DNS Ports from All IP Addresses
- Block Generic Access to Elasticsearch Ports from All IP Addresses
- Block Generic Access to FTP Ports
- Block Generic Access to HTTP Ports
- Block Generic Access to LDAP Ports
- Block Generic Access to Memcached Ports
- Block Generic Access to MongoDB Ports
- Block Generic Access to MySQL Ports
- Block Generic Access to NetBIOS Ports from All IP Addresses
- Block Generic Access to Oracle Database Ports
- Block Generic Access to POP3 Server Ports
- Block Generic Access to PostgreSQL Server Ports from All IP Addresses
- Block Generic Access to RDP Ports
- Block Generic Access to Redis Server Ports from All IP Addresses
- Block Generic Access to SMTP Server Ports
- Block Generic Access to SSH Ports
- Block Generic Access to Telnet Servers
- Block Overly Permissive Firewall Rules
- Enforce Deny All Egress Firewall Rule
- Prevent IP Forwarding on Compute Engine Instances
cis-controls-4-6
Securely manage enterprise assets and software. Example implementations include managing configuration through version-controlled Infrastructure-as-Code (IaC) and accessing administrative interfaces over secure network protocols, such as Secure Shell (SSH) and Hypertext Transfer Protocol Secure (HTTPS). Do not use insecure management protocols, such as Telnet (Teletype Network) and HTTP, unless operationally essential.
- Block Public IP Addresses for AlloyDB Cluster Instances
- Block Public IP Addresses for Cloud SQL Instances
- Don't Use Kubernetes Web UI
cis-controls-4-7
Manage default accounts on enterprise assets and software, such as root, administrator, and other pre-configured vendor accounts. Example implementations can include: disabling default accounts or making them unusable.
- Restrict API Access to Google Cloud APIs for Compute Engine Instances
- Use Custom Service Accounts for Compute Engine Instances
cis-controls-4-8
Uninstall or disable unnecessary services on enterprise assets and software, such as an unused file sharing service, web application module, or service function.
- Block Serial Ports for Compute Engine Instances
- Configure Access Controls for the Network Boundary
- Configure the Disable VPC Internal IPv6 Usage Organization Policy
- Disable Legacy Metadata Server Endpoints on Compute Engine
- Set Application Restriction on API Keys
- Turn Off Remote Access Flag for SQL Server
cis-controls-5-1
Establish and maintain an inventory of all accounts managed in the enterprise. The inventory must at a minimum include user, administrator, and service accounts. The inventory, at a minimum, should contain the person’s name, username, start/stop dates, and department. Validate that all active accounts are authorized, on a recurring schedule at a minimum quarterly, or more frequently.
- Block External IP Address Access on Compute Engine VM Instances
- Create GKE Clusters with Limited Privileges
- Define VPC Connector Egress For Cloud Run Functions
- Enable Artifact Analysis Vulnerability Scanning
- Enable OS Login
- Enable Private Google Access for VPC Subnets
cis-controls-5-2
Use unique passwords for all enterprise assets. Best practice implementation includes, at a minimum, an 8-character password for accounts using Multi-Factor Authentication (MFA) and a 14-character password for accounts not using MFA.
- Block Project-Wide SSH Keys on Compute Engine Instances
- Don't Use Kubernetes Web UI
- Enable Private Google Access for VPC Subnets
cis-controls-5-4
Restrict administrator privileges to dedicated administrator accounts on enterprise assets. Conduct general computing activities, such as internet browsing, email, and productivity suite use, from the user’s primary, non-privileged account.
- Block Automatic IAM Grants to Default Service Accounts
- Use Least Privilege Service Accounts for GKE Clusters
cis-controls-5-5
Establish and maintain an inventory of service accounts. The inventory, at a minimum, must contain department owner, review date, and purpose. Perform service account reviews to validate that all active accounts are authorized, on a recurring schedule at a minimum quarterly, or more frequently.
- Block External IP Address Access on Compute Engine VM Instances
- Configure Remote Access Inactivity Timeout
- Enable Workload Identity Federation for GKE on clusters
cis-controls-5-6
Centralize account management through a directory or identity service.
- Don't Use Kubernetes Web UI
- Enable OS Login for All Instances at Project Level
- Require OS Login on Compute Engine Instances
cis-controls-6-1
Establish and follow a documented process, preferably automated, for granting access to enterprise assets upon new hire or role change of a user.
- Block Generic Access to Directory Service Ports
- Block Legacy Authorization on GKE Clusters
- Configure Access Controls for the Network Boundary
- Enable Private Google Access for VPC Subnets
- Enable the Confidential VM Organization Policy Constraint
- Enable Workload Identity Federation for GKE on clusters
- Restrict Default Network Creation for Compute Engine Instances
cis-controls-6-2
Establish and follow a process, preferably automated, for revoking access to enterprise assets, through disabling accounts immediately upon termination, rights revocation, or role change of a user. Disabling accounts, instead of deleting accounts, may be necessary to preserve audit trails.
- Disable File Downloads on Agent Platform Workbench Instances
- Enable Private Google Access for VPC Subnets
- Enable the Confidential VM Organization Policy Constraint
- Restrict Default Network Creation for Compute Engine Instances
cis-controls-6-3
Require all externally-exposed enterprise or third-party applications to enforce MFA, where supported. Enforcing MFA through a directory service or SSO provider is a satisfactory implementation of this Safeguard.
- Set Log Min Error Statement Flag for AlloyDB Instances
- Set Log Min Messages Flag for AlloyDB Instances
cis-controls-6-5
Require MFA for all administrative access accounts, where supported, on all enterprise assets, whether managed on-site or through a service provider.
- Create GKE Clusters with Limited Privileges
- Set Log Min Error Statement Flag for AlloyDB Instances
- Set Log Min Messages Flag for AlloyDB Instances
cis-controls-6-6
Establish and maintain an inventory of the enterprise’s authentication and authorization systems, including those hosted on-site or at a remote service provider. Review and update the inventory, at a minimum, annually, or more frequently.
- Enable Cloud Asset Inventory Service
- Enable Private Google Access for VPC Subnets
- Enable the Confidential VM Organization Policy Constraint
- Restrict Default Network Creation for Compute Engine Instances
cis-controls-6-7
Centralize access control for all enterprise assets through a directory service or SSO provider, where supported.
- Configure Access Controls for the Network Boundary
- Enable OS Login for All Instances at Project Level
- Ensure Minimum TLS 1.2 Version
- Require OS Login on Compute Engine Instances
- Set Application Restriction on API Keys
cis-controls-6-8
Define and maintain role-based access control, through determining and documenting the access rights necessary for each role within the enterprise to successfully carry out its assigned duties. Perform access control reviews of enterprise assets to validate that all privileges are authorized, on a recurring schedule at a minimum annually, or more frequently.
- Block Automatic IAM Grants to Default Service Accounts
- Configure the Allowed VPC Egress Settings for Cloud Run Organization Policy Constraint
- Create GKE Clusters with Limited Privileges
- Set Application Restriction on API Keys
- Use Least Privilege Service Accounts for GKE Clusters
cis-controls-7-2
Establish and maintain a risk-based remediation strategy documented in a remediation process, with monthly, or more frequent, reviews.
cis-controls-7-7
Remediate detected vulnerabilities in software through processes and tooling on a monthly, or more frequent, basis, based on the remediation process.
- Disable Legacy Metadata Server Endpoints on Compute Engine
- Use Latest Image Versions on Dataproc Clusters
cis-controls-8-1
Establish and maintain a documented audit log management process that defines the enterprise’s logging requirements. At a minimum, address the collection, review, and retention of audit logs for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
- Allocate Audit Log Storage Capacity
- Block Automatic IAM Grants to Default Service Accounts
- Block Service Account Key Creation
- Block Service Account Key Uploads
- Enable Audit Logs for Google Cloud Services
- Enable Firewall Rule Logging
- Enable Log Checkpoints Flag for PostgreSQL
- Enable Log Duration Flag for PostgreSQL instance
- Require Cloud Storage Bucket Logging
- Require Object Versioning for Cloud Storage Buckets
- Retain Audit Records
- Set Log Error Verbosity Flag for AlloyDB Instances
- Set Log Min Error Statement Flag for AlloyDB Instances
- Set Log Min Messages Flag for AlloyDB Instances
- Turn Off Log Executor Stats Flag for PostgreSQL
- Turn off Log Hostname Flag for PostgreSQL
cis-controls-8-11
Conduct reviews of audit logs to detect anomalies or abnormal events that could indicate a potential threat. Conduct reviews on a weekly, or more frequent, basis.
- Configure Security Logging Policies for Google Cloud Services
- Enable Cloud DNS Logs Monitoring
- Enable Log Temp Files Flag for PostgreSQL instance
- Implement Event Logging for Google Cloud Services
- Set Log Error Verbosity Flag for AlloyDB Instances
- Set Log Min Error Statement Flag for AlloyDB Instances
- Set Log Min Messages Flag for AlloyDB Instances
- Turn Off Log Executor Stats Flag for PostgreSQL
- Turn off Log Parser Stats Flag for PostgreSQL
- Turn off Log Planner Stats Flag for PostgreSQL
- Turn off Log Statement Stats Flag for PostgreSQL
cis-controls-8-2
Collect audit logs. Ensure that logging, per the enterprise’s audit log management process, has been enabled across enterprise assets.
- Allocate Audit Log Storage Capacity
- Configure Security Logging Policies for Google Cloud Services
- Don't Use Kubernetes Web UI
- Enable Audit Logs for Google Cloud Services
- Enable Cloud Logging on GKE Clusters
- Enable Firewall Rule Logging
- Enable Load Balancer Logging
- Enable Log Locks Wait Flag for PostgreSQL instance
- Implement Event Logging for Google Cloud Services
- Turn off Log Parser Stats Flag for PostgreSQL
cis-controls-8-3
Ensure that logging destinations maintain adequate storage to comply with the enterprise’s audit log management process.
cis-controls-8-4
Standardize time synchronization. Configure at least two synchronized time sources across enterprise assets, where supported.
- Block Automatic IAM Grants to Default Service Accounts
- Define Cloud KMS Crypto Keys Purpose
- Don't Use Kubernetes Web UI
- Set Uniform Bucket Level Access for Cloud Storage Buckets
cis-controls-8-5
Configure detailed audit logging for enterprise assets containing sensitive data. Include event source, date, username, timestamp, source addresses, destination addresses, and other useful elements that could assist in a forensic investigation.
- Allocate Audit Log Storage Capacity
- Block Service Account Key Creation
- Block Service Account Key Uploads
- Configure Security Logging Policies for Google Cloud Services
- Enable Audit Logs for Google Cloud Services
- Enable Log Checkpoints Flag for PostgreSQL
- Enable Log Connections Flag for PostgreSQL
- Enable Log Disconnections Flag for PostgreSQL
- Enable Log Error Verbosity Flag for PostgreSQL
- Enable Log Min Error Statement Flag for PostgreSQL
- Enable Log Min Messages Flag for PostgreSQL
- Enable Log Statement Flag for PostgreSQL
- Enforce Compute Session Inactive Policy
- Require Cloud Storage Bucket Logging
- Set Log Error Verbosity Flag for AlloyDB Instances
- Turn Off Log Executor Stats Flag for PostgreSQL
- Turn Off Log Min Duration Statement Flag for PostgreSQL
cis-controls-8-6
Collect DNS query audit logs on enterprise assets, where appropriate and supported.
- Enable Cloud DNS Logs Monitoring
- Enable Integrity Monitoring on GKE Clusters
- Enforce Public Access Prevention
- Ensure Minimum TLS 1.2 Version
- Implement Continuous Network Traffic Monitoring
cis-controls-8-7
Collect URL request audit logs on enterprise assets, where appropriate and supported.
- Block Service Account Key Creation
- Block Service Account Key Uploads
- Define Secret Manager Rotation Schedule
- Restrict Legacy TLS Versions
cis-controls-8-8
Collect command-line audit logs. Example implementations include collecting audit logs from PowerShell®, BASH™, and remote administrative terminals.
- Enable Log Temp Files Flag for PostgreSQL instance
- Set Log Error Verbosity Flag for AlloyDB Instances
- Set Log Min Error Statement Flag for AlloyDB Instances
- Set Log Min Messages Flag for AlloyDB Instances
- Turn Off Log Executor Stats Flag for PostgreSQL
- Turn off Log Parser Stats Flag for PostgreSQL
- Turn off Log Planner Stats Flag for PostgreSQL
- Turn off Log Statement Stats Flag for PostgreSQL
cis-controls-8-9
Centralize, to the extent possible, audit log collection and retention across enterprise assets in accordance with the documented audit log management process. Example implementations primarily include leveraging a SIEM tool to centralize multiple log sources.
- Configure Security Logging Policies for Google Cloud Services
- Enable Audit Logs for Google Cloud Services
- Enable Log Checkpoints Flag for PostgreSQL
- Enable Log Duration Flag for PostgreSQL instance
- Require Cloud Storage Bucket Logging
- Require Object Versioning for Cloud Storage Buckets
- Set Log Error Verbosity Flag for AlloyDB Instances
- Turn Off Log Executor Stats Flag for PostgreSQL
- Turn off Log Hostname Flag for PostgreSQL
cis-controls-9-1
Ensure only fully supported browsers and email clients are allowed to execute in the enterprise, only using the latest version of browsers and email clients provided through the vendor.
cis-controls-9-2
Use DNS filtering services on all end-user devices, including remote and on-premises assets, to block access to known malicious domains.
- Block External IP Address Access on Compute Engine VM Instances
- Create and Manage Asymmetric Keys
- Define VPC Connector Egress For Cloud Run Functions
cis-controls-9-3
Enforce and update network-based URL filters to limit an enterprise asset from connecting to potentially malicious or unapproved websites. Example implementations include category-based filtering, reputation-based filtering, or through the use of block lists. Enforce filters for all enterprise assets.
cis-controls-9-4
Restrict, either through uninstalling or disabling, any unauthorized or unnecessary browser or email client plugins, extensions, and add-on applications.
CSA Cloud Controls Matrix v4.0.11
Supported cloud provider: Google Cloud
A cybersecurity control framework designed specifically for the cloud computing environment. It provides a comprehensive set of controls across key domains to help you assess the security posture of your cloud services.
This framework includes the cloud control groups and cloud controls in the following sections.
ccm-aa-01
Establish, document, approve, communicate, apply, evaluate and maintain audit and assurance policies and procedures and standards. Review and update the policies and procedures at least annually.
- Enable Log Duration Flag for PostgreSQL instance
- Enable Object Versioning on Buckets
- Enable Subnet Flow Logs
- Enable VPC Flow Logs for Compute Engine Instances
ccm-aa-02
Conduct independent audit and assurance assessments according to relevant standards at least annually.
- Allocate Audit Log Storage Capacity
- Create and Manage Asymmetric Keys
- Disable Alpha Features on GKE Clusters
- Enable Cloud Monitoring on GKE Clusters
- Ensure Minimum TLS 1.2 Version
- Terminate Network Connections
ccm-ais-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for application security to provide guidance to the appropriate planning, delivery and support of the organization's application security capabilities. Review and update the policies and procedures at least annually.
ccm-ais-02
Establish, document and maintain baseline requirements for securing different applications.
- Enable Artifact Analysis Vulnerability Scanning
- Enable CMEK for Cloud SQL Databases
- Turn off Log Parser Stats Flag for PostgreSQL
- Turn off Log Planner Stats Flag for PostgreSQL
ccm-ais-03
Define and implement technical and operational metrics in alignment with business objectives, security requirements, and compliance obligations.
ccm-ais-04
Define and implement a SDLC process for application design, development, deployment, and operation in accordance with security requirements defined by the organization.
- Enable CMEK on Compute Engine Persistent Disks
- Require Container-Optimized OS for a GKE Cluster
- Set Application Restriction on API Keys
ccm-ais-05
Implement a testing strategy, including criteria for acceptance of new information systems, upgrades and new versions, which provides application security assurance and maintains compliance while enabling organizational speed of delivery goals. Automate when applicable and possible.
- Define VPC Connector Egress For Cloud Run Functions
- Restrict Insecure SSL Policies for Compute Engine Instances
ccm-bcr-03
Establish strategies to reduce the impact of, withstand, and recover from business disruptions within risk appetite.
ccm-bcr-07
Establish communication with stakeholders and participants in the course of business continuity and resilience procedures.
ccm-bcr-08
Periodically backup data stored in the cloud. Ensure the confidentiality, integrity and availability of the backup, and verify data restoration from backup for resiliency.
ccm-bcr-09
Establish, document, approve, communicate, apply, evaluate and maintain a disaster response plan to recover from natural and man-made disasters. Update the plan at least annually or upon significant changes.
ccm-bcr-10
Exercise the disaster response plan annually or upon significant changes, including if possible local emergency authorities.
ccm-bcr-11
Supplement business-critical equipment with redundant equipment independently located at a reasonable minimum distance in accordance with applicable industry standards.
ccm-ccc-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for managing the risks associated with applying changes to organization assets, including application, systems, infrastructure, configuration, etc. The policies and procedures must be managed, regardless of whether the assets are managed internally or externally. Review and update the policies and procedures at least annually.
- Block Automatic IAM Grants to Default Service Accounts
- Don't Use User Connections Flag for SQL Server
- Don't Use User Options Flag for SQL Server
- Enable 3625 Trace Database Flag for SQL Server
- Enable OS Login
- Enable Shielded GKE Nodes on a Cluster
- Restrict Service Usage
ccm-ccc-02
Follow a defined quality change control, approval and testing process with established baselines, testing, and release standards.
ccm-ccc-07
Implement detection measures with proactive notification in case of changes deviating from the established baseline.
ccm-cek-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for Cryptography, Encryption and Key Management. Review and update the policies and procedures at least annually.
- Enable CMEK for Cloud SQL Databases
- Enable CMEK for Cloud Storage Buckets
- Enable SSL Encryption On AlloyDB Instances
- Encrypt Pub/Sub topic with CMEK
ccm-cek-02
Define and implement cryptographic, encryption and key management roles and responsibilities.
ccm-cek-03
Provide cryptographic protection to data at-rest and in-transit, using cryptographic libraries certified to approved standards.
- Block Project-Wide SSH Keys on Compute Engine Instances
- Enable CMEK for AlloyDB Clusters
- Enable CMEK for BigQuery Datasets
- Enable CMEK for BigQuery Tables
- Enable CSEK On Compute Engine Persistent Disks
- Enable SSL Encryption On AlloyDB Instances
- Require CMEK on Dataproc Clusters
- Restrict Non CMEK Services
- Use Least Privilege Service Accounts for GKE Clusters
ccm-cek-04
Use encryption algorithms that are appropriate for data protection, considering the classification of data, associated risks, and usability of the encryption technology.
ccm-cek-05
Establish a standard change management procedure, to accommodate changes from internal and external sources, for review, approval, implementation and communication of cryptographic, encryption and key management technology changes.
ccm-cek-08
CSPs must provide the capability for CSCs to manage their own data encryption keys.
ccm-cek-10
Generate Cryptographic keys using industry accepted cryptographic libraries specifying the algorithm strength and the random number generator used.
- Enable CMEK for Cloud SQL Databases
- Encrypt Pub/Sub topic with CMEK
- Restrict Insecure SSL Policies for Compute Engine Instances
ccm-cek-11
Manage cryptographic secret and private keys that are provisioned for a unique purpose.
ccm-cek-18
Define, implement and evaluate processes, procedures and technical measures to manage archived keys in a secure repository requiring least privilege access, which include provisions for legal and regulatory requirements.
ccm-cek-21
Define, implement and evaluate processes, procedures and technical measures in order for the key management system to track and report all cryptographic materials and changes in status, which include provisions for legal and regulatory requirements.
ccm-dcs-07
Implement physical security perimeters to safeguard personnel, data, and information systems. Establish physical security perimeters between the administrative and business areas and the data storage and processing facilities areas.
- Enable Secure Boot for Shielded GKE Nodes
- Enforce Deny All Egress Firewall Rule
- Subscribe a GKE Cluster to a Release Channel
ccm-dcs-09
Allow only authorized personnel access to secure areas, with all ingress and egress points restricted, documented, and monitored by physical access control mechanisms. Retain access control records on a periodic basis as deemed appropriate by the organization.
ccm-dsp-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the classification, protection and handling of data throughout its lifecycle, and according to all applicable laws and regulations, standards, and risk level. Review and update the policies and procedures at least annually.
ccm-dsp-02
Apply industry accepted methods for the secure disposal of data from storage media such that data is not recoverable by any forensic means.
ccm-dsp-07
Develop systems, products, and business practices based upon a principle of security by design and industry best practices.
- Define Retention Period for Cloud Storage Buckets
- Require Rotation of API Key
- Restrict API Keys for Required APIs Only
ccm-dsp-08
Develop systems, products, and business practices based upon a principle of privacy by design and industry best practices. Ensure that systems' privacy settings are configured by default, according to all applicable laws and regulations.
ccm-dsp-10
Define, implement and evaluate processes, procedures and technical measures that ensure any transfer of personal or sensitive data is protected from unauthorized access and only processed within scope as permitted by the respective laws and regulations.
- Create and Manage Asymmetric Keys
- Encrypt Data at Rest with CMEK
- Enforce CMEK
- Lock Storage Bucket Retention Policies
ccm-dsp-16
Data retention, archiving and deletion is managed in accordance with business requirements, applicable laws and regulations.
ccm-dsp-17
Define and implement, processes, procedures and technical measures to protect sensitive data throughout its lifecycle.
- Block Public IP Addresses for AlloyDB Cluster Instances
- Enable Log Connections Flag for PostgreSQL
- Enable Log Disconnections Flag for PostgreSQL
- Enable Log Error Verbosity Flag for PostgreSQL
- Enable Log Min Error Statement Flag for PostgreSQL
- Enable Log Min Messages Flag for PostgreSQL
- Enable Log Statement Flag for PostgreSQL
- Enable Skip Show Database Flag for MySQL
- Enable Uniform Bucket-Level Access on Cloud Storage Buckets
- Restrict Non CMEK Services
- Restrict Public IP Addresses to Compute Engine Instances
- Set Log Error Verbosity Flag for AlloyDB Instances
- Set Log Min Error Statement Flag for AlloyDB Instances
- Set Log Min Messages Flag for AlloyDB Instances
- Turn Off Contained Database Authentication Flag for SQL Server
- Turn Off Cross Database Ownership Chaining Flag for SQL Server
- Turn Off Log Min Duration Statement Flag for PostgreSQL
- Use Least Privilege Service Accounts for GKE Clusters
ccm-grc-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for an information governance program, which is sponsored by the leadership of the organization. Review and update the policies and procedures at least annually.
ccm-grc-03
Review all relevant organizational policies and associated procedures at least annually or when a substantial change occurs within the organization.
ccm-grc-07
Identify and document all relevant standards, regulations, legal, contractual, and statutory requirements, which are applicable to your organization.
ccm-iam-01
Establish, document, approve, communicate, implement, apply, evaluate and maintain policies and procedures for identity and access management. Review and update the policies and procedures at least annually.
- Block External IP Address Access on Compute Engine VM Instances
- Don't Use Kubernetes Web UI
- Enable CMEK for Cloud SQL Databases
- Enable OS Login for All Instances at Project Level
- Enable Private Clusters for GKE
- Enable Private Google Access for VPC Subnets
- Restrict Default Network Creation for Compute Engine Instances
- Restrict Legacy TLS Versions
ccm-iam-03
Manage, store, and review the information of system identities, and level of access.
- Block Automatic IAM Grants to Default Service Accounts
- Enable OS Login for All Instances at Project Level
ccm-iam-04
Employ the separation of duties principle when implementing information system access.
- Enable Cloud Logging on GKE Clusters
- Enable Private Clusters for GKE
- Restrict Public Access to Cloud Storage Buckets
ccm-iam-05
Employ the least privilege principle when implementing information system access.
- Block External IP Address Access on Compute Engine VM Instances
- Configure the Allowed VPC Egress Settings for Cloud Run Organization Policy Constraint
- Create GKE Clusters with Limited Privileges
- Define Cloud KMS Crypto Keys Purpose
- Don't Use Kubernetes Web UI
- Enable Private Clusters for GKE
- Enforce Deny All Egress Firewall Rule
- Enforce SSL for all Incoming Database Connections
- Restrict Public Access to BigQuery Datasets
- Restrict Public Access to Cloud SQL Database Instances
- Restrict Public Access to Cloud Storage Buckets
- Set Application Restriction on API Keys
- Subscribe a GKE Cluster to a Release Channel
ccm-iam-07
De-provision or respectively modify access of movers, leavers, or system identity changes in a timely manner in order to effectively adopt and communicate identity and access management policies.
- Block Service Account Key Creation
- Block Service Account Key Uploads
- Define Secret Manager Rotation Schedule
ccm-iam-09
Define, implement and evaluate processes, procedures and technical measures for the segregation of privileged access roles such that administrative access to data, encryption and key management capabilities and logging capabilities are distinct and separated.
- Block Automatic IAM Grants to Default Service Accounts
- Configure Remote Access Inactivity Timeout
- Don't Use Kubernetes Web UI
- Enable Secure Boot on Compute Engine Instances
- Enable SSL Encryption On AlloyDB Instances
- Set Application Restriction on API Keys
ccm-iam-10
Define and implement an access process to ensure privileged access roles and rights are granted for a time limited period, and implement procedures to prevent the culmination of segregated privileged access.
- Block Service Account Key Creation
- Block Service Account Key Uploads
- Configure Remote Access Inactivity Timeout
- Create GKE Clusters with Limited Privileges
- Restrict Public Access to BigQuery Datasets
ccm-iam-11
Define, implement and evaluate processes and procedures for customers to participate, where applicable, in the granting of access for agreed, high risk privileged access roles as defined by the organizational risk assessment.
ccm-iam-12
Define, implement and evaluate processes, procedures and technical measures to ensure the logging infrastructure is read-only for all with write access, including privileged access roles, and that the ability to disable it is controlled through a procedure that ensures the segregation of duties and break glass procedures.
- Block Generic Access to Cassandra Ports
- Block Public IP Addresses for Cloud SQL Instances
- Configure the Allowed Ingress Settings for Cloud Run Organization Policy Constraint
- Configure the Disable VM Serial Port Logging to Stackdriver Organization Policy
- Configure the Disable VPC External IPv6 Usage Organization Policy
- Enable Control Plane Authorized Networks on GKE Clusters
- Enable IP Alias Range for GKE Clusters
- Enable OS Login
- Enable Private Google Access on an instance
- Enable the Restrict Authorized Networks on Cloud SQL Instances Organization Policy Constraint
- Restrict Public Access to BigQuery Datasets
- Restrict Public Access to Cloud SQL Database Instances
- Restrict Public Access to Cloud Storage Buckets
ccm-iam-13
Define, implement and evaluate processes, procedures and technical measures that ensure users are identifiable through unique IDs or which can associate individuals to the usage of user IDs.
ccm-iam-14
Define, implement and evaluate processes, procedures and technical measures for authenticating access to systems, application and data assets, including multifactor authentication for at least privileged user and sensitive data access. Adopt digital certificates or alternatives which achieve an equivalent level of security for system identities.
ccm-iam-16
Define, implement and evaluate processes, procedures and technical measures to verify access to data and system functions is authorized.
- Enable OS Login
- Enforce SSL for all Incoming Database Connections
- Set Application Restriction on API Keys
ccm-ivs-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for infrastructure and virtualization security. Review and update the policies and procedures at least annually.
- Define a Security Policy to Mitigate for DDoS Events
- Enable Auto Upgrade on GKE Clusters
- Enable Intranode Visibility for GKE Clusters
- Terminate Network Connections
ccm-ivs-03
Monitor, encrypt and restrict communications between environments to only authenticated and authorized connections, as justified by the business. Review these configurations at least annually, and support them by a documented justification of all allowed services, protocols, ports, and compensating controls.
- Block Generic Access to DNS Ports from All IP Addresses
- Block Generic Access to Elasticsearch Ports from All IP Addresses
- Block Generic Access to FTP Ports
- Block Generic Access to HTTP Ports
- Block Generic Access to LDAP Ports
- Block Generic Access to Memcached Ports
- Block Generic Access to MongoDB Ports
- Block Generic Access to MySQL Ports
- Block Generic Access to NetBIOS Ports from All IP Addresses
- Block Generic Access to Oracle Database Ports
- Block Generic Access to POP3 Server Ports
- Block Generic Access to PostgreSQL Server Ports from All IP Addresses
- Block Generic Access to Redis Server Ports from All IP Addresses
- Block Generic Access to SMTP Server Ports
- Block Generic Access to Telnet Servers
- Block Legacy Authorization on GKE Clusters
- Block Overly Permissive Firewall Rules
- Block Public IP Addresses for Cloud SQL Instances
- Configure the Allowed Ingress Settings for Cloud Run Organization Policy Constraint
- Configure the Allowed VPC Egress Settings for Cloud Run Organization Policy Constraint
- Configure the Disable VPC External IPv6 Usage Organization Policy
- Configure the Disable VPC Internal IPv6 Usage Organization Policy
- Define a Security Policy to Mitigate for DDoS Events
- Enable Control Plane Authorized Networks on GKE Clusters
- Enable IP Alias Range for GKE Clusters
- Enable Private Google Access on an instance
- Enable Secure Boot for Shielded GKE Nodes
- Enforce Deny All Egress Firewall Rule
- Ensure Minimum TLS 1.2 Version
- Implement Continuous Network Traffic Monitoring
- Restrict Public Access to Cloud SQL Database Instances
- Subscribe a GKE Cluster to a Release Channel
- Terminate Network Connections
ccm-ivs-04
Harden host and guest OS, hypervisor or infrastructure control plane according to their respective best practices, and supported by technical controls, as part of a security baseline.
- Avoid RSASHA1 for DNSSEC Signing
- Configure the Disable VM Serial Port Logging to Stackdriver Organization Policy
- Disable Legacy Metadata Server Endpoints on Compute Engine
- Don't Use Legacy Networks
- Enable Control Plane Authorized Networks on GKE Clusters
- Enable Integrity Monitoring on GKE Clusters
- Enable IP Alias Range for GKE Clusters
- Enable Log Checkpoints Flag for PostgreSQL
- Enable Log Duration Flag for PostgreSQL instance
- Enable Log Locks Wait Flag for PostgreSQL instance
- Enable Log Temp Files Flag for PostgreSQL instance
- Enable Private Google Access on an instance
- Enable Workload Identity Federation for GKE on clusters
- Turn Off Log Executor Stats Flag for PostgreSQL
- Turn off Log Hostname Flag for PostgreSQL
- Turn off Log Statement Stats Flag for PostgreSQL
- Use Custom VPC Networks
ccm-ivs-06
Design, develop, deploy and configure applications and infrastructures such that CSP and CSC (tenant) user access and intra-tenant access is appropriately segmented and segregated, monitored and restricted from other tenants.
- Block Generic Access to Cassandra Ports
- Block Legacy Authorization on GKE Clusters
- Configure Access Controls for the Network Boundary
- Enable Secure Boot for Shielded GKE Nodes
ccm-ivs-07
Use secure and encrypted communication channels when migrating servers, services, applications, or data to cloud environments. Such channels must include only up-to-date and approved protocols.
- Configure Access Controls for the Network Boundary
- Define a Security Policy to Mitigate for DDoS Events
ccm-ivs-09
Define, implement and evaluate processes, procedures and defense-in-depth techniques for protection, detection, and timely response to network-based attacks.
ccm-log-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for logging and monitoring. Review and update the policies and procedures at least annually.
- Allocate Audit Log Storage Capacity
- Configure Security Logging Policies for Google Cloud Services
- Don't Use Kubernetes Web UI
- Enable Audit Logs for Google Cloud Services
- Enable Firewall Rule Logging
- Retain Audit Records
ccm-log-02
Define, implement and evaluate processes, procedures and technical measures to ensure the security and retention of audit logs.
- Configure Security Logging Policies for Google Cloud Services
- Disable Alpha Features on GKE Clusters
- Enable Cloud Monitoring on GKE Clusters
- Enable Firewall Rule Logging
- Enable Log Checkpoints Flag for PostgreSQL
- Enable Log Duration Flag for PostgreSQL instance
- Enable Log Locks Wait Flag for PostgreSQL instance
- Enable Network Policy on GKE Clusters
- Require Cloud Storage Bucket Logging
- Require Object Versioning for Cloud Storage Buckets
- Retain Audit Records
- Turn Off Log Executor Stats Flag for PostgreSQL
- Turn off Log Hostname Flag for PostgreSQL
ccm-log-03
Identify and monitor security-related events within applications and the underlying infrastructure. Define and implement a system to generate alerts to responsible stakeholders based on such events and corresponding metrics.
- Allocate Audit Log Storage Capacity
- Configure Security Logging Policies for Google Cloud Services
- Enable Audit Logs for Google Cloud Services
- Enable Firewall Rule Logging
- Enable Log Checkpoints Flag for PostgreSQL
- Enforce Compute Session Inactive Policy
- Require Cloud Storage Bucket Logging
- Turn Off Log Executor Stats Flag for PostgreSQL
ccm-log-04
Restrict audit logs access to authorized personnel and maintain records that provide unique access accountability.
- Disable Alpha Features on GKE Clusters
- Enable Auto Repair for GKE Clusters
- Enable Cloud Monitoring on GKE Clusters
- Enable Log Temp Files Flag for PostgreSQL instance
- Enable Network Policy on GKE Clusters
ccm-log-05
Monitor security audit logs to detect activity outside of typical or expected patterns. Establish and follow a defined process to review and take appropriate and timely actions on detected anomalies.
- Don't Use Kubernetes Web UI
- Enable Cloud DNS Logs Monitoring
- Enable Firewall Rule Logging
- Enable Log Temp Files Flag for PostgreSQL instance
- Implement Continuous Network Traffic Monitoring
- Implement Event Logging for Google Cloud Services
- Turn Off Log Executor Stats Flag for PostgreSQL
- Turn off Log Parser Stats Flag for PostgreSQL
- Turn off Log Planner Stats Flag for PostgreSQL
- Turn off Log Statement Stats Flag for PostgreSQL
ccm-log-07
Establish, document and implement which information metadata and data system events should be logged. Review and update the scope at least annually or whenever there is a change in the threat environment.
- Allocate Audit Log Storage Capacity
- Configure Security Logging Policies for Google Cloud Services
- Enable Audit Logs for Google Cloud Services
- Retain Audit Records
ccm-log-08
Generate audit records containing relevant security information.
- Allocate Audit Log Storage Capacity
- Enable Load Balancer Logging
- Turn off Log Parser Stats Flag for PostgreSQL
ccm-log-12
Monitor and log physical access using an auditable access control system.
ccm-sef-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for Security Incident Management, E-Discovery, and Cloud Forensics. Review and update the policies and procedures at least annually.
ccm-sef-02
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the timely management of security incidents. Review and update the policies and procedures at least annually.
ccm-sef-08
Maintain points of contact for applicable regulation authorities, national and local law enforcement, and other legal jurisdictional authorities.
ccm-sta-04
Delineate the shared ownership and applicability of all CSA CCM controls according to the SSRM for the cloud service offering.
ccm-sta-08
CSPs periodically review risk factors associated with all organizations within their supply chain.
ccm-sta-09
Service agreements between CSPs and CSCs (tenants) must incorporate at least the mutually-agreed upon provisions and terms that include Scope, characteristics and location of business relationship and services offered, Information security requirements (including SSRM), Change management process, Logging and monitoring capability, Incident management and communication procedures, Right to audit and third party assessment, Service termination, Interoperability and portability requirements, and Data privacy.
ccm-tvm-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures to identify, report and prioritize the remediation of vulnerabilities, in order to protect systems against vulnerability exploitation. Review and update the policies and procedures at least annually.
- Define a Security Policy to Mitigate for DDoS Events
- Disable Legacy Metadata Server Endpoints on Compute Engine
- Require Container-Optimized OS for a GKE Cluster
ccm-tvm-02
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures to protect against malware on managed assets. Review and update the policies and procedures at least annually.
- Enable Auto Repair for GKE Clusters
- Enable Auto Upgrade on GKE Clusters
- Enable Cloud Logging on GKE Clusters
- Enable CMEK on GKE Node Pool Boot Disks
- Enable Encryption on GKE Clusters
- Enable Intranode Visibility for GKE Clusters
- Enable Shielded GKE Nodes on a Cluster
- Enable Workload Identity Federation for GKE on clusters
ccm-tvm-03
Define, implement and evaluate processes, procedures and technical measures to enable both scheduled and emergency responses to vulnerability identifications, based on the identified risk.
ccm-tvm-06
Define, implement and evaluate processes, procedures and technical measures for the periodic performance of penetration testing by independent third parties.
- Configure the Allowed Ingress Settings for Cloud Run Organization Policy Constraint
- Enable the Restrict Authorized Networks on Cloud SQL Instances Organization Policy Constraint
- Use Latest Image Versions on Dataproc Clusters
ccm-uem-04
Maintain an inventory of all endpoints used to store and access company data.
ccm-uem-07
Manage changes to endpoint operating systems, patch levels, and applications through the company's change management processes.
- Enable CMEK on GKE Node Pool Boot Disks
- Enable Encryption on GKE Clusters
- Enable Integrity Monitoring on GKE Clusters
- Enable Workload Identity Federation for GKE on clusters
ccm-uem-10
Configure managed endpoints with properly configured software firewalls.
- Block Generic Access to CiscoSecure/WebSM Ports
- Block Generic Access to Directory Service Ports
- Block Generic Access to FTP Ports
- Block Generic Access to HTTP Ports
- Block Generic Access to LDAP Ports
- Block Generic Access to Memcached Ports
- Block Generic Access to MongoDB Ports
- Block Generic Access to MySQL Ports
- Block Generic Access to NetBIOS Ports from All IP Addresses
- Block Generic Access to Oracle Database Ports
- Block Generic Access to POP3 Server Ports
- Block Generic Access to PostgreSQL Server Ports from All IP Addresses
- Block Generic Access to Redis Server Ports from All IP Addresses
- Block Generic Access to SMTP Server Ports
- Block Generic Access to Telnet Servers
- Block Overly Permissive Firewall Rules
ccm-uem-11
Configure managed endpoints with Data Loss Prevention (DLP) technologies and rules in accordance with a risk assessment.
DBG CSA CCM
Supported cloud provider: Google Cloud
DBG CSA CCM
This framework includes the cloud control groups and cloud controls in the following sections.
csa-ccm-bcr-08-3
The BCR-08.3 monitors configuration of standard Backup agents for three GCP services running in the current project:
- Backup Agent for GKE is enabled for all GKE clusters;
- Backup configuration is enabled for Cloud SQL instances;
- Continuous backup is enabled for AlloyDB instances;
The controls is violated if any of the required Backup configurations is not enabled.
csa-ccm-bcr-11-2
The BCR-11.2 monitors effective value of the Organization Policy gcp.resourceLocations.
The control is violated if the Organization Policy is not set or is not restricting location of new resources to the regions:
- europe-west3 (Frankfurt)
- europe-west6 (Milan)
- europe-west8 (Zurich)
csa-ccm-bcr-11-4
The BCR-11.4 monitors geographical location of Google Cloud resources, supporting regionalization.
Complaint Google Cloud resources should be launched in any of these regions:
- europe-west3 (Frankfurt)
- europe-west6 (Milan)
- europe-west8 (Zurich)
The control is violated if any other location is used. This includes EU multi-region.
- GCP Foundation Landing Zone Constraints Regions To Europe
- GCP Foundation Resources Not Running Outside Europe
csa-ccm-ccc-05-1
Check shared responsibility documentation in change procedures
csa-ccm-ccc-06
CCC-06 monitors that every Google Cloud project enables only those GCP services that have been tested and approved for usage.
csa-ccm-cek-02-5
Newly created data storage services must use CMEK, located in a specific dedicated project. This project ID must be enforced with Organization Policy constraints/gcp.restrictCmekCryptoKeyProjects
csa-ccm-cek-04-3
All keys, used for encrypting data in storage, should be generated in on-premise HSM device and then imported to GCP CMEK. All keys are stored in the cloud-based HSM system
csa-ccm-cek-08-3
All Storage Service used in GCP should use Customer Managed Encryption Key for encrypting data-at-rest.
csa-ccm-dsp-04
DSP-04.1 monitors that all resources, supporting labels, have a label attached.
csa-ccm-dsp-16
DSP-16.3 monitors configuration of GCS buckets. Every GCS bucket needs to have the Soft Delete feature enabled or both features: Object Versioning and Object Retention enabled simultaneously.
csa-ccm-ivs-05-1
IVS-05.1 monitors that every GCP project has the attached Resource Manager Tag that define the environment.
csa-ccm-ivs-09-1
Firewall rules are not using tags and do not enable access to any services from the public Internet
csa-ccm-log-04-1
Restrict audit logs access to authorized personnel and maintain records that provide unique access accountability.
csa-ccm-log-06
Use a reliable time source across all relevant information processing systems.
DORA
Supported cloud provider: Google Cloud
Digital Operational Resilience Act
This framework includes the cloud control groups and cloud controls in the following sections.
dora-article-07
Financial entities must maintain updated ICT systems, protocols and tools that are appropriate for use, reliable, and resilient.
- Block Generic Access to Cassandra Ports
- Block Generic Access to CiscoSecure/WebSM Ports
- Block Generic Access to Directory Service Ports
- Block Generic Access to DNS Ports from All IP Addresses
- Block Generic Access to Elasticsearch Ports from All IP Addresses
- Block Generic Access to FTP Ports
- Block Generic Access to HTTP Ports
- Block Generic Access to LDAP Ports
- Block Generic Access to Memcached Ports
- Block Generic Access to MongoDB Ports
- Block Generic Access to MySQL Ports
- Block Generic Access to NetBIOS Ports from All IP Addresses
- Block Generic Access to Oracle Database Ports
- Block Generic Access to POP3 Server Ports
- Block Generic Access to PostgreSQL Server Ports from All IP Addresses
- Block Generic Access to Redis Server Ports from All IP Addresses
- Block Generic Access to SMTP Server Ports
- Block Generic Access to Telnet Servers
- Block Overly Permissive Firewall Rules
- Block Serial Ports for Compute Engine Instances
- Configure the Allowed Ingress Settings for Cloud Run Organization Policy Constraint
- Configure the Allowed VPC Egress Settings for Cloud Run Organization Policy Constraint
- Configure the Disable VPC External IPv6 Usage Organization Policy
- Define Rotation Period for Cloud KMS Keys
- Enable CMEK for AlloyDB Clusters
- Enable CMEK for BigQuery Datasets
- Enable CMEK for BigQuery Tables
- Enable CMEK for Cloud SQL Databases
- Enable CMEK for Cloud Storage Buckets
- Enable CMEK on GKE Node Pool Boot Disks
- Enable Control Plane Authorized Networks on GKE Clusters
- Enable DNSSEC for Cloud DNS
- Enable Encryption on GKE Clusters
- Enable IP Alias Range for GKE Clusters
- Enable Network Policy on GKE Clusters
- Enable Private Clusters for GKE
- Enable Private Google Access for VPC Subnets
- Enable Private Google Access on an instance
- Enable Shielded GKE Nodes on a Cluster
- Enable SSL Encryption On AlloyDB Instances
- Enable the Restrict Authorized Networks on Cloud SQL Instances Organization Policy Constraint
- Encrypt Pub/Sub topic with CMEK
- Enforce SSL for all Incoming Database Connections
- Limit KMS Crypto Keys Users to Three
- Require Container-Optimized OS for a GKE Cluster
- Restrict Public Access to BigQuery Datasets
- Restrict User Managed Service Account Keys
- Use Custom VPC Networks
dora-article-09
Financial entities must implement security tools that continually monitor and control ICT systems and ensure, but not limited to, privacy, availability, integrity and confidentiality.
- Allocate Audit Log Storage Capacity
- Assess Actions that Don't Require Identification or Authentication
- Authorize and Monitor Privileged Remote Access
- Authorize Wireless Access to Production Systems
- Automate Account Management System
- Automate Near Real-time Event Analysis
- Avoid RSASHA1 for DNSSEC Signing
- Block Administrator Roles from Service Accounts
- Block Automatic IAM Grants to Default Service Accounts
- Block External IP Address Access on Compute Engine VM Instances
- Block Generic Access to Cassandra Ports
- Block Generic Access to CiscoSecure/WebSM Ports
- Block Generic Access to Directory Service Ports
- Block Generic Access to DNS Ports from All IP Addresses
- Block Generic Access to Elasticsearch Ports from All IP Addresses
- Block Generic Access to FTP Ports
- Block Generic Access to HTTP Ports
- Block Generic Access to LDAP Ports
- Block Generic Access to Memcached Ports
- Block Generic Access to MongoDB Ports
- Block Generic Access to MySQL Ports
- Block Generic Access to NetBIOS Ports from All IP Addresses
- Block Generic Access to Oracle Database Ports
- Block Generic Access to POP3 Server Ports
- Block Generic Access to PostgreSQL Server Ports from All IP Addresses
- Block Generic Access to RDP Ports
- Block Generic Access to Redis Server Ports from All IP Addresses
- Block Generic Access to SMTP Server Ports
- Block Generic Access to SSH Ports
- Block Generic Access to Telnet Servers
- Block Legacy Authorization on GKE Clusters
- Block Overly Permissive Firewall Rules
- Block Project-Wide SSH Keys on Compute Engine Instances
- Block Public IP Addresses for AlloyDB Cluster Instances
- Block Public IP Addresses for Cloud SQL Instances
- Block Serial Ports for Compute Engine Instances
- Block Service Account Key Creation
- Block Service Account Key Uploads
- Configure a Wireless Intrusion Detection Mechanism
- Configure Access Controls for the Network Boundary
- Configure Log Metrics and Alerts for Cloud Storage IAM Policy Changes
- Configure Network Devices to Fail in a Secure State
- Configure Security Logging Policies for Google Cloud Services
- Configure the Allowed VPC Egress Settings for Cloud Run Organization Policy Constraint
- Configure the Disable VM Serial Port Logging to Stackdriver Organization Policy
- Configure the Disable VPC External IPv6 Usage Organization Policy
- Configure the Disable VPC Internal IPv6 Usage Organization Policy
- Configure VPC Firewall Rules, Subnets, and VPN Gateway
- Control Integrations with External Systems
- Control Remote Device Connections
- Correlate Audit Records
- Create Alerts for Monitoring Security Command Center Errors
- Create Artifact Registry Cleanup Policies
- Create GKE Clusters with Limited Privileges
- Create Inventory of Security Data Assets
- Define a Security Policy to Mitigate for DDoS Events
- Define Allowed Services for Service Perimeter
- Define Cloud Billing Budget Threshold
- Define Cloud KMS Crypto Keys Protection Level
- Define Mobile Code Policies and Controls
- Define Rotation Period for Cloud KMS Keys
- Define Service Perimeters in VPC Service Controls
- Define Storage Class Lifestyle Action
- Define the Maximum Number of Concurrent Sessions for System Accounts in Workforce Identity Pools
- Define VPC Connector Egress For Cloud Run Functions
- Define Worker Pools for Cloud Builds
- Develop System and Communications Protection Policy and Procedures
- Disable Alpha Features on GKE Clusters
- Don't Use Legacy Networks
- Don't Use User Connections Flag for SQL Server
- Don't Use User Options Flag for SQL Server
- Employ Monthly Checks for Flaw Remediation Status
- Employ Spam Protection Mechanisms
- Enable 3625 Trace Database Flag for SQL Server
- Enable Artifact Analysis Vulnerability Scanning
- Enable Audit Logs Bucket Enumeration
- Enable Audit Logs for All Services
- Enable Audit Logs for Google Cloud Services
- Enable Auto Upgrade on GKE Clusters
- Enable Cloud Asset Inventory Service
- Enable Cloud DNS Logs Monitoring
- Enable Cloud Logging on GKE Clusters
- Enable Cloud Monitoring on GKE Clusters
- Enable CMEK for AlloyDB Clusters
- Enable CMEK for BigQuery Datasets
- Enable CMEK for BigQuery Tables
- Enable CMEK for Cloud SQL Databases
- Enable CMEK for Cloud Storage Buckets
- Enable CMEK on Compute Engine Persistent Disks
- Enable CMEK on GKE Node Pool Boot Disks
- Enable Confidential Computing for Compute Engine Instances
- Enable Control Plane Authorized Networks on GKE Clusters
- Enable CSEK On Compute Engine Persistent Disks
- Enable Data Write Audit Logs for Organization Policy
- Enable DNSSEC for Cloud DNS
- Enable Encryption for Mobile Devices
- Enable Encryption on GKE Clusters
- Enable Flow Logs for VPC Subnet
- Enable Integrity Monitoring on GKE Clusters
- Enable Intranode Visibility for GKE Clusters
- Enable IP Alias Range for GKE Clusters
- Enable Log Checkpoints Flag for PostgreSQL
- Enable Log Connections Flag for PostgreSQL
- Enable Log Disconnections Flag for PostgreSQL
- Enable Log Duration Flag for PostgreSQL instance
- Enable Log Error Verbosity Flag for PostgreSQL
- Enable Log Events Data Sharing
- Enable Log Locks Wait Flag for PostgreSQL instance
- Enable Log Min Error Statement Flag for PostgreSQL
- Enable Log Min Messages Flag for PostgreSQL
- Enable Log Statement Flag for PostgreSQL
- Enable Network Policy on GKE Clusters
- Enable Private Clusters for GKE
- Enable Private Google Access for VPC Subnets
- Enable Private Google Access on an instance
- Enable SDP for Data Discovery
- Enable Shielded GKE Nodes on a Cluster
- Enable Shielded VM for Compute Engine Instances
- Enable Skip Show Database Flag for MySQL
- Enable SSL Encryption On AlloyDB Instances
- Enable System Use Notifications on VMs
- Enable the Confidential VM Organization Policy Constraint
- Enable Uniform Bucket-Level Access on Cloud Storage Buckets
- Enable VPC Flow Logs for Compute Engine Instances
- Enable Workload Identity Federation for GKE on clusters
- Encrypt Data at Rest with CMEK
- Encrypt Pub/Sub topic with CMEK
- Enforce 2-Step Verification for Super Admin Accounts
- Enforce CMEK for Supported Services
- Enforce Compute Session Inactive Policy
- Enforce Deny All Egress Firewall Rule
- Enforce Domain Restricted Sharing
- Enforce HTTPS Traffic Only
- Enforce IAM Least Privilege
- Enforce Least Privilege
- Enforce Least Privilege Guide
- Enforce Separation of Duties
- Enforce Session Lock Policy
- Enforce SSL Encryption for Remote Access
- Enforce SSL for all Incoming Database Connections
- Generate Auditable Events
- Implement Authorized Decision Makers for Access Requests
- Implement Centralized Security Monitoring
- Implement certificate lifecycle management
- Implement Continuous Network Traffic Monitoring
- Implement Error Handling Mechanism
- Implement Event Logging for Google Cloud Services
- Implement On-Demand Audit Log Access
- Implement Remote Access Policy
- Implement Secure Domain Name Resolution Service
- Implement Security Alert Advisory Management
- Import Google Workspace Audit Logs
- Inspect the External Load Balancer and SSL Connections
- Limit KMS Crypto Keys Users to Three
- Limit Super Admin Accounts
- Maintain Resource Isolation
- Manage Access to Audit Logs
- Manage Access to Google Cloud Resources from Mobile Devices
- Manage Data Handling and Retention
- Manage Malicious Code Protection Mechanisms
- Manage Publicly Accessible Content
- Manage System Integrity Policies and Procedures
- Perform Integrity Checks Every Month
- Prevent IP Forwarding on Compute Engine Instances
- Protect System Memory
- Remove Inactive Accounts
- Remove Temporary Accounts
- Require Additional Logging for Sensitive Buckets
- Require Audit Logging for Privileged Activities
- Require CMEK on Dataproc Clusters
- Require Container-Optimized OS for a GKE Cluster
- Require Least Privilege
- Require Service Account Key Rotation
- Require Unique Super Admin Account
- Restrict Access Control Points for Authorized and Managed Remote Access
- Restrict Access to Audit Logs
- Restrict API Access to Google Cloud APIs for Compute Engine Instances
- Restrict Cloud Shell Access Settings
- Restrict CMEK Crypto Key Projects
- Restrict External IP Addresses to Specific VM Instances
- Restrict Insecure SSL Policies for Compute Engine Instances
- Restrict Legacy TLS Versions
- Restrict Non CMEK Services
- Restrict Non-Privileged Users from Executing Privileged Functions
- Restrict Public Access to BigQuery Datasets
- Restrict Public Access to Cloud SQL Database Instances
- Restrict Public Access to Cloud Storage Buckets
- Restrict Public IP Addresses to Compute Engine Instances
- Restrict User Managed Service Account Keys
- Restrict VM IP Forwarding for Compute Engine Instances
- Restrict VPC Networks on Agent Platform Workbench Instances
- Retain Audit Records
- Review Authentication, Authorization, User Account Management
- Review Log and Alert Configuration
- Separate User and Administrator Roles
- Set Ingress and Egress Controls for Compute
- Set Log Bucket Flag for Bucket Logging
- Set Log Error Verbosity Flag for AlloyDB Instances
- Set Log Min Error Statement Flag for AlloyDB Instances
- Set Log Min Messages Flag for AlloyDB Instances
- Set Uniform Bucket Level Access for Cloud Storage Buckets
- Set Up Job Scheduling and Configurations
- Subscribe a GKE Cluster to a Release Channel
- Synchronize System Clocks
- Terminate Network Connections
- Triage and Remediate System Flaws
- Turn Off Contained Database Authentication Flag for SQL Server
- Turn Off Cross Database Ownership Chaining Flag for SQL Server
- Turn Off External Scripts Flag for SQL Server
- Turn off Log Hostname Flag for PostgreSQL
- Turn Off Log Min Duration Statement Flag for PostgreSQL
- Turn Off Remote Access Flag for SQL Server
- Use Custom Service Accounts for Compute Engine Instances
- Use Custom VPC Networks
- Use IAM Tags
- Use Least Privilege Service Accounts for GKE Clusters
- Use Secure Web Proxy for Network Traffic Control
- Use TLS 1.2 or Higher
- Verify Cloud KMS Key Version Algorithm
dora-article-10
Financial entities must implement mechanisms for prompt detection of anomalous activities and support ICT related incident response.
- Activate Security Command Center
- Allocate Audit Log Storage Capacity
- Automate Integrity Verification
- Automate Near Real-time Event Analysis
- Block Generic Access to RDP Ports
- Block Generic Access to SSH Ports
- Block Legacy Authorization on GKE Clusters
- Configure a Wireless Intrusion Detection Mechanism
- Configure Log Metrics and Alerts for Cloud Storage IAM Policy Changes
- Configure Security Logging Policies for Google Cloud Services
- Create Alerts for Monitoring Security Command Center Errors
- Create Artifact Registry Cleanup Policies
- Disable Alpha Features on GKE Clusters
- Employ Monthly Checks for Flaw Remediation Status
- Enable Artifact Analysis Vulnerability Scanning
- Enable Audit Logs Bucket Enumeration
- Enable Audit Logs for All Services
- Enable Audit Logs for Google Cloud Services
- Enable Cloud Logging on GKE Clusters
- Enable Cloud Monitoring on GKE Clusters
- Enable Data Write Audit Logs for Organization Policy
- Enable Intranode Visibility for GKE Clusters
- Enable Log Checkpoints Flag for PostgreSQL
- Enable Log Connections Flag for PostgreSQL
- Enable Log Disconnections Flag for PostgreSQL
- Enable Log Duration Flag for PostgreSQL instance
- Enable Log Error Verbosity Flag for PostgreSQL
- Enable Log Locks Wait Flag for PostgreSQL instance
- Enable Log Min Error Statement Flag for PostgreSQL
- Enable Log Min Messages Flag for PostgreSQL
- Enable Log Statement Flag for PostgreSQL
- Generate Auditable Events
- Implement Alerting for Incidence Response
- Implement Audit Lifecycle Management
- Implement Centralized Security Monitoring
- Implement Error Handling Mechanism
- Implement Event Logging for Google Cloud Services
- Implement Security Alert Advisory Management
- Import Google Workspace Audit Logs
- Incorporate Integrity Monitoring into Incident Response
- Limit Super Admin Accounts
- Manage Access to Audit Logs
- Manage Data Handling and Retention
- Manage Malicious Code Protection Mechanisms
- Manage System Integrity Policies and Procedures
- Perform Integrity Checks Every Month
- Prevent IP Forwarding on Compute Engine Instances
- Protect System Memory
- Require Additional Logging for Sensitive Buckets
- Require Container-Optimized OS for a GKE Cluster
- Restrict Access to Audit Logs
- Restrict Resource Service Usage
- Retain Audit Records
- Review Log and Alert Configuration
- Set Log Bucket Flag for Bucket Logging
- Set Log Error Verbosity Flag for AlloyDB Instances
- Set Log Min Error Statement Flag for AlloyDB Instances
- Set Log Min Messages Flag for AlloyDB Instances
- Subscribe a GKE Cluster to a Release Channel
- Synchronize System Clocks
- Triage and Remediate System Flaws
- Turn Off External Scripts Flag for SQL Server
- Turn off Log Hostname Flag for PostgreSQL
- Turn Off Log Min Duration Statement Flag for PostgreSQL
EU Data Boundary
Supported cloud provider: Google Cloud
Supports compliance with EU data residency requirements by restricting resource locations to EU regions.
This framework includes the following cloud controls:
- BigQuery compliance settings
- Cloud Databases Context Store Regulatory Settings
- Configure Dataplex to Support Data Boundaries
- Configure Dataproc to Support Data Boundaries
- Configure Google Agent Platform to Support Data Boundaries
- Define Locations for Cloud Logging Buckets
- Define Locations for Technical Support Services
- Disable Global Cloud Armor Policies
- Disable Pub/Sub Subscription Message Transforms
- Disable Pub/Sub Topic Message Transforms
- Disable the Creation and Update of Kafka Connect Clusters
- Enable Access Transparency
- Enable Cloud Logging Compliance with FedRAMP or DoD Impact Levels
- Enable Compliance Settings for Cloud Monitoring
- Enable Looker (Google Cloud core) Compliance with FedRAMP or DoD Impact Levels
- Enable Regulatory Settings for Apigee
- Require CMEK Protection
- Restrict Resource Locations
- Restrict Service Usage
- Restrict TLS Versions
EU Data Boundary and Support
Supported cloud provider: Google Cloud
Supports compliance with EU data residency and support requirements by restricting resource locations to EU regions and limiting support access to EU-based personnel.
This framework includes the following cloud controls:
- BigQuery compliance settings
- Cloud Databases Context Store Regulatory Settings
- Configure Dataplex to Support Data Boundaries
- Configure Dataproc to Support Data Boundaries
- Configure Google Agent Platform to Support Data Boundaries
- Configure Spanner to Support Data Boundaries
- Define Locations for Cloud Logging Buckets
- Define Locations for Technical Support Services
- Disable Global Cloud Armor Policies
- Disable Pub/Sub Subscription Message Transforms
- Disable Pub/Sub Topic Message Transforms
- Disable Spanner Multi-Region Instances
- Disable the Creation and Update of Kafka Connect Clusters
- Enable Access Transparency
- Enable Advanced Service Controls for Spanner
- Enable Cloud Logging Compliance with FedRAMP or DoD Impact Levels
- Enable Compliance Settings for Cloud Monitoring
- Enable Looker (Google Cloud core) Compliance with FedRAMP or DoD Impact Levels
- Enable Regulatory Settings for Apigee
- Require CMEK Protection
- Restrict Resource Locations
- Restrict Service Usage
- Restrict TLS Versions
FedRAMP High
Supported cloud provider: Google Cloud
Controls for meeting FedRAMP High compliance requirements.
This framework includes the following cloud controls:
- BigQuery compliance settings
- Cloud Databases Context Store Regulatory Settings
- Configure Dataplex to Support Data Boundaries
- Configure Dataproc to Support Data Boundaries
- Configure Google Agent Platform to Support Data Boundaries
- Configure Google Cloud Serverless for Apache Spark to Support Data Boundaries
- Configure Spanner to Support Data Boundaries
- Define Locations for Cloud Logging Buckets
- Define Locations for Technical Support Services
- Define the Permitted Versions for Cloud Run Functions
- Disable Creation of Global Load Balancers
- Disable Global Cloud Armor Policies
- Disable Pub/Sub Subscription Message Transforms
- Disable Pub/Sub Topic Message Transforms
- Enable Access Transparency
- Enable Cloud Logging Compliance with FedRAMP or DoD Impact Levels
- Enable Compliance Regulatory Settings for Cloud Deploy
- Enable Compliance Settings for Cloud Identity
- Enable Compliance Settings for Cloud Monitoring
- Enable Looker (Google Cloud core) Compliance with FedRAMP or DoD Impact Levels
- Enable Regulatory Settings for Cloud DNS
- Enable Regulatory Settings for Gemini Enterprise
- Require CMEK Protection
- Restrict Resource Locations
- Restrict Service Usage
- Restrict the BigQuery Data Transfer Service API
- Restrict TLS Versions
FedRAMP Low 20x
Supported cloud provider: Google Cloud
A Government-wide program that provides a standardized, reusable approach to security assessment and authorization for cloud computing products and services that process unclassified information used by agencies. FedRAMP Low impact is most appropriate for CSOs where the loss of confidentiality, integrity and availability would result in limited adverse effect on an agency's operations, assets or individuals.
This framework includes the cloud control groups and cloud controls in the following sections.
ksi-ced-1
Ensure employees receive security awareness training.
ksi-ced-2
Mandate role-specific training for high-risk roles, in particular for roles with privileged access.
ksi-cmt-1
Log and monitor system modifications. Ensure that all system changes are documented and configuration baselines are updated.
- Configure Log Metrics and Alerts for Audit Logging Changes
- Configure Log Metrics and Alerts for Cloud SQL Configuration Changes
- Configure Log Metrics and Alerts for Cloud Storage IAM Policy Changes
- Configure Log Metrics and Alerts for Custom Role Changes
- Configure Log Metrics and Alerts for VPC Network Changes
- Configure Log Metrics and Alerts for VPC Network Firewall Changes
- Configure Log Metrics and Alerts for VPC Route Changes
- Restrict Non-Privileged Users from Executing Privileged Functions
ksi-cmt-3
Implement automated testing and validation of changes before deployment.
ksi-cmt-4
Implement a documented change management procedure.
ksi-cmt-5
Evaluate the risk and potential impact of every change.
ksi-cna-1
Configure all information resources to limit inbound and outbound traffic.
- Configure the Allowed Ingress Settings for Cloud Run Organization Policy Constraint
- Configure the Allowed VPC Egress Settings for Cloud Run Organization Policy Constraint
- Define VPC Connector Egress For Cloud Run Functions
- Enable Network Policy on GKE Clusters
- Enable Private Clusters for GKE
- Enforce Deny All Egress Firewall Rule
- Extract External IP Addresses for VM Instances
- Extract GKE Public IP Addresses List
- Extract Public IP Addresses for Cloud SQL
- Restrict External IP Addresses to Specific VM Instances
- Retrieve Cloud NAT Configurations
- Set Ingress and Egress Controls for Compute
ksi-cna-2
Design systems to help reduce the attack surface and minimize lateral movement if compromised.
- Block Generic Access to CiscoSecure/WebSM Ports
- Block Generic Access to Directory Service Ports
- Block Generic Access to DNS Ports from All IP Addresses
- Block Generic Access to Elasticsearch Ports from All IP Addresses
- Block Generic Access to FTP Ports
- Block Generic Access to HTTP Ports
- Block Generic Access to LDAP Ports
- Block Generic Access to Memcached Ports
- Block Generic Access to MongoDB Ports
- Block Generic Access to MySQL Ports
- Block Generic Access to NetBIOS Ports from All IP Addresses
- Block Generic Access to Oracle Database Ports
- Block Generic Access to POP3 Server Ports
- Block Generic Access to PostgreSQL Server Ports from All IP Addresses
- Block Generic Access to RDP Ports
- Block Generic Access to Redis Server Ports from All IP Addresses
- Block Generic Access to SMTP Server Ports
- Block Generic Access to SSH Ports
- Block Generic Access to Telnet Servers
- Block Overly Permissive Firewall Rules
- Block Public IP Addresses for AlloyDB Cluster Instances
- Block Public IP Addresses for Cloud SQL Instances
- Don't Use Kubernetes Web UI
- Restrict Public Access to BigQuery Datasets
- Restrict Public Access to Cloud Storage Buckets
- Restrict Public IP Addresses on Agent Platform Workbench Notebooks and Instances
- Restrict Public IP Addresses to Compute Engine Instances
ksi-cna-3
Implement traffic flow controls using logical networking and related capabilities.
- Configure VPC Firewall Rules, Subnets, and VPN Gateway
- Define Allowed Services for Service Perimeter
- Define Service Perimeters in VPC Service Controls
- Define Worker Pools for Cloud Builds
- Enable Private Google Access for VPC Subnets
- Retrieve VPC Network Peering Configurations
ksi-cna-4
Use immutable infrastructure with strictly defined functionality and privileges.
- Define External Build Integrations for Cloud Build
- Enable Auto Repair for GKE Clusters
- Guidance for Immutable Infrastructure on Google Cloud
- Review Artifact Registry Images
- Review Cloud Run Images
- Review Hardened Compute Images
- Verify GKE Container Optimized OS
ksi-cna-5
Enforce denial-of-service protection to help protect information systems resources built on Google Cloud.
ksi-cna-6
Design information systems with high availability and rapid recovery capabilities to help prevent data loss.
- Assess the Availability of Compute and GKE Resources
- Disable Alpha Features on GKE Clusters
- Enable Object Versioning on Buckets
- GKE Node Pool Autoscaling
- Retrieve GKE Availability
- Verify Cloud SQL Failover Replication
- Verify Cloud Storage Regional Deployment
ksi-cna-7
Implement cloud-first information resources that are based on the host provider's best practices and documented guidance.
- Block Generic Access to Cassandra Ports
- Define Retention Period for Cloud Storage Buckets
- Define Storage Class Lifestyle Action
- Implement Best Practices for Cloud Deployments
- Lock Storage Bucket Retention Policies
- Require CMEK on Dataproc Clusters
ksi-iam-1
Enforce multi-factor authentication (MFA) using methods that are difficult to intercept or impersonate (phishing-resistant MFA) for user authentication.
ksi-iam-2
Implement secure, passwordless methods when feasible, or enforce strong passwords with multi-factor authentication (MFA) for secure user authentication and authorization.
ksi-iam-3
Enforce secure authentication methods for all non-user accounts and services within Google Cloud to help protect data and resources from unauthorized access.
- Block Service Account Key Creation
- Block Service Account Key Uploads
- Enable Workload Identity Federation for GKE on clusters
- Restrict User Managed Service Account Keys
ksi-iam-4
Implement a security authorization model that is least-privileged, role and attribute-based, and just-in-time. Use this model for all user and non-user accounts and services to help reduce the risk of unauthorized access or misuse.
- Automate Account Management System
- Block Automatic IAM Grants to Default Service Accounts
- Define IsLive Attribute for Delete Action Lifestyle Rule on Bucket
- Use Least Privilege and Just in Time Access
- Use Least Privilege Service Accounts for GKE Clusters
ksi-iam-5
Enforce zero-trust design principles on your applications and services to enhance security.
ksi-iam-6
Automatically disable or secure accounts with privileged access when suspicious activity is detected to help mitigate security risks.
ksi-inr-1
Report incidents according to FedRAMP requirements and cloud service provider policies.
ksi-inr-2
Maintain a log of incidents and review past incidents for patterns or vulnerabilities at regular intervals.
ksi-inr-3
Generate after-action reports, and incorporate lessons learned into operations.
ksi-mla-1
Implement a centralized and tamper-resistant logging system using a Security Information and Event Management (SIEM) or similar system to record all application and service events, activities, and changes.
ksi-mla-2
Regularly review the audit logs of your applications and services.
- Enable Cloud DNS Logs Monitoring
- Enable Cloud Logging on GKE Clusters
- Enable Cloud Monitoring on GKE Clusters
- Enable Data Write Audit Logs for Organization Policy
- Enable Firewall Rule Logging
- Enable Flow Logs for VPC Subnet
- Enable Intranode Visibility for GKE Clusters
- Enable Load Balancer Logging
- Import Google Workspace Audit Logs
- Require Cloud Storage Bucket Logging
- Require IAM Logs
- Review Log and Alert Configuration
ksi-mla-3
Detect vulnerabilities and promptly remediate or mitigate them to help reduce the risk impact on applications and services.
- Create Alerts for Monitoring Security Command Center Errors
- Enable Artifact Analysis Vulnerability Scanning
- Enable Security Command Center
ksi-mla-4
Conduct regular authenticated vulnerability scans on information resources.
ksi-mla-5
Implement Infrastructure as Code (IaC) and perform configuration evaluation and testing.
ksi-mla-6
Track and prioritize the mitigation and remediation of identified vulnerabilities in a central system.
ksi-piy-1
Maintain an updated information resource inventory or code that defines all deployed assets, software, and services.
ksi-piy-2
Outline policies with the security objectives for all information resources.
ksi-piy-3
Maintain a vulnerability disclosure program that includes intentional, organized, universal guidance for how every information resource, including personnel, is secured.
ksi-piy-4
Build security considerations into the Software Development Lifecycle (SDLC) and align with Cybersecurity and Infrastructure Security Agency's (CISA's) Secure By Design principles.
- Enforce HTTPS Traffic Only
- Enforce SSL for all Incoming Database Connections
- Implement Software Development Lifecycle Security Considerations
ksi-piy-5
Document the methods that are used to evaluate information resource implementations.
ksi-piy-6
Maintain dedicated staff and budget for security with executive support, in line with the size, complexity, scope, and risk of the service offering.
ksi-piy-7
Document risk management decisions for software supply chain security.
ksi-rpl-1
Define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) to ensure minimal service disruption and data loss during incidents and contingencies.
ksi-rpl-2
Develop and maintain a recovery plan that aligns with the defined recovery objectives.
ksi-rpl-3
Perform system backups that are aligned with recovery objectives.
- Enable AlloyDB Automated Backups on Cluster
- Enable Automatic Backups for Cloud SQL Databases
- Perform System Backups
ksi-rpl-4
Test your organization's ability to recover from incidents and contingencies at regular intervals.
ksi-svc-1
Regularly review and strengthen the network and system configurations to help ensure a secure baseline.
- Block Serial Ports for Compute Engine Instances
- Don't Use Legacy Networks
- Don't Use User Connections Flag for SQL Server
- Don't Use User Options Flag for SQL Server
- Enable 3625 Trace Database Flag for SQL Server
- Enable Cloud Asset Inventory Service
- Enable DNSSEC for Cloud DNS
- Require Security Hardening
ksi-svc-2
Encrypt all core content data that is exchanged between machines that connect to Google Cloud, or alternatively, secure all network traffic to help protect data.
ksi-svc-3
Ensure all federal and sensitive information at rest is encrypted.
ksi-svc-4
Manage configurations centrally to ensure consistent governance and security.
ksi-svc-5
Implement cryptographic mechanisms and integrity verification tools to enforce system and information resource integrity and help detect unauthorized changes.
ksi-svc-6
Use automated key management systems to help protect, manage, and regularly rotate digital keys and certificates.
- Enable OS Login for All Instances at Project Level
- Enable Workload Identity Federation for GKE on clusters
- Implement certificate lifecycle management
- Retrieve Cloud KMS Configurations
ksi-svc-7
Implement a consistent, risk-informed approach for applying security patches to your applications and services.
- Employ Monthly Checks for Flaw Remediation Status
- Enable Auto Upgrade on GKE Clusters
- Require Auto Upgrade Schedule Set for Agent Platform Workbench
- Subscribe a GKE Cluster to a Release Channel
ksi-tpr-1
Identify all third-party information resources to understand, monitor, and manage supply chain risks.
ksi-tpr-2
Ensure that the services that are federal information or are likely to impact the confidentiality, integrity, or availability of federal information are FedRAMP authorized and securely configured.
ksi-tpr-3
Identify and prioritize mitigation of potential supply chain risks.
ksi-tpr-4
Monitor third-party software information resources for upstream vulnerabilities, using contractual notification requirements or active monitoring services.
FedRAMP Moderate
Supported cloud provider: Google Cloud
Controls for meeting FedRAMP Moderate compliance requirements.
This framework includes the following cloud controls:
- Cloud Databases Context Store Regulatory Settings
- Configure Dataplex to Support Data Boundaries
- Configure Dataproc to Support Data Boundaries
- Configure Google Agent Platform to Support Data Boundaries
- Configure Google Cloud Serverless for Apache Spark to Support Data Boundaries
- Configure Spanner to Support Data Boundaries
- Define Locations for Cloud Logging Buckets
- Define Locations for Technical Support Services
- Enable Cloud Logging Compliance with FedRAMP or DoD Impact Levels
- Enable Looker (Google Cloud core) Compliance with FedRAMP or DoD Impact Levels
- Enable Regulatory Settings for Cloud DNS
- Require CMEK Protection
- Restrict Resource Locations
- Restrict Service Usage
- Restrict the BigQuery Data Transfer Service API
- Restrict TLS Versions
HIPAA
Supported cloud provider: Google Cloud
Health Insurance Portability and Accountability Act
This framework includes the cloud control groups and cloud controls in the following sections.
hipaa-security-ss164-308-a-3-i-workforce-security
Implement policies and procedures to ensure that all members of its workforce have appropriate access to electronic protected health information and to prevent those workforce members who do not have access from obtaining access to electronic protected health information.
- Enable Skip Show Database Flag for MySQL
- Restrict Public IP Addresses to Compute Engine Instances
- Set Uniform Bucket Level Access for Cloud Storage Buckets
- Turn Off Contained Database Authentication Flag for SQL Server
- Turn Off Cross Database Ownership Chaining Flag for SQL Server
hipaa-security-ss164-308-a-3-ii-a-workforce-security-authorization-and-or-supervision
Implement procedures for the authorization and/or supervision of workforce members who work with EPHI or in locations where it might be accessed.
- Enable Skip Show Database Flag for MySQL
- Restrict Public IP Addresses to Compute Engine Instances
- Set Uniform Bucket Level Access for Cloud Storage Buckets
- Turn Off Contained Database Authentication Flag for SQL Server
- Turn Off Cross Database Ownership Chaining Flag for SQL Server
hipaa-security-ss164-308-a-7-ii-a-contingency-plan-data-backup-plan
Establish and implement procedures to create and maintain retrievable exact copies of EPHI.
hipaa-security-ss164-310-d-2-iii-device-and-media-controls-accountability
Maintain a record of the movements of hardware and electronic media and any person responsible therefore.
hipaa-security-ss164-312-a-1-access-control
Implement technical policies and procedures for electronic information systems that maintain electronic protected health information to allow access only to those persons or software programs that have been granted access rights
- Enable Skip Show Database Flag for MySQL
- Restrict Public IP Addresses to Compute Engine Instances
- Set Uniform Bucket Level Access for Cloud Storage Buckets
- Turn Off Contained Database Authentication Flag for SQL Server
- Turn Off Cross Database Ownership Chaining Flag for SQL Server
hipaa-security-ss164-312-a-2-iv-access-control-encryption-and-decryption
Implement a mechanism to encrypt and decrypt EPHI.
- Block Project-Wide SSH Keys on Compute Engine Instances
- Define Rotation Period for Cloud KMS Keys
- Enable CMEK for BigQuery Tables
- Enable Confidential Computing for Compute Engine Instances
- Enable CSEK On Compute Engine Persistent Disks
- Enforce SSL for all Incoming Database Connections
- Require CMEK on Dataproc Clusters
hipaa-security-ss164-312-b-audit-controls
Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.
hipaa-security-ss164-312-e-1-transmission
Implement technical security measures to guard against unauthorized access to electronic protected health information that is being transmitted over an electronic communications network.
- Block Project-Wide SSH Keys on Compute Engine Instances
- Enforce SSL for all Incoming Database Connections
hipaa-security-ss164-312-e-2-i-transmission-security-integrity-controls
Implement security measures to ensure that electronically transmitted EPHI is not improperly modified without detection until disposed of.
- Block Project-Wide SSH Keys on Compute Engine Instances
- Enforce SSL for all Incoming Database Connections
hipaa-security-ss164-312-e-2-ii-transmission-security-encryption
Implement a mechanism to encrypt EPHI whenever deemed appropriate.
- Block Project-Wide SSH Keys on Compute Engine Instances
- Define Rotation Period for Cloud KMS Keys
- Enable CMEK for BigQuery Tables
- Enable Confidential Computing for Compute Engine Instances
- Enable CSEK On Compute Engine Persistent Disks
- Enforce SSL for all Incoming Database Connections
- Require CMEK on Dataproc Clusters
IL2
Supported cloud provider: Google Cloud
Controls for meeting IL2 compliance requirements.
This framework includes the following cloud controls:
- BigQuery compliance settings
- Cloud Databases Context Store Regulatory Settings
- Configure Dataplex to Support Data Boundaries
- Configure Dataproc to Support Data Boundaries
- Configure Google Agent Platform to Support Data Boundaries
- Configure Spanner to Support Data Boundaries
- Define Locations for Cloud Logging Buckets
- Define Locations for Technical Support Services
- Define the Permitted Versions for Cloud Run Functions
- Disable Creation of Global Load Balancers
- Disable Global Cloud Armor Policies
- Disable Pub/Sub Subscription Message Transforms
- Disable Pub/Sub Topic Message Transforms
- Enable Access Transparency
- Enable Cloud Logging Compliance with FedRAMP or DoD Impact Levels
- Enable Compliance Regulatory Settings for Cloud Deploy
- Enable Compliance Settings for Cloud Identity
- Enable Compliance Settings for Cloud Monitoring
- Enable Looker (Google Cloud core) Compliance with FedRAMP or DoD Impact Levels
- Enable Regulatory Settings for Cloud DNS
- Require CMEK Protection
- Restrict Resource Locations
- Restrict Service Usage
- Restrict the BigQuery Data Transfer Service API
- Restrict TLS Versions
IL4
Supported cloud provider: Google Cloud
Controls for meeting IL4 compliance requirements.
This framework includes the following cloud controls:
- BigQuery compliance settings
- Cloud Databases Context Store Regulatory Settings
- Configure Dataplex to Support Data Boundaries
- Configure Dataproc to Support Data Boundaries
- Configure Google Agent Platform to Support Data Boundaries
- Configure Spanner to Support Data Boundaries
- Define Locations for Cloud Logging Buckets
- Define Locations for Technical Support Services
- Disable Compute Instance Data Access APIs
- Disable Creation of Global Load Balancers
- Disable GKE Diagnostic Administrative Access
- Disable Global Cloud Armor Policies
- Disable Pub/Sub Subscription Message Transforms
- Disable Pub/Sub Topic Message Transforms
- Disable Spanner Multi-Region Instances
- Enable Access Transparency
- Enable Cloud Logging Compliance with FedRAMP or DoD Impact Levels
- Enable Compliance Settings for Cloud Identity
- Enable Compliance Settings for Cloud Monitoring
- Enable Regulatory Settings for Cloud DNS
- Enable Regulatory Settings for Gemini Enterprise
- Require CMEK Protection
- Restrict Resource Locations
- Restrict Service Usage
- Restrict TLS Versions
- Specify Cloud KMS Key Protection Levels
IL5
Supported cloud provider: Google Cloud
Controls for meeting IL5 compliance requirements.
This framework includes the following cloud controls:
- Allow Only IL5 Compliant APIs for Gemini Enterprise Agent Platform
- BigQuery compliance settings
- Cloud Databases Context Store Regulatory Settings
- Configure Dataplex to Support Data Boundaries
- Configure Dataproc to Support Data Boundaries
- Configure Google Agent Platform to Support Data Boundaries
- Configure Spanner to Support Data Boundaries
- Create CMEK Project and Key Ring
- Define Locations for Cloud Logging Buckets
- Define Locations for Technical Support Services
- Disable Compute Instance Data Access APIs
- Disable Creation of Global Load Balancers
- Disable diagnostic and administrative access pathways in Cloud SQL
- Disable Global Cloud Armor Policies
- Disable Pub/Sub Subscription Message Transforms
- Disable Pub/Sub Topic Message Transforms
- Disable Service Account Key Creation
- Disable Spanner Multi-Region Instances
- Enable Access Transparency
- Enable Cloud Logging Compliance with FedRAMP or DoD Impact Levels
- Enable Compliance Settings for Cloud Identity
- Enable Compliance Settings for Cloud Monitoring
- Enable Regulatory Settings for Cloud DNS
- Prevent Automatic Creation of Default Network
- Prevent Automatic Granting of Editor Role to Default Service Accounts
- Require CMEK Protection
- Restrict Cloud SQL Resource Creation
- Restrict Public Access to Data Stored in Buckets
- Restrict Resource Locations
- Restrict Service Usage
- Restrict TLS Versions
- Set Zonal DNS as Default for Compute Engine
- Specify Cloud KMS Key Protection Levels
ISO 27001:2022
Supported cloud provider: Google Cloud
The international standard for an Information Security Management System (ISMS). It provides a systematic, risk-based approach to managing sensitive information by specifying requirements for establishing and improving security controls.
This framework includes the cloud control groups and cloud controls in the following sections.
iso-27001-2022-a-5-1
Information security policy and topic-specific policies shall be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties, and reviewed at planned intervals and if significant changes occur.
iso-27001-2022-a-5-10
Rules for the acceptable use and procedures for handling information and other associated assets shall be identified, documented and implemented.
- Block Public IP Addresses for AlloyDB Cluster Instances
- Block Public IP Addresses for Cloud SQL Instances
- Enable Skip Show Database Flag for MySQL
- Enable Uniform Bucket-Level Access on Cloud Storage Buckets
- Restrict Public Access to BigQuery Datasets
- Restrict Public Access to Cloud SQL Database Instances
- Restrict Public Access to Cloud Storage Buckets
- Restrict Public IP Addresses to Compute Engine Instances
- Turn Off Contained Database Authentication Flag for SQL Server
- Turn Off Cross Database Ownership Chaining Flag for SQL Server
iso-27001-2022-a-5-12
Information shall be classified according to the information security needs of the organization based on confidentiality, integrity, availability and relevant interested party requirements.
iso-27001-2022-a-5-14
Information transfer rules, procedures, or agreements shall be in place for all types of transfer facilities within the organization and between the organization and other parties.
iso-27001-2022-a-5-15
Rules to control physical and logical access to information and other associated assets shall be established and implemented based on business and information security requirements.
- Block Public IP Addresses for AlloyDB Cluster Instances
- Block Public IP Addresses for Cloud SQL Instances
- Block Root Access on Agent Platform Workbench Instances
- Block Terminal Access on Agent Platform Workbench Instances
- Define Agent Platform Workbench Instance Access Mode
- Enable OS Login for All Instances at Project Level
- Enable Skip Show Database Flag for MySQL
- Enable Uniform Bucket-Level Access on Cloud Storage Buckets
- Enforce Public Access Prevention
- Restrict Public Access to BigQuery Datasets
- Restrict Public Access to Cloud SQL Database Instances
- Restrict Public Access to Cloud Storage Buckets
- Restrict Public IP Addresses to Compute Engine Instances
- Restrict Service Usage
- Set Application Restriction on API Keys
- Set Uniform Bucket Level Access for Cloud Storage Buckets
- Turn Off Contained Database Authentication Flag for SQL Server
- Turn Off Cross Database Ownership Chaining Flag for SQL Server
iso-27001-2022-a-5-17
Allocation and management of authentication information shall be controlled by a management process, including advising personnel on appropriate handling of authentication information.
iso-27001-2022-a-5-18
Access rights to information and other associated assets shall be provisioned, reviewed, modified and removed in accordance with the organization’s topic-specific policy on and rules for access control.
- Block Automatic IAM Grants to Default Service Accounts
- Retain Audit Records
- Set Application Restriction on API Keys
iso-27001-2022-a-5-19
Processes and procedures shall be defined and implemented to manage the information security risks associated with the use of supplier’s products or services.
iso-27001-2022-a-5-20
Relevant information security requirements shall be established and agreed with each supplier based on the type of supplier relationship.
iso-27001-2022-a-5-23
Processes for acquisition, use, management and exit from cloud services shall be established in accordance with the organization’s information security requirements.
- Block Root Access on Agent Platform Workbench Instances
- Block Terminal Access on Agent Platform Workbench Instances
- Define Agent Platform Workbench Instance Access Mode
- Disable File Downloads on Agent Platform Workbench Instances
- Enforce CMEK for Supported Services
- Require Auto Upgrade Schedule Set for Agent Platform Workbench
- Restrict Non CMEK Services
- Restrict Public IP Addresses on Agent Platform Workbench Notebooks and Instances
- Restrict Service Usage
iso-27001-2022-a-5-24
The organization shall plan and prepare for managing information security incidents by defining, establishing and communicating information security incident management processes, roles and responsibilities.
iso-27001-2022-a-5-25
The organization shall assess information security events and decide if they are to be categorized as information security incidents.
iso-27001-2022-a-5-28
The organization shall establish and implement procedures for the identification, collection, acquisition and preservation of evidence related to information security events.
- Enable Log Connections Flag for PostgreSQL
- Enable Log Disconnections Flag for PostgreSQL
- Enable Log Error Verbosity Flag for PostgreSQL
- Enable Log Min Error Statement Flag for PostgreSQL
- Enable Log Min Messages Flag for PostgreSQL
- Enable Log Statement Flag for PostgreSQL
- Set Log Error Verbosity Flag for AlloyDB Instances
- Set Log Min Error Statement Flag for AlloyDB Instances
- Set Log Min Messages Flag for AlloyDB Instances
- Turn Off Log Min Duration Statement Flag for PostgreSQL
iso-27001-2022-a-5-30
ICT readiness shall be planned, implemented, maintained and tested based on business continuity objectives and ICT continuity requirements.
iso-27001-2022-a-5-33
Records shall be protected from loss, destruction, falsification, unauthorized access and unauthorized release.
- Define Retention Period for Cloud Storage Buckets
- Enable CMEK for AlloyDB Clusters
- Enable CMEK for BigQuery Datasets
- Enable CMEK for BigQuery Tables
- Enable Object Versioning on Buckets
- Lock Storage Bucket Retention Policies
- Require CMEK on Dataproc Clusters
iso-27001-2022-a-5-5
The organization shall establish and maintain contact with relevant authorities.
iso-27001-2022-a-5-6
The organization shall establish and maintain contact with special interest groups or other specialist security forums and professional associations.
iso-27001-2022-a-5-9
An inventory of information and other associated assets, including owners, shall be developed and maintained.
- Define Set Storage Class Lifestyle Action on Bucket
- Define Storage Class Lifestyle Action
- Enable Cloud Asset Inventory Service
iso-27001-2022-a-6-7
Security measures shall be implemented when personnel are working remotely to protect information accessed, processed or stored outside the organization’s premises.
iso-27001-2022-a-8-1
Information stored on, processed by or accessible using user end point devices shall be protected.
- Don't Use User Connections Flag for SQL Server
- Don't Use User Options Flag for SQL Server
- Enable 3625 Trace Database Flag for SQL Server
iso-27001-2022-a-8-10
Information stored in information systems, devices or in any other storage media shall be deleted when no longer required.
- Define Retention Period for Cloud Storage Buckets
- Lock Storage Bucket Retention Policies
- Turn Off External Scripts Flag for SQL Server
iso-27001-2022-a-8-13
Backup copies of information, software and systems shall be maintained and regularly tested in accordance with the agreed topic-specific policy on backup.