Assured Workloads cloud controls

This page provides reference content for the built-in cloud controls that are included in Assured Workloads frameworks. Cloud controls can apply to folders or projects.

Google Cloud cloud controls

Activate Security Command Center

Activate Security Command Center to evaluate security and data attack surfaces and help mitigate and remediate risks related to misconfigurations, vulnerabilities, and threats.

Enforcement mode Audit
Finding category SCC_NOT_ACTIVATED
Revision number 1
Supported target resources
  • Organization
  • Folder
  • Project

Remediation steps

To activate Security Command Center, see Overview of activating Security Command Center.

Activate Security Command Center for Continuous Monitoring

Use Security Command Center to define security policies and deploy and monitor them.

Enforcement mode Audit
Finding category SECURITY_COMMAND_CENTER_NOT_ACTIVATED
Revision number 1
Supported target resources
  • Organization
  • Folder
  • Project

Remediation steps

Complete the following:

Allocate Audit Log Storage Capacity

Allocate sufficient audit log storage capacity to accommodate audit logs

Enforcement mode
  • Detective
  • Audit
Severity LOW
Finding category INSUFFICIENT_AUDIT_LOG_STORAGE
Revision number 2
Supported target resources
  • Organization
  • Folder
  • Project

Remediation steps

  • Verify that you can see audit logs.

  • Verify that logs are being exported to the Cloud Storage bucket.

  • Verify the retention period for your log buckets.

  • Verify log storage capacity. In the console, got to Logging > Metrics and enter the following: custom.googleapis.com/log_storage_capacity

  • Verify the alerting policy for low log storage in your bucket.

  • Verify that storage capacity is sufficient for the Cloud Storage bucket (the usage is less than 90%).

  • Review the bucket retention period to ensure that regular review and adjustment of log storage capacity is complete.

Allow Only IL5 Compliant APIs for Gemini Enterprise Agent Platform

Restrict your folder or project to permit only Gemini Enterprise Agent Platform APIs that are compliant with Impact Level 5 (IL5).

Enforcement mode
  • Preventive
  • Detective