Assured Workloads cloud controls
This page provides reference content for the built-in cloud controls that are included in Assured Workloads frameworks. Cloud controls can apply to folders or projects.
Google Cloud cloud controls
Activate Security Command Center
Activate Security Command Center to evaluate security and data attack surfaces and help mitigate and remediate risks related to misconfigurations, vulnerabilities, and threats.
| Enforcement mode | Audit |
| Finding category | SCC_NOT_ACTIVATED |
| Revision number | 1 |
| Supported target resources |
|
Remediation steps
To activate Security Command Center, see Overview of activating Security Command Center.
Activate Security Command Center for Continuous Monitoring
Use Security Command Center to define security policies and deploy and monitor them.
| Enforcement mode | Audit |
| Finding category | SECURITY_COMMAND_CENTER_NOT_ACTIVATED |
| Revision number | 1 |
| Supported target resources |
|
Remediation steps
Complete the following:
-
Activate Security Command Center.
-
Create and deploy frameworks with cloud controls that align with your security policies.
-
Integrate with notification channels such as email and chat.
Allocate Audit Log Storage Capacity
Allocate sufficient audit log storage capacity to accommodate audit logs
| Enforcement mode |
|
| Severity | LOW |
| Finding category | INSUFFICIENT_AUDIT_LOG_STORAGE |
| Revision number | 2 |
| Supported target resources |
|
Remediation steps
-
Verify that you can see audit logs.
-
Verify that logs are being exported to the Cloud Storage bucket.
-
Verify the retention period for your log buckets.
-
Verify log storage capacity. In the console, got to Logging > Metrics and enter the following:
custom.googleapis.com/log_storage_capacity -
Verify the alerting policy for low log storage in your bucket.
-
Verify that storage capacity is sufficient for the Cloud Storage bucket (the usage is less than 90%).
-
Review the bucket retention period to ensure that regular review and adjustment of log storage capacity is complete.
Allow Only IL5 Compliant APIs for Gemini Enterprise Agent Platform
Restrict your folder or project to permit only Gemini Enterprise Agent Platform APIs that are compliant with Impact Level 5 (IL5).
| Enforcement mode |
|
| Severity | HIGH |
| Finding category | GEMINI_ENTERPRISE_AGENT_PLATFORM_ALLOW_IL5_COMPLIANT_APIS |
| Category name in the API | CC_CATEGORY_INFRASTRUCTURE |
| Revision number | 1 |
| Supported target resources |
|
Rules
| Organization policy constraint |
constraints/vertexai.allowOnlyIL5CompliantAPIs
|
Remediation steps
- Remediation for organization policy violation: Set the
vertexai.allowOnlyIL5CompliantAPIsconstraint totrue. See Updating policies with boolean rules.
Allow Only ITAR Compliant APIs for Gemini Enterprise Agent Platform
Restrict your folder or project to permit only Gemini Enterprise Agent Platform APIs that are compliant with International Traffic in Arms Regulations (ITAR).
| Enforcement mode |
|
| Severity | HIGH |
| Finding category | GEMINI_ENTERPRISE_AGENT_PLATFORM_ALLOW_ITAR_COMPLIANT_APIS |
| Category name in the API | CC_CATEGORY_INFRASTRUCTURE |
| Revision number | 1 |
| Supported target resources |
|
Rules
| Organization policy constraint |
constraints/vertexai.allowOnlyITARCompliantAPIs
|
Remediation steps
- Remediation for organization policy violation: Set the
vertexai.allowOnlyITARCompliantAPIsconstraint totrue. See