CIS Google Cloud Platform Foundation v4.0.0 L1

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS Google Cloud Platform Foundation v4.0.0 L1

Updated: 6/9/2026

Authority: CIS

Plugin: GCP

Revision: 1.1

Estimated Item Count: 49

File Details

Filename: CIS_Google_Cloud_Platform_Foundation_v4.0.0_L1.audit

Size: 153 kB

MD5: 2e6dc1f33b1739a5381179f9a112223d
SHA256: a82383a420cce4c6eeaa30b257b59a7ba7844c52ab80fcea77172ec8f71af0f7

Audit Changelog

 
Revision 1.1

Jun 9, 2026

Informational Update
  • 1.1 Ensure that Corporate Login Credentials are Used
  • 1.10 Ensure KMS Encryption Keys Are Rotated Within a Period of 90 Days
  • 1.16 Ensure Essential Contacts is Configured for Organization
  • 1.17 Ensure Secrets are Not Stored in Cloud Functions Environment Variables by Using Secret Manager
  • 1.4 Ensure That There Are Only GCP-Managed Service Account Keys for Each Service Account
  • 1.5 Ensure That Service Account Has No Admin Privileges
  • 1.6 Ensure That IAM Users Are Not Assigned the Service Account User or Service Account Token Creator Roles at Project Level
  • 1.7 Ensure User-Managed/External Keys for Service Accounts Are Rotated Every 90 Days or Fewer
  • 1.9 Ensure That Cloud KMS Cryptokeys Are Not Anonymously or Publicly Accessible
  • 2.1 Ensure That Cloud Audit Logging Is Configured Properly
  • 2.12 Ensure That Cloud DNS Logging Is Enabled for All VPC Networks
  • 2.13 Ensure Cloud Asset Inventory Is Enabled
  • 2.2 Ensure That Sinks Are Configured for All Log Entries
  • 2.4 Ensure Log Metric Filter and Alerts Exist for Project Ownership Assignments/Changes
  • 2.5 Ensure That the Log Metric Filter and Alerts Exist for Audit Configuration Changes
  • 2.6 Ensure That the Log Metric Filter and Alerts Exist for Custom Role Changes
  • 3.3 Ensure That DNSSEC Is Enabled for Cloud DNS
  • 3.4 Ensure That RSASHA1 Is Not Used for the Key-Signing Key in Cloud DNS DNSSEC
  • 3.5 Ensure That RSASHA1 Is Not Used for the Zone-Signing Key in Cloud DNS DNSSEC
  • 3.9 Ensure No HTTPS or SSL Proxy Load Balancers Permit SSL Policies With Weak Cipher Suites
  • 4.1 Ensure That Instances Are Not Configured To Use the Default Service Account
  • 4.2 Ensure That Instances Are Not Configured To Use the Default Service Account With Full Access to All Cloud APIs
  • 4.3 Ensure \"Block Project-Wide SSH Keys\" Is Enabled for VM Instances
  • 4.4 Ensure Oslogin Is Enabled for a Project
  • 4.5 Ensure 'Enable Connecting to Serial Ports' Is Not Enabled for VM Instance
  • 4.6 Ensure That IP Forwarding Is Not Enabled on Instances
  • 5.1 Ensure That Cloud Storage Bucket Is Not Anonymously or Publicly Accessible
  • 6.1.1 Ensure That a MySQL Instance Does Not Allow Anyone To Connect With Administrative Privileges
  • 6.1.2 Ensure 'Skip_show_database' Database Flag for Cloud SQL MySQL Instance Is Set to 'On'
  • 6.1.3 Ensure That the 'Local_infile' Database Flag for a Cloud SQL MySQL Instance Is Set to 'Off'
  • 6.2.2 Ensure That the 'Log_connections' Database Flag for Cloud SQL PostgreSQL Instance Is Set to 'On'
  • 6.2.3 Ensure That the 'Log_disconnections' Database Flag for Cloud SQL PostgreSQL Instance Is Set to 'On'
  • 6.2.5 Ensure that the 'Log_min_messages' Flag for a Cloud SQL PostgreSQL Instance is set at minimum to 'Warning'
  • 6.2.6 Ensure 'Log_min_error_statement' Database Flag for Cloud SQL PostgreSQL Instance Is Set to 'Error' or Stricter
  • 6.2.7 Ensure That the 'Log_min_duration_statement' Database Flag for Cloud SQL PostgreSQL Instance Is Set to '-1' (Disabled)
  • 6.2.8 Ensure That 'cloudsql.enable_pgaudit' Database Flag for each Cloud Sql Postgresql Instance Is Set to 'on' For Centralized Logging
  • 6.3.1 Ensure 'external scripts enabled' Database Flag for Cloud SQL SQL Server Instance Is Set to 'off'
  • 6.3.2 Ensure 'cross db ownership chaining' Database Flag for Cloud SQL SQL Server Instance Is Set to 'off'
  • 6.3.3 Ensure 'user Connections' Database Flag for Cloud SQL SQL Server Instance Is Set to a Non-limiting Value
  • 6.3.4 Ensure 'user options' Database Flag for Cloud SQL SQL Server Instance Is Not Configured
  • 6.3.5 Ensure 'remote access' Database Flag for Cloud SQL SQL Server Instance Is Set to 'off'
  • 6.3.6 Ensure '3625 (trace flag)' Database Flag for all Cloud SQL SQL Server Instances Is Set to 'on'
  • 6.3.7 Ensure 'contained database authentication' Database Flag for Cloud SQL SQL Server Instance Is Set to 'off'
  • 6.4 Ensure That the Cloud SQL Database Instance Requires All Incoming Connections To Use SSL
  • 6.5 Ensure That Cloud SQL Database Instances Do Not Implicitly Whitelist All Public IP Addresses
  • 6.7 Ensure That Cloud SQL Database Instances Are Configured With Automated Backups
  • 7.1 Ensure That BigQuery Datasets Are Not Anonymously or Publicly Accessible
Miscellaneous
  • Audit deprecated.
  • Metadata updated.
  • References updated.