1.2 Ensure that Multi-Factor Authentication is 'Enabled' for All Non-Service Accounts

Information

Setup multi-factor authentication for Google Cloud Platform accounts.

Multi-factor authentication requires more than one mechanism to authenticate a user. This secures user logins from attackers exploiting stolen or weak credentials.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

From Google Cloud Console

For each Google Cloud Platform project:

-

Identify non-service accounts.

-

Setup multi-factor authentication for each account.

See Also

https://workbench.cisecurity.org/benchmarks/17308

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2(1), 800-53|IA-2(2), CSCv7|16.3

Plugin: GCP

Control ID: e5c6c42dab1f151a5dfce3dcc38712fa6052bd995c529d3ec9f10ad442a4b3d2