5.10.5 Enable Cloud Security Command Center (Cloud SCC)

Information

Enable Cloud Security Command Center (Cloud SCC) to provide a centralized view of security for your GKE clusters.

Rationale:

Cloud Security Command Center (Cloud SCC) is the canonical security and data risk database for GCP. Cloud SCC enables you to understand your security and data attack surface by providing asset inventory, discovery, search, and management.

Impact:

None.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Note: The Security Command Center Asset APIs have been deprecated, pending removal on or after 26th June 2024. Cloud Asset Inventory should be used instead.
Follow the instructions at: https://cloud.google.com/security-command-center/docs/quickstart-scc-setup.

Default Value:

By default, Cloud SCC is disabled.

See Also

https://workbench.cisecurity.org/benchmarks/13178

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv7|5.5

Plugin: GCP

Control ID: 05759c6a9af03e1076789b3f73f2ef5db0ec6236e3ff15909fc4d89a5eb344bc