More Info:

Ensure that BigQuery User Activity Audit Logging is configured properly across all projects.

Risk Level

Medium

Address

Security

Compliance Standards

CISGCP, CBP, GDPR, HIPAA, ISO27001

Triage and Remediation

Remediation

To remediate the misconfiguration “GCP BigQuery Should Have User Activity Logging Enabled” for GCP using GCP console, follow the below steps:

  1. Open the GCP console and navigate to the BigQuery service.

  2. Click on the “Navigation Menu” icon on the top-left corner of the console.

  3. From the menu, select “BigQuery”.

  4. In the BigQuery console, click on the “Settings” icon on the left-hand side panel.

  5. Click on the “Audit logs” tab.

  6. Under the “Audit logs” tab, click on the “Configure” button.

  7. In the “Configure audit logs” window, select the checkbox next to “Data access”.

  8. Select the checkbox next to “Cloud audit logs”.

  9. Click on the “Save” button.

  10. Once the configuration is saved, the user activity logging for BigQuery is enabled.

Note: It is recommended to create a log sink to export the logs to a centralized logging system for further analysis.

Additional Reading: