More Info:

Cloud CDN global backend services should have request logging enabled. Logging requests to Cloud CDN endpoints is a helpful way of detecting and investigating potential attacks.

Risk Level

Low

Address

Security, Operational Maturity

Compliance Standards

GDPR, HITRUST, SOC2, NISTCSF, PCIDSS

Triage and Remediation

Remediation

To remediate the misconfiguration of “Cloud CDN Global Backend Services Should Have Logging Enabled” for GCP using GCP console, please follow the below steps:

  1. Open the Google Cloud Console and select the project where the Cloud CDN is configured.
  2. Select the “Navigation menu” on the top-left corner of the console and navigate to “Networking” -> “Cloud CDN”.
  3. Click on the name of the backend service that you want to remediate.
  4. In the backend service details page, click on the “Edit” button at the top of the page.
  5. Scroll down to the “Logging” section and click on the “Enable logging” checkbox.
  6. Select the “Cloud Storage bucket” where you want to store the logs.
  7. Choose a “Log format” from the drop-down list. You can choose either “JSON” or “Legacy”.
  8. Click on the “Save” button to save the changes.

Once the changes are saved, the Cloud CDN global backend service will have logging enabled, and the logs will be stored in the specified Cloud Storage bucket.

Additional Reading: