More Info:

Compute instances should not be configured to have external IP addresses.

Risk Level

High

Address

Security

Compliance Standards

CISGCP, CBP, SOC2, ISO27001, HITRUST, NISTCSF, PCIDSS, FedRAMP

Triage and Remediation

Remediation

To remediate the misconfiguration “Compute Instances Should Not Have Public IPs” in GCP using GCP console, please follow the below steps:

  1. Login to GCP console (https://console.cloud.google.com/).
  2. In the navigation menu, click on “Compute Engine”.
  3. Click on “VM instances”.
  4. Select the instance for which you want to remove the public IP.
  5. Click on “Edit” button at the top of the page.
  6. Scroll down to the “Network interfaces” section.
  7. Under “External IP”, select “None” from the dropdown menu.
  8. Click on “Save” to save the changes.

Once the changes are saved, the public IP will be removed from the instance and it will no longer be accessible publicly.