More Info:

Serial ports connection should not be enabled for VM instances. As serial console does not allow restricting IP Addresses, so then it allows any IP address to connect to instance and should therefore be disabled.

Risk Level

Low

Address

Security

Compliance Standards

CISGCP, CBP, HITRUST, SOC2, NISTCSF, PCIDSS

Triage and Remediation

Remediation

To remediate the misconfiguration “Serial Ports Connection Should Be Disabled” for GCP using GCP console, you can follow the below steps:

  1. Login to the GCP console.

  2. Select the project in which you want to remediate the misconfiguration.

  3. Click on the “Compute Engine” option from the left-hand side menu.

  4. Select the instance for which you want to disable the serial port connection.

  5. Click on the “Edit” button at the top of the page.

  6. Scroll down to the “Cloud API access scopes” section.

  7. In the “Cloud API access scopes” section, click on the “Allow full access to all Cloud APIs” option to expand it.

  8. Uncheck the “Enable connecting to serial ports” option.

  9. Click on the “Save” button at the bottom of the page to apply the changes.

  10. Once the changes are applied, the serial port connection will be disabled for the selected instance.

By following the above steps, you can remediate the misconfiguration “Serial Ports Connection Should Be Disabled” for GCP using GCP console.

Additional Reading: