More Info:

Ensure Dataflow jobs worker ip is not public

Risk Level

Critical

Address

Security

Compliance Standards

CBP, CISGCP, HITRUST, SOC2, GDPR, NISTCSF, PCIDSS

Triage and Remediation

Remediation

To remediate the misconfiguration “Dataflow Worker IP should not be public” in GCP, you can follow the below steps using GCP console:

  1. Go to the GCP console and navigate to the Dataflow Workers page.
  2. Select the worker pool that you want to update.
  3. Click on the “Edit” button.
  4. In the “Network settings” section, select the “Private” option for the “Worker IP” setting.
  5. Click on the “Save” button to save the changes.

By selecting the “Private” option, the Dataflow worker IP will not be exposed to the public internet. This will help to ensure the security of your Dataflow jobs and prevent unauthorized access.