More Info:

Ensure that “Disable VM serial port access” constraint policy is enabled for your Google Cloud Platform (GCP) organizations. Due to security and compliance regulations, the serial port access to your Compute Engine virtual machine (VM) instances must be disabled.

Risk Level

Medium

Address

Security, Operational Maturity

Compliance Standards

CISGCP, CBP

Triage and Remediation

Remediation

To remediate the “Disable Serial Port Access Support at Organization Level” misconfiguration in GCP using the GCP console, follow these steps:

  1. Open the GCP console and navigate to the “IAM & Admin” section.
  2. Click on “Organization” and select your organization from the dropdown menu.
  3. Click on the “Policies” tab and scroll down to the “Compute Engine” section.
  4. Locate the policy for “Serial Port Access” and click on the “Edit” button next to it.
  5. In the policy editor, select “Deny” for the “SerialPortAccess” permission.
  6. Click on “Save” to update the policy.

This will disable Serial Port Access Support at the organization level in GCP. Note that this change may take some time to propagate across all resources in your organization.