More Info:

Ensure that all the Google Cloud APIs and services restricted within your organization are defined using the “Restrict allowed Google Cloud APIs and services” organization policy. This constraint policy helps you achieve regulatory compliance by defining the set of cloud services and APIs that cannot be used within your GCP organization.

Risk Level

Medium

Address

Security, Operational Maturity

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the misconfiguration of “Restrict Allowed Google Cloud APIs and Services” in GCP using the GCP console, please follow the below steps:

Step 1: Login to your Google Cloud Platform console.

Step 2: Select the project you want to remediate the misconfiguration for.

Step 3: Click on the Navigation menu, go to the “IAM & Admin” section, and select “IAM”.

Step 4: In the IAM page, select the role for which you want to restrict the allowed APIs and services.

Step 5: Click on the “Edit” button next to the selected role.

Step 6: Scroll down to the “Permissions” section and click on the “Add Condition” button.

Step 7: In the “Add Condition” dialog box, select the “APIs & Services” option from the dropdown menu.

Step 8: In the “APIs & Services” section, select the “APIs” tab and select the APIs and services you want to allow.

Step 9: Click on the “Save” button to apply the changes.

Step 10: Verify that the allowed APIs and services are restricted by checking the IAM page for the role you modified.

By following these steps, you can remediate the misconfiguration of “Restrict Allowed Google Cloud APIs and Services” in GCP using the GCP console.