More Info:

Service account keys should be managed by Google to ensure that they are as secure as possible, including key rotations and restrictions to the accessibility of the keys.

Risk Level

High

Address

Security

Compliance Standards

CISGCP, CBP, HIPAA, ISO27001

Triage and Remediation

Remediation

To remediate the misconfiguration “Keys Should Be Managed By Google” in GCP, follow the below steps using GCP console:

  1. Open the GCP Console and navigate to the project for which you want to remediate the misconfiguration.
  2. Click on the “IAM & Admin” option in the left-hand menu.
  3. Click on the “Service Accounts” tab.
  4. Select the service account for which you want to remediate the misconfiguration.
  5. Click on the “Edit” button at the top of the page.
  6. Scroll down to the “Keys” section.
  7. Click on the “Delete” button next to any existing keys that are not managed by Google.
  8. Click on the “Create Key” button.
  9. Select the “JSON” key type.
  10. Click on the “Create” button.

By following these steps, you have now remediated the misconfiguration “Keys Should Be Managed By Google” in GCP by deleting any existing keys that are not managed by Google and creating a new key that is managed by Google.