More Info:

Ensure that retention policies on log buckets are configured using Bucket Locks.

Risk Level

Low

Address

Security

Compliance Standards

CISGCP, CBP

Triage and Remediation

Remediation

Sure, I can help you with that. Here are the step-by-step instructions to remediate the misconfiguration “Log Buckets Should Have Retention Policies” in GCP using the GCP console:

  1. Open the GCP Console in your web browser and log in to your account.
  2. Navigate to the Cloud Storage section by clicking on the hamburger menu (☰) in the top-left corner of the console, then selecting “Storage” and “Browser” from the dropdown menu.
  3. Locate the log bucket that needs to have a retention policy added.
  4. Click on the name of the bucket to open its details page.
  5. Click on the “Edit bucket retention” button located in the “Bucket metadata” section.
  6. In the “Retention period” section, select the desired retention period for the logs. You can choose a custom period or select from the predefined options.
  7. Click on the “Save” button to apply the retention policy to the bucket.

Once you have completed these steps, the log bucket will have a retention policy applied to it, which will help ensure that logs are retained for the appropriate amount of time.