More Info:

Ensures that logging and log alerts exist for project ownership assignments and changes. Project Ownership is the highest level of privilege on a project, any changes in project ownership should be heavily monitored to prevent unauthorized changes.

Risk Level

High

Address

Security

Compliance Standards

CISGCP, CBP, HIPAA, ISO27001, HITRUST

Triage and Remediation

Remediation

To remediate the misconfiguration “Project Ownership Change Log Alerts Should Be Enabled” for GCP using GCP console, follow the below steps:

  1. Login to the GCP console.
  2. Navigate to the “Logging” section from the left-hand menu.
  3. In the “Logging” section, click on “Logs Explorer”.
  4. In the “Logs Explorer” page, select the “Resource” dropdown and select the project for which you want to enable the ownership change log alerts.
  5. In the search bar, type “project ownership change” and press enter.
  6. From the search results, select “Admin Activity” and then select “Project Ownership Change”.
  7. Click on “Create Metric” and give a name to the metric.
  8. Click on “Create Alert” and configure the alert as per your requirement.
  9. Click on “Save” to save the alert configuration.

By following the above steps, you will be able to enable the “Project Ownership Change Log Alerts” for the selected project in GCP.

Additional Reading: