More Info:

Ensures that logging and log alerts exist for SQL configuration changes. Project Ownership is the highest level of privilege on a project, any changes in SQL configurations should be heavily monitored to prevent unauthorized changes.

Risk Level

Medium

Address

Security

Compliance Standards

CISGCP, CBP, HIPAA, ISO27001, HITRUST, SOC2, NISTCSF, PCIDSS

Triage and Remediation

Remediation

To remediate the misconfiguration “SQL Configuration Change Log Alerts Should Be Enabled” in GCP, follow these steps:

  1. Go to the GCP Console and select the project that has the SQL instance that needs to be configured.

  2. Navigate to the SQL Instances page by clicking on the “SQL” option in the left-hand menu.

  3. Select the SQL instance that needs to be configured.

  4. Click on the “Edit” button at the top of the page.

  5. Scroll down to the “Alerting and Monitoring” section.

  6. In the “Alerting and Monitoring” section, enable the “Configuration changes” option.

  7. Click on the “Save” button at the bottom of the page to save the changes.

Once you have completed these steps, the SQL Configuration Change Log Alerts will be enabled for your SQL instance in GCP.

Additional Reading: