More Info:

Ensure that Cloud SQL System Event Audit Logging is configured properly across all projects.

Risk Level

Medium

Address

Security

Compliance Standards

HITRUST, SOC2, NISTCSF, PCIDSS, CISGCP, CBP, HIPAA, ISO27001

Triage and Remediation

Remediation

To remediate the misconfiguration “Cloud SQL System Event Audit Logging Should Be Enabled” in GCP using GCP console, you can follow the below steps:

  1. Open the GCP Console and navigate to the Cloud SQL instances page.

  2. Select the instance for which you want to enable audit logging.

  3. Click on the “Edit” button at the top of the page.

  4. Scroll down to the “Data Access” section and click on “Advanced Configuration”.

  5. Under “Audit Configuration”, select the checkbox for “System Event Audit Logs”.

  6. Click on the “Save” button at the bottom of the page to apply the changes.

  7. Verify that the audit logging is enabled by checking the “Audit Logs” tab in the Cloud SQL instance details page.

By following these steps, you can remediate the misconfiguration “Cloud SQL System Event Audit Logging Should Be Enabled” in GCP using GCP console.

Additional Reading: