More Info:

Ensures that logging and log alerts exist for firewall rule changes.

Risk Level

Low

Address

Security

Compliance Standards

CISGCP, CBP, HIPAA, ISO27001, HITRUST, SOC2, NISTCSF, PCIDSS

Triage and Remediation

Remediation

To remediate the misconfiguration “Firewall Change Log Alerts Should Be Enabled” for GCP using GCP console, follow the below steps:

  1. Login to your GCP console.
  2. Navigate to the Security Command Center.
  3. Click on the “Security Health Analytics” option from the left-hand menu.
  4. Click on the “Firewall rules” option.
  5. Select the project for which you want to enable Firewall Change Log Alerts.
  6. Click on the “Edit” button.
  7. Scroll down to the “Logging” section and enable the “Firewall Change Log” option.
  8. Click on the “Save” button to save the changes.

By following the above steps, you have successfully enabled the Firewall Change Log Alerts for the selected project in GCP. This will help you to track any changes made to the firewall rules and take necessary actions in case of any unauthorized changes.

Additional Reading: