More Info:

Ensure Cloud Monitoring monitors IAM key authentication events count

Risk Level

Medium

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the misconfiguration of not monitoring IAM Key Authentication Events Count in GCP, you can follow the below steps using the GCP console:

  1. Open the GCP console and navigate to the Security Command Center.

  2. Click on the “Security Health Analytics” tab on the left-hand side of the screen.

  3. Under the “Security Health Analytics” tab, click on the “Security Health Analytics Findings” option.

  4. In the “Findings” section, search for the finding “IAM Key Authentication Events Count Not Monitored”.

  5. Click on the finding to view the details.

  6. In the details section, click on the “Remediation Steps” tab.

  7. Follow the recommended remediation steps to enable monitoring of IAM Key Authentication Events Count.

  8. The recommended remediation steps include creating a new custom dashboard in the GCP console, adding a widget to the dashboard to monitor IAM Key Authentication Events Count, and configuring the widget to display the count of authentication events.

  9. Once the remediation steps are completed, the finding for “IAM Key Authentication Events Count Not Monitored” should be resolved in the Security Health Analytics section.

By following these steps, you can remediate the misconfiguration of not monitoring IAM Key Authentication Events Count in GCP using the GCP console.

Additional Reading: