More Info:

Ensure Cloud Monitoring monitors storage ACL operations count.

Risk Level

Medium

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the misconfiguration of not monitoring Storage ACL Operations Count in GCP using GCP console, please follow the below steps:

  1. Open the GCP console and select the desired project in which the storage bucket is located.
  2. Navigate to the Cloud Storage section from the left-hand menu.
  3. Select the storage bucket for which you want to enable monitoring of ACL operations count.
  4. Click on the “Edit bucket permissions” button located at the top of the page.
  5. In the “Bucket Permissions” section, click on the “Add members” button.
  6. Enter the email address of the user or service account that will be responsible for monitoring the Storage ACL Operations Count.
  7. Select the “Storage Legacy Bucket Reader” role from the “Select a role” dropdown menu.
  8. Click on the “Add” button to add the user or service account to the bucket permissions.
  9. Once the user or service account has been added, navigate to the “Monitoring” section of the storage bucket.
  10. In the “Monitoring” section, click on the “Create Policy” button.
  11. Enter a name for the policy and select the “Metric” option.
  12. In the “Filter” section, select the “Storage > Bucket” option from the dropdown menu.
  13. Select the storage bucket for which you want to monitor the ACL operations count.
  14. In the “Condition” section, select the “Metric Threshold” option.
  15. Set the threshold value for the ACL operations count and select the time interval for which you want to monitor the metric.
  16. Click on the “Save” button to save the policy.

By following these steps, you will be able to remediate the misconfiguration of not monitoring Storage ACL Operations Count in GCP using GCP console.

Additional Reading: