More Info:

Ensure Cloud Monitoring monitors storage object specific ACL mutation count.

Risk Level

Medium

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the misconfiguration “Cloud Monitoring Should Monitor Storage Object Specific ACL Mutation Count” for GCP using the GCP console, follow the steps below:

  1. Log in to your GCP console and navigate to the Cloud Storage page.

  2. Click on the bucket that you want to monitor.

  3. Click on the “Permissions” tab.

  4. Review the current IAM policies and ensure that only authorized users or groups have access to the bucket.

  5. Click on the “Edit Bucket Permissions” button.

  6. Remove any unnecessary or unauthorized users or groups from the IAM policies.

  7. Click on the “Add Members” button to add authorized users or groups to the IAM policies.

  8. Set the appropriate permissions for each user or group.

  9. Click on the “Save” button to save the changes.

  10. Navigate to the Cloud Monitoring page.

  11. Click on the “Uptime Checks” tab.

  12. Click on the “Create Uptime Check” button.

  13. Select “Cloud Storage” as the resource type.

  14. Enter the bucket name and select the appropriate region.

  15. Set the check interval and timeout values.

  16. Click on the “Next” button.

  17. Set the alerting policy for the uptime check.

  18. Click on the “Create” button to create the uptime check.

  19. Test the uptime check to ensure that it is monitoring the bucket’s ACL mutation count.

By following these steps, you can remediate the misconfiguration “Cloud Monitoring Should Monitor Storage Object Specific ACL Mutation Count” for GCP using the GCP console.

Additional Reading: