Ensure that Cloud Asset Inventory is enabled for all your GCP projects in order to efficiently manage the history and the inventory of your cloud resources. Google Cloud Asset Inventory is a fully managed metadata inventory service that allows you to view, monitor, analyze, and gain insights for your Google Cloud and Anthos assets. Cloud Asset Inventory is disabled by default in each GCP project.
This rule resolution is part of the Conformity Security & Compliance tool for GCP.
Gaining insight into Google Cloud resources and policies is vital for tasks such as DevOps, security analytics, multi-cluster and fleet management, auditing, and governance. With Cloud Asset Inventory you can discover, monitor, and analyze all GCP assets in one place, achieving a better understanding of all your cloud assets across projects and services.
Audit
To determine if Google Cloud Asset Inventory is enabled for your GCP projects, perform the following operations:
Remediation / Resolution
To enable Google Cloud Asset Inventory for all your GCP projects, perform the following operations:
References
- Google Cloud Platform (GCP) Documentation
- Cloud Asset Inventory
- Cloud Asset Inventory documentation
- Cloud Asset API
- CIS Security Documentation
- Securing Google Cloud Computing Platform
- GCP Command Line Interface (CLI) Documentation
- gcloud projects list
- gcloud services list
- gcloud services enable