Ensure that Essential Contacts are configured at the GCP organization level to designate email addresses for cloud services in order to notify of important technical and/or security information. Essential Contacts are inherited through the GCP resource hierarchy, making them available for all the folders and projects in your organization.
This rule resolution is part of the Conformity Security & Compliance tool for GCP.
optimisation
excellence
efficiency
Google Cloud Platform (GCP) services, such as Cloud Billing, send out billing notifications to share important information with the cloud platform users. By default, these types of notifications are sent to members with certain Identity and Access Management (IAM) roles such as "roles/owner" and "roles/billing.admin". With Essential Contacts, you can specify exactly who receives important notifications by providing your own list of contacts (i.e. email addresses).
Audit
To determine if the Essential Contacts are configured for your GCP organization, perform the following operations:
Remediation / Resolution
To define essential contacts for your GCP organization in order to receive critical notifications, perform the following operations:
References
- Google Cloud Platform (GCP) Documentation
- Viewing and managing organization resources
- Managing contacts for notifications
- CIS Security Documentation
- Securing Google Cloud Computing Platform
- GCP Command Line Interface (CLI) Documentation
- gcloud organizations list
- gcloud beta essential-contacts list
- gcloud beta essential-contacts create