Ensure that the Integrity Monitoring feature is enabled for your Google Cloud Vertex AI notebook instances to automatically check and monitor the runtime boot integrity of your shielded notebook instances using Google Cloud Monitoring. The feature requires Virtual Trusted Platform Module (vTPM).
This rule resolution is part of the Conformity Security & Compliance tool for GCP.
Integrity Monitoring enables monitoring and attestation of the boot integrity for Vertex AI notebook instances. The attestation is performed against the integrity policy baseline. This baseline is initially derived from the implicitly trusted boot image when the instance is created. To protect your application data and ensure that the boot loader on your instances remains untampered, it is strongly recommended to enable Integrity Monitoring for your Vertex AI notebook instances.
Audit
To determine if Integrity Monitoring is enabled for your Vertex AI notebook instances, perform the following operations:
Remediation / Resolution
To enable the Integrity Monitoring feature for your Google Cloud Vertex AI notebook instances, perform the following operations:
Enabling Integrity Monitoring for Vertex AI notebook instances using Google Cloud Platform (GCP) console is not currently supported.References
- Google Cloud Platform (GCP) Documentation
- Shielded VMs
- What is Shielded VM?
- Introduction to Vertex AI Workbench
- GCP Command Line Interface (CLI) Documentation
- gcloud projects list
- gcloud workbench instances list
- gcloud workbench instances describe
- gcloud workbench instances stop
- gcloud workbench instances update
- gcloud workbench instances start