{"id":22803,"date":"2022-04-19T17:49:17","date_gmt":"2022-04-19T15:49:17","guid":{"rendered":"https:\/\/www.makingscience.com\/?p=22803"},"modified":"2022-04-19T17:49:17","modified_gmt":"2022-04-19T15:49:17","slug":"google-cloud-platform-security-command-centre","status":"publish","type":"post","link":"https:\/\/www.makingscience.com\/en\/blog\/google-cloud-platform-security-command-centre\/","title":{"rendered":"Gain centralised visibility and control over your cloud&#8217;s infrastructure with Google Cloud Platform Security Command Centre"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">When migrating your infrastructure to the cloud, one of your main concerns can be: is the cloud secure? And how can I maintain control of all that happens in my cloud infrastructure?\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Hopefully, Google Cloud Platform\u2019s Security Command Center is here to help answer those questions on centralising the visualisation of all your organisation\u2019s assets and their possible vulnerabilities or misconfiguration.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">You have to activate the Security Command Center in your organisation with an account with a few privileged roles in order to start using it. Luckily you can try the standard tier free of charge.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">We want to highlight some of the several useful features this standard tier comprises, like:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security Health Analytics scans Google Cloud assets looking for vulnerabilities and misconfigurations like:<\/span>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">MFA is not active for an account (we know how risky this is in a privileged account)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Members outside the organisation have access to resources as they are included in a group with permissions.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Dangerous open ports in the perimetral firewall.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Public buckets to the internet and many more.<\/span><\/li>\n<\/ul>\n<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">With predefined rules against the most common attacks and the possibility to create custom rules like IP filtering, Cloud Armor acts as a WAF, adding another layer of security to all your deployments. We love and use this feature profusely in all our website deployments, and the Security Command Center helps us visualise all the incidents detected by it and to adapt our rules accordingly.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">You can detect security anomalies in your VMs like potentially leaked credentials and crypto mining.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">All this information can be exported to BigQuery or your favourite third-party SIEM to be processed.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Please check the official documentation for a more detailed rundown of all the features.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">There are additional features in the Security Command Center premium tier, such as:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Container Threat Detection: this service continuously monitors the state of the deployed container images, alerting if there was an added binary to the image that was not in the original one or the execution of malicious scripts or reverse shells.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Using threat intelligence and machine learning, Malware, brute force ssh and outgoing DoS anomalies are added to the Event Threat Detection. It also detects changes to MFA, SSO, or leaked passwords to the user&#8217;s account protection.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">One of this tier\u2019s big features is the possibility to create compliance dashboards and reports following the most used standards in the industry like CIS, NIST, PCI or ISO27001. You can view and export those compliance reports to help ensure all your resources meet their compliance requirements.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">If you enable VM Manager, you can detect vulnerabilities in the operating systems installed on Compute Engine virtual machines.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Create SMS alerts, mails, or to your favourite chat application with Pub\/Sub notifications.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">We use the Security Command Center extensively for its defensive security features like Cloud Armor and its health monitoring of the organisation\u2019s users and assets, but we are integrating more of its features as we discover its real potential.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Here we have just detailed some of the capabilities of the Security Command Center, but there are many more that can suit your specific needs. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you would like to find out more information on Google Cloud Platform Security Command Centre and how it can help your business, get in touch with us at info@makingscience.com.\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>When migrating your infrastructure to the cloud, one of your main concerns can be: is the cloud secure? And how can I maintain control of all that happens in my cloud infrastructure?\u00a0 Hopefully, Google Cloud Platform\u2019s Security Command Center is here to help answer those questions on centralising the visualisation of all your organisation\u2019s assets [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":22804,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[848],"tags":[],"class_list":["post-22803","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-google-cloud-en"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.makingscience.com\/en\/wp-json\/wp\/v2\/posts\/22803","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.makingscience.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.makingscience.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.makingscience.com\/en\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.makingscience.com\/en\/wp-json\/wp\/v2\/comments?post=22803"}],"version-history":[{"count":0,"href":"https:\/\/www.makingscience.com\/en\/wp-json\/wp\/v2\/posts\/22803\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.makingscience.com\/en\/wp-json\/wp\/v2\/media\/22804"}],"wp:attachment":[{"href":"https:\/\/www.makingscience.com\/en\/wp-json\/wp\/v2\/media?parent=22803"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.makingscience.com\/en\/wp-json\/wp\/v2\/categories?post=22803"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.makingscience.com\/en\/wp-json\/wp\/v2\/tags?post=22803"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}