CloudCompliance

Google Cloud SCC and organization policies

On Google Cloud, organization policies prevent the most common findings before they happen, and the security command console reports what slips through. Set the constraints first.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

Set a baseline of organization policy constraints at the organization node, enable the security command console (Security Command Center) with Security Health Analytics, and triage its findings on a schedule. The Standard tier is enough configuration evidence for most first audits. Premium and Enterprise add threat detection, attack path analysis and compliance reports, with usage-based pricing that should be checked against your estate.

Organization policy constraints

Constraints are preventive: a resource that breaks one cannot be created. Google publishes a set of recommended secure defaults, and newer organizations get several enforced automatically. Check which apply to yours.

Constraints that map to common audit controls
ConstraintControl it supports
iam.disableServiceAccountKeyCreationNo long-lived credentials
iam.allowedPolicyMemberDomainsAccess only for your own identities
gcp.resourceLocationsData residency
storage.publicAccessPreventionNo public data
storage.uniformBucketLevelAccessConsistent bucket access control
sql.restrictPublicIpDatabases not exposed
compute.requireOsLoginInstance access tied to identity and logged
compute.vmExternalIpAccessNo public IPs on instances except where listed

Evidence is the constraint configuration at the organization or folder plus, ideally, a log entry showing a denied attempt.

The security command console

Tiers and what they add
TierIncludesUse for
StandardSecurity Health Analytics (a subset of detectors), web security scanning basicsConfiguration findings for a first audit
PremiumAll Security Health Analytics detectors, Event Threat Detection, compliance reports mapped to CIS, PCI DSS, NIST SP 800-53, ISO 27001Threat detection and framework reporting
EnterpriseMulti-cloud coverage and security operations featuresLarge or multi-cloud estates

Whatever the tier, findings only become evidence when there is a record of what was done. Use finding state and muting with notes, and export findings to a ticket system for anything high or critical.

Other Google Cloud evidence sources

Cloud Asset Inventory
Point-in-time and historical inventory of resources and IAM policies, exportable to BigQuery. Good for access reviews and asset lists.
IAM Recommender
Shows unused permissions per principal over 90 days. Useful evidence of least privilege work.
Policy Intelligence
Policy Analyzer answers "who can access this resource", which is often the exact auditor question.
Assured Workloads
Enforces controls for specific regulatory regimes and data locations. Check whether a Canadian option fits your needs before relying on it.
Is Security Command Center free?

The Standard tier is included at no additional charge. Premium and Enterprise are priced on usage. A first audit rarely needs more than Standard plus organization policies and good logging.

Can organization policies be overridden in a project?

Only if the policy allows inheritance to be overridden and the person has the organization policy administrator role. Keep that role restricted and alert on policy changes so a local override is visible.

Does Google Cloud have an equivalent of AWS Config?

Cloud Asset Inventory provides resource and IAM history, and Security Health Analytics evaluates configuration against detectors. Together they cover what Config and Security Hub cover on AWS.

Need a Google Cloud baseline set up?

Firms in the network set constraints, logging and triage before the audit.

Get matched