Google Cloud SCC and organization policies
On Google Cloud, organization policies prevent the most common findings before they happen, and the security command console reports what slips through. Set the constraints first.
Set a baseline of organization policy constraints at the organization node, enable the security command console (Security Command Center) with Security Health Analytics, and triage its findings on a schedule. The Standard tier is enough configuration evidence for most first audits. Premium and Enterprise add threat detection, attack path analysis and compliance reports, with usage-based pricing that should be checked against your estate.
Organization policy constraints
Constraints are preventive: a resource that breaks one cannot be created. Google publishes a set of recommended secure defaults, and newer organizations get several enforced automatically. Check which apply to yours.
| Constraint | Control it supports |
|---|---|
iam.disableServiceAccountKeyCreation | No long-lived credentials |
iam.allowedPolicyMemberDomains | Access only for your own identities |
gcp.resourceLocations | Data residency |
storage.publicAccessPrevention | No public data |
storage.uniformBucketLevelAccess | Consistent bucket access control |
sql.restrictPublicIp | Databases not exposed |
compute.requireOsLogin | Instance access tied to identity and logged |
compute.vmExternalIpAccess | No public IPs on instances except where listed |
Evidence is the constraint configuration at the organization or folder plus, ideally, a log entry showing a denied attempt.
The security command console
| Tier | Includes | Use for |
|---|---|---|
| Standard | Security Health Analytics (a subset of detectors), web security scanning basics | Configuration findings for a first audit |
| Premium | All Security Health Analytics detectors, Event Threat Detection, compliance reports mapped to CIS, PCI DSS, NIST SP 800-53, ISO 27001 | Threat detection and framework reporting |
| Enterprise | Multi-cloud coverage and security operations features | Large or multi-cloud estates |
Whatever the tier, findings only become evidence when there is a record of what was done. Use finding state and muting with notes, and export findings to a ticket system for anything high or critical.
Other Google Cloud evidence sources
- Cloud Asset Inventory
- Point-in-time and historical inventory of resources and IAM policies, exportable to BigQuery. Good for access reviews and asset lists.
- IAM Recommender
- Shows unused permissions per principal over 90 days. Useful evidence of least privilege work.
- Policy Intelligence
- Policy Analyzer answers "who can access this resource", which is often the exact auditor question.
- Assured Workloads
- Enforces controls for specific regulatory regimes and data locations. Check whether a Canadian option fits your needs before relying on it.
Is Security Command Center free?
The Standard tier is included at no additional charge. Premium and Enterprise are priced on usage. A first audit rarely needs more than Standard plus organization policies and good logging.
Can organization policies be overridden in a project?
Only if the policy allows inheritance to be overridden and the person has the organization policy administrator role. Keep that role restricted and alert on policy changes so a local override is visible.
Does Google Cloud have an equivalent of AWS Config?
Cloud Asset Inventory provides resource and IAM history, and Security Health Analytics evaluates configuration against detectors. Together they cover what Config and Security Hub cover on AWS.
Need a Google Cloud baseline set up?
Firms in the network set constraints, logging and triage before the audit.
Get matched