{"_id":"@cloudgraph/policy-pack-gcp-cis-1.3.0","_rev":"3-179ea8f60bf83f2854112e8d55696447","name":"@cloudgraph/policy-pack-gcp-cis-1.3.0","dist-tags":{"alpha":"1.0.1-alpha.2","latest":"1.0.0"},"versions":{"1.0.0-alpha.1":{"name":"@cloudgraph/policy-pack-gcp-cis-1.3.0","description":"Policy pack implementing CIS Google Cloud Platform Foundations 1.3.0 Benchmark","version":"1.0.0-alpha.1","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/gcp/cis-1.2.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.4.0","@types/node":"^17.0.8","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.5.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true,"arrowParens":"avoid"},"scripts":{"build":"npm run prepack","clean":"rm -rf dist","lint":"eslint","prepack":"pnpm clean && tsc -b","test":"NODE_ENV=test jest","release":"npx semantic-release --no-ci -e semantic-release-monorepo"},"gitHead":"f678507319344b9b8a8a22e097197786a2001a85","_id":"@cloudgraph/policy-pack-gcp-cis-1.3.0@1.0.0-alpha.1","_nodeVersion":"18.12.1","_npmVersion":"8.19.3","dist":{"integrity":"sha512-ChkBudj8iohQhXfJgtP04++vtaQeJBtMH3uPJxbMcKqksuRg7hwSGe2p9rtBu91T6IEzSlZWiZPbUyjDlD8acA==","shasum":"f8c8958dd5fa2c3123e316c50c5ad4e17e9a7d1b","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-gcp-cis-1.3.0/-/policy-pack-gcp-cis-1.3.0-1.0.0-alpha.1.tgz","fileCount":157,"unpackedSize":378619,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHzFsgLV7Q291OnW7yDD7IoO2OcQ39SzNylDzTHVeLEUAiAyjase4qQok3GfyEKL0vKVGzMEvAdVQ5RfJIcX1V47SA=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmRzmACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoVvg/+J0S2WgTNH5dPUR7xP1tLcdZjQKTCeuTO5kpgAL06mIejgP8U\r\neEZQwBpI+iEDo1GbqzFC27l5kVwvgV60OwDrcTKURElWW60WdIuH2JihZgs5\r\nZjIb8ekt7aZk0Si0s0VMY4kyFqSgDebiO078ad+spY8BDdBZuxrVJdi2k6kP\r\n6/39fITPmMhkhfm2xMZGuFrOa+W7wN5LUOIhgj5/cNjAGjZz+FILl3D3GIxy\r\niFkBYPxxCRTKCCVqTRNbgr5BXIt5WFEiCl0H3EpROMNtkiL8gQwJMklURzMZ\r\nLJf7DI0ppXiNO6umWffUJCCkoOP9YHW28qCcC1nTrcukIRObEayHi0xqnW0t\r\nx+bzlUm7rlkMTENFIdbQzHTxW9urIzXFiqVRy777aW0StdB5tMDKZ3scYspe\r\nhf7P8VTR/O2+umUd1jo8h+FvuHU0VNvmGJVzAmxL4zQAxp2c0e4gGimH8fc6\r\nrPHhHLT/AruK9iQXEV26Ippc5LS44gv14jGShc6is82/Tx9Uv5xk7Gvpz/wm\r\nNNXhLHt67q8lt+ypWXtceCokKitxFTSvY4pLBU0oNiVDZXNpPUgCT3T2W9b+\r\nJCiWIOmdDAbyauzva3apzkIRy66iTXdFC0T+pqM3bwvOkpDObXvV614K43dN\r\ncwQWT1VNrrA9ebjVD4iS1Rty8BcK4TDQHI0=\r\n=ZJpL\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-gcp-cis-1.3.0_1.0.0-alpha.1_1670978789938_0.06256254890197344"},"_hasShrinkwrap":false},"1.0.0":{"name":"@cloudgraph/policy-pack-gcp-cis-1.3.0","description":"Policy pack implementing CIS Google Cloud Platform Foundations 1.3.0 Benchmark","version":"1.0.0","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/gcp/cis-1.2.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.4.0","@types/node":"^17.0.8","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.5.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true,"arrowParens":"avoid"},"scripts":{"build":"npm run prepack","clean":"rm -rf dist","lint":"eslint","prepack":"pnpm clean && tsc -b","test":"NODE_ENV=test jest","release":"npx semantic-release --no-ci"},"gitHead":"90dafcdff76b92d6f9612ca5ab5f535826aebad6","_id":"@cloudgraph/policy-pack-gcp-cis-1.3.0@1.0.0","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-MpX6ToePDmHtoS7pGA4AIJX9T9iua07o51AFFXTyx69+JRfVhdRuqHwy6jdlr9OT3xd3cnCqeeMQ3Z4OWB6CmA==","shasum":"e371c165bd82a16e3803b5707cb0c8734e64d72d","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-gcp-cis-1.3.0/-/policy-pack-gcp-cis-1.3.0-1.0.0.tgz","fileCount":173,"unpackedSize":489827,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBg491EePVXKEEs4zU/mhA+8D1q+u94a8+ee3I3mWwFDAiAITV5E8PtnVkhX0fctkbZNTnqK3HOIgLR9pyli+Nruag=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkS/uyACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoQAA//YTFYv6cA7JAQIikfUzROFgqmRYKuOxSW69056Ssr71qfFipZ\r\nKY4LmREJvBzf6pG6hhANqdJxGtSQmAxvDgHQ5CoYYkh0+BDtfC7V0OxSq3Ev\r\nuk802IzB4Z4lFIiHHIf+A+iNmH4XjKh+5LaHi+LPxFWfk7U93NTe3tdeICzY\r\nM/VJCHI6GQ4QYPqxyBPcOQhCF9j3IbtcS9oBZrTM3jwn6ekdxse7Q996Xjc5\r\neIxpX+kViP6TtNpKrfrfgX/XK4Zz7qgv5+2SKG7qEbe1XgTfQZMbpslxU4a+\r\nv53lLIl/CchezceMcdfC/ICl/AWDMn48ZAgU7z6Db9Q9uj6SocewjrnAlP00\r\nBSm8+V+JN2/xrwQ7nBLZ3kaK5VvU8eHUsyojlI/NoxJTzrHHdwXBLeN25v/f\r\noGuYLputUchEhkrQ7awHHPTYDSDGoVTT9u/k7qPuvDmXHqS64iTWNzLAgELs\r\nLIHkjsbCNPa32McmSeYXfqjokeeIPueQI3HAtKoqU1sqEmdvD34Ji1wmD72D\r\nS2M4pJWjkxW9HL2hLb2XlRZ+4+dNcnt4IT7ahnKII2ngoJP2LXscr4tly87s\r\nfmq8QT+mIhr9Z8yKdYhlzPRunYL3M23mU0H1PyJgmaPjIJUHnTEX18gwo8Os\r\nT6yHWfY7H8H/dMlQjfYU0ZLsMlVYI6ObRi4=\r\n=D87e\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-gcp-cis-1.3.0_1.0.0_1682701234035_0.7356603787902871"},"_hasShrinkwrap":false},"1.0.1-alpha.1":{"name":"@cloudgraph/policy-pack-gcp-cis-1.3.0","description":"Policy pack implementing CIS Google Cloud Platform Foundations 1.3.0 Benchmark","version":"1.0.1-alpha.1","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/gcp/cis-1.2.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.4.0","@types/node":"^17.0.8","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.5.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true,"arrowParens":"avoid"},"scripts":{"build":"npm run prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest","release":"npx semantic-release"},"readme":"# CIS Google Cloud Platform Foundations 1.3.0\n\nPolicy Pack based on the GCP Foundations 1.3.0 benchmark provided by the [Center for Internet Security (CIS)](https://www.cisecurity.org/benchmark/google_cloud_computing_platform/)\n\n## First Steps\n\n1. Install [Cloud Graph CLI](https://docs.cloudgraph.dev/quick-start).\n2. Set up the [GCP Provider](https://www.npmjs.com/package/@cloudgraph/cg-provider-gcp) for CG with the `cg init gcp` command.\n3. Add Policy Pack for CIS Google Cloud Platform Foundations benchmark using `cg policy add gcp-cis-1.3.0` command.\n4. Execute the ruleset using the scan command `cg scan gcp`.\n5. Query the findings using the different options:\n\n   5a. Querying findings by provider:\n\n   ```graphql\n   query {\n     querygcpFindings {\n       CISFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n   5b. Querying findings by specific benchmark:\n\n   ```graphql\n   query {\n     querygcpCISFindings {\n       id\n       resourceId\n       result\n     }\n   }\n   ```\n\n   5c. Querying findings by resource:\n\n   ```graphql\n   query {\n     querygcpIamPolicy {\n       id\n       CISFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n## Available Ruleset\n\n| Rule           | Description                                                                                                                                                         |\n| -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| GCP CIS 1.1    | Ensure that corporate login credentials are used                                                                                                                    |\n| GCP CIS 1.2    | Ensure that multi-factor authentication is enabled for all non-service accounts                                                                                     |\n| GCP CIS 1.3    | Ensure that Security Key Enforcement is enabled for all admin accounts                                                                                              |\n| GCP CIS 1.4    | Ensure that there are only GCP-managed service account keys for each service account                                                                                |\n| GCP CIS 1.5    | Ensure that Service Account has no Admin privileges                                                                                                                 |\n| GCP CIS 1.6    | Ensure that IAM users are not assigned the Service Account User or Service Account Token Creator roles at project level                                             |\n| GCP CIS 1.7    | Ensure user-managed/external keys for service accounts are rotated every 90 days or less                                                                            |\n| GCP CIS 1.8    | Ensure that Separation of duties is enforced while assigning service account related roles to users                                                                 |\n| GCP CIS 1.9    | Ensure that Cloud KMS cryptokeys are not anonymously or publicly accessible                                                                                         |\n| GCP CIS 1.10   | Ensure KMS encryption keys are rotated within a period of 90 days                                                                                                   |\n| GCP CIS 1.11   | Ensure that Separation of duties is enforced while assigning KMS related roles to users                                                                             |\n| GCP CIS 1.12   | Ensure API keys are not created for a project                                                                                                                       |\n| GCP CIS 1.13   | Ensure API keys are restricted to use by only specified Hosts and Apps                                                                                              |\n| GCP CIS 1.14   | Ensure API keys are restricted to only APIs that application needs access                                                                                           |\n| GCP CIS 1.15   | Ensure API keys are rotated every 90 days                                                                                                                           |\n| GCP CIS 1.16   | Ensure Essential Contacts is Configured for Organization                                                                                                            |\n| GCP CIS 1.17   | Ensure that Dataproc Cluster is encrypted using CustomerManaged Encryption Key                                                                                      |\n| GCP CIS 1.18   | Ensure Secrets are Not Stored in Cloud Functions Environment Variables by Using Secret Manager                                                                      |\n| GCP CIS 2.1    | Ensure that Cloud Audit Logging is configured properly across all services and all users from a project                                                             |\n| GCP CIS 2.2    | Ensure that sinks are configured for all log entries                                                                                                                |\n| GCP CIS 2.3    | Ensure that retention policies on log buckets are configured using Bucket Lock                                                                                      |\n| GCP CIS 2.4    | Ensure log metric filter and alerts exist for project ownership assignments/changes                                                                                 |\n| GCP CIS 2.5    | Ensure that the log metric filter and alerts exist for Audit Configuration changes                                                                                  |\n| GCP CIS 2.6    | Ensure that the log metric filter and alerts exist for Custom Role changes                                                                                          |\n| GCP CIS 2.7    | Ensure that the log metric filter and alerts exist for VPC Network Firewall rule changes                                                                            |\n| GCP CIS 2.8    | Ensure that the log metric filter and alerts exist for VPC network route changes                                                                                    |\n| GCP CIS 2.9    | Ensure that the log metric filter and alerts exist for VPC network changes                                                                                          |\n| GCP CIS 2.10   | Ensure that the log metric filter and alerts exist for Cloud Storage IAM permission changes                                                                         |\n| GCP CIS 2.11   | Ensure that the log metric filter and alerts exist for SQL instance configuration changes                                                                           |\n| GCP CIS 2.12   | Ensure that Cloud DNS logging is enabled for all VPC networks                                                                                                       |\n| GCP CIS 2.13   | Ensure Cloud Asset Inventory Is Enabled                                                                                                                             |\n| GCP CIS 2.14   | Ensure 'Access Transparency' is 'Enabled'                                                                                                                           |\n| GCP CIS 2.15   | Ensure 'Access Approval' is 'Enabled'                                                                                                                         |\n| GCP CIS 3.1    | Ensure that the default network does not exist in a project                                                                                                         |\n| GCP CIS 3.2    | Ensure legacy networks do not exist for a project                                                                                                                   |\n| GCP CIS 3.3    | Ensure that DNSSEC is enabled for Cloud DNS                                                                                                                         |\n| GCP CIS 3.4    | Ensure that RSASHA1 is not used for the key-signing key in Cloud DNS DNSSEC                                                                                         |\n| GCP CIS 3.5    | Ensure that RSASHA1 is not used for the zone-signing key in Cloud DNS DNSSEC                                                                                        |\n| GCP CIS 3.6    | Ensure that SSH access is restricted from the internet                                                                                                              |\n| GCP CIS 3.7    | Ensure that RDP access is restricted from the internet                                                                                                              |\n| GCP CIS 3.8    | Ensure that VPC Flow Logs is enabled for every subnet in a VPC Network                                                                                              |\n| GCP CIS 3.9    | Ensure no HTTPS or SSL proxy load balancers permit SSL policies with weak cipher suites                                                                             |\n| GCP CIS 3.10   | Use Identity Aware Proxy (IAP) to Ensure Only Traffic From Google IP Addresses are 'Allowed'                                                                        |\n| GCP CIS 4.1    | Ensure that instances are not configured to use the default service account                                                                                         |\n| GCP CIS 4.2    | Ensure that instances are not configured to use the default service account with full access to all Cloud APIs                                                      |\n| GCP CIS 4.3    | Ensure \"Block Project-wide SSH keys\" is enabled for VM instances                                                                                                    |\n| GCP CIS 4.4    | Ensure oslogin is enabled for a Project                                                                                                                             |\n| GCP CIS 4.5    | Ensure 'Enable connecting to serial ports' is not enabled for VM Instance                                                                                           |\n| GCP CIS 4.6    | Ensure that IP forwarding is not enabled on Instances                                                                                                               |\n| GCP CIS 4.7    | Ensure VM disks for critical VMs are encrypted with Customer-Supplied Encryption Keys (CSEK)                                                                        |\n| GCP CIS 4.8    | Ensure Compute instances are launched with Shielded VM enabled                                                                                                      |\n| GCP CIS 4.9    | Ensure that Compute instances do not have public IP addresses                                                                                                       |\n| GCP CIS 4.10   | In order to maintain the highest level of security all connections to an application should be secure by default                                                    |\n| GCP CIS 4.11   | Ensure that Compute instances have Confidential Computing enabled                                                                                                   |\n| GCP CIS 4.12   | Ensure the Latest Operating System Updates Are Installed On Your Virtual Machines in All Projects                                                                   |\n| GCP CIS 5.1    | Ensure that Cloud Storage bucket is not anonymously or publicly accessible                                                                                          |\n| GCP CIS 5.2    | Ensure that Cloud Storage buckets have uniform bucket-level access enabled                                                                                          |\n| GCP CIS 6.1.1  | Ensure that a MySQL database instance does not allow anyone to connect with administrative privileges                                                               |\n| GCP CIS 6.1.2  | Ensure 'skip_show_database' database flag for Cloud SQL Mysql instance is set to 'on'                                                                               |\n| GCP CIS 6.1.3  | Ensure that the 'local_infile' database flag for a Cloud SQL Mysql instance is set to 'off'                                                                         |\n| GCP CIS 6.2.1  | Ensure 'log_error_verbosity' database flag for Cloud SQL PostgreSQL instance is set to 'DEFAULT' or stricter                                                        |\n| GCP CIS 6.2.2  | Ensure that the 'log_connections' database flag for Cloud SQL PostgreSQL instance is set to 'on'                                                                    |\n| GCP CIS 6.2.3  | Ensure that the 'log_disconnections' database flag for Cloud SQL PostgreSQL instance is set to 'on'                                                                 |\n| GCP CIS 6.2.4  | Ensure 'log_statement' database flag for Cloud SQL PostgreSQL instance is set appropriately                                                                         |\n| GCP CIS 6.2.5  | Ensure 'log_hostname' database flag for Cloud SQL PostgreSQL instance is set appropriately                                                                          |\n| GCP CIS 6.2.6  | Ensure that the 'log_min_messages' database flag for Cloud SQL PostgreSQL instance is set appropriately                                                             |\n| GCP CIS 6.2.7  | Ensure 'log_min_error_statement' database flag for Cloud SQL PostgreSQL instance is set to 'Error' or stricter                                                      |\n| GCP CIS 6.2.8  | Ensure that the 'log_min_duration_statement' database flag for Cloud SQL PostgreSQL instance is set to '-1' (disabled)                                              |\n| GCP CIS 6.2.9  | Ensure That 'cloudsql.enable_pgaudit' Database Flag for each Cloud Sql Postgresql Instance Is Set to 'on' For Centralized Logging                                   |\n| GCP CIS 6.3.1  | Ensure 'external scripts enabled' database flag for Cloud SQL SQL Server instance is set to 'off'                                                                   |\n| GCP CIS 6.3.2  | Ensure that the 'cross db ownership chaining' database flag for Cloud SQL SQL Server instance is set to 'off'                                                       |\n| GCP CIS 6.3.3  | Ensure 'user connections' database flag for Cloud SQL SQL Server instance is set as appropriate                                                                     |\n| GCP CIS 6.3.4  | Ensure 'user options' database flag for Cloud SQL SQL Server instance is not configured                                                                             |\n| GCP CIS 6.3.5  | Ensure 'remote access' database flag for Cloud SQL SQL Server instance is set to 'off'                                                                              |\n| GCP CIS 6.3.6  | Ensure '3625 (trace flag)' database flag for Cloud SQL SQL Server instance is set to 'off'                                                                          |\n| GCP CIS 6.3.7  | Ensure that the 'contained database authentication' database flag for Cloud SQL on the SQL Server instance is set to 'off'                                          |\n| GCP CIS 7.1    | Ensure that BigQuery datasets are not anonymously or publicly accessible                                                                                            |\n| GCP CIS 7.2    | Ensure that all BigQuery Tables are encrypted with Customer-managed encryption key                                                                                  |\n| GCP CIS 7.3    | Ensure that a Default Customer-managed encryption key (CMEK) is specified for all BigQuery Data Sets                                                                |\n","readmeFilename":"README.md","gitHead":"e12d23402ae6715386ee3c8bae86c4274b61de3b","_id":"@cloudgraph/policy-pack-gcp-cis-1.3.0@1.0.1-alpha.1","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-OAaglLX/SHBHKarQzAfnj1rUhV/tlXLGXTpYHYx87RvKapdBE6r+ZcIuNdzsIzYS0ClZGypzKRNdSiZoTq2QxA==","shasum":"223f7da0e30ee26ae7731f351445bf9d46a26d37","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-gcp-cis-1.3.0/-/policy-pack-gcp-cis-1.3.0-1.0.1-alpha.1.tgz","fileCount":3,"unpackedSize":76664,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIAeGI4nEEO2tivpj4P2uzaxs2LyAyuDd1jJzLbAGVbDuAiEAsUwo9q2o/7xoExqiMrur1R0fZO2iw3uijeZhU7BcmHU="}]},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-gcp-cis-1.3.0_1.0.1-alpha.1_1684332785961_0.11428443672181476"},"_hasShrinkwrap":false},"1.0.1-alpha.2":{"name":"@cloudgraph/policy-pack-gcp-cis-1.3.0","description":"Policy pack implementing CIS Google Cloud Platform Foundations 1.3.0 Benchmark","version":"1.0.1-alpha.2","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/gcp/cis-1.2.0"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.4.0","@types/node":"^17.0.8","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.5.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true,"arrowParens":"avoid"},"scripts":{"build":"npm run prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest","release":"npx semantic-release"},"readme":"# CIS Google Cloud Platform Foundations 1.3.0\n\nPolicy Pack based on the GCP Foundations 1.3.0 benchmark provided by the [Center for Internet Security (CIS)](https://www.cisecurity.org/benchmark/google_cloud_computing_platform/)\n\n## First Steps\n\n1. Install [Cloud Graph CLI](https://docs.cloudgraph.dev/quick-start).\n2. Set up the [GCP Provider](https://www.npmjs.com/package/@cloudgraph/cg-provider-gcp) for CG with the `cg init gcp` command.\n3. Add Policy Pack for CIS Google Cloud Platform Foundations benchmark using `cg policy add gcp-cis-1.3.0` command.\n4. Execute the ruleset using the scan command `cg scan gcp`.\n5. Query the findings using the different options:\n\n   5a. Querying findings by provider:\n\n   ```graphql\n   query {\n     querygcpFindings {\n       CISFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n   5b. Querying findings by specific benchmark:\n\n   ```graphql\n   query {\n     querygcpCISFindings {\n       id\n       resourceId\n       result\n     }\n   }\n   ```\n\n   5c. Querying findings by resource:\n\n   ```graphql\n   query {\n     querygcpIamPolicy {\n       id\n       CISFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n## Available Ruleset\n\n| Rule           | Description                                                                                                                                                         |\n| -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| GCP CIS 1.1    | Ensure that corporate login credentials are used                                                                                                                    |\n| GCP CIS 1.2    | Ensure that multi-factor authentication is enabled for all non-service accounts                                                                                     |\n| GCP CIS 1.3    | Ensure that Security Key Enforcement is enabled for all admin accounts                                                                                              |\n| GCP CIS 1.4    | Ensure that there are only GCP-managed service account keys for each service account                                                                                |\n| GCP CIS 1.5    | Ensure that Service Account has no Admin privileges                                                                                                                 |\n| GCP CIS 1.6    | Ensure that IAM users are not assigned the Service Account User or Service Account Token Creator roles at project level                                             |\n| GCP CIS 1.7    | Ensure user-managed/external keys for service accounts are rotated every 90 days or less                                                                            |\n| GCP CIS 1.8    | Ensure that Separation of duties is enforced while assigning service account related roles to users                                                                 |\n| GCP CIS 1.9    | Ensure that Cloud KMS cryptokeys are not anonymously or publicly accessible                                                                                         |\n| GCP CIS 1.10   | Ensure KMS encryption keys are rotated within a period of 90 days                                                                                                   |\n| GCP CIS 1.11   | Ensure that Separation of duties is enforced while assigning KMS related roles to users                                                                             |\n| GCP CIS 1.12   | Ensure API keys are not created for a project                                                                                                                       |\n| GCP CIS 1.13   | Ensure API keys are restricted to use by only specified Hosts and Apps                                                                                              |\n| GCP CIS 1.14   | Ensure API keys are restricted to only APIs that application needs access                                                                                           |\n| GCP CIS 1.15   | Ensure API keys are rotated every 90 days                                                                                                                           |\n| GCP CIS 1.16   | Ensure Essential Contacts is Configured for Organization                                                                                                            |\n| GCP CIS 1.17   | Ensure that Dataproc Cluster is encrypted using CustomerManaged Encryption Key                                                                                      |\n| GCP CIS 1.18   | Ensure Secrets are Not Stored in Cloud Functions Environment Variables by Using Secret Manager                                                                      |\n| GCP CIS 2.1    | Ensure that Cloud Audit Logging is configured properly across all services and all users from a project                                                             |\n| GCP CIS 2.2    | Ensure that sinks are configured for all log entries                                                                                                                |\n| GCP CIS 2.3    | Ensure that retention policies on log buckets are configured using Bucket Lock                                                                                      |\n| GCP CIS 2.4    | Ensure log metric filter and alerts exist for project ownership assignments/changes                                                                                 |\n| GCP CIS 2.5    | Ensure that the log metric filter and alerts exist for Audit Configuration changes                                                                                  |\n| GCP CIS 2.6    | Ensure that the log metric filter and alerts exist for Custom Role changes                                                                                          |\n| GCP CIS 2.7    | Ensure that the log metric filter and alerts exist for VPC Network Firewall rule changes                                                                            |\n| GCP CIS 2.8    | Ensure that the log metric filter and alerts exist for VPC network route changes                                                                                    |\n| GCP CIS 2.9    | Ensure that the log metric filter and alerts exist for VPC network changes                                                                                          |\n| GCP CIS 2.10   | Ensure that the log metric filter and alerts exist for Cloud Storage IAM permission changes                                                                         |\n| GCP CIS 2.11   | Ensure that the log metric filter and alerts exist for SQL instance configuration changes                                                                           |\n| GCP CIS 2.12   | Ensure that Cloud DNS logging is enabled for all VPC networks                                                                                                       |\n| GCP CIS 2.13   | Ensure Cloud Asset Inventory Is Enabled                                                                                                                             |\n| GCP CIS 2.14   | Ensure 'Access Transparency' is 'Enabled'                                                                                                                           |\n| GCP CIS 2.15   | Ensure 'Access Approval' is 'Enabled'                                                                                                                         |\n| GCP CIS 3.1    | Ensure that the default network does not exist in a project                                                                                                         |\n| GCP CIS 3.2    | Ensure legacy networks do not exist for a project                                                                                                                   |\n| GCP CIS 3.3    | Ensure that DNSSEC is enabled for Cloud DNS                                                                                                                         |\n| GCP CIS 3.4    | Ensure that RSASHA1 is not used for the key-signing key in Cloud DNS DNSSEC                                                                                         |\n| GCP CIS 3.5    | Ensure that RSASHA1 is not used for the zone-signing key in Cloud DNS DNSSEC                                                                                        |\n| GCP CIS 3.6    | Ensure that SSH access is restricted from the internet                                                                                                              |\n| GCP CIS 3.7    | Ensure that RDP access is restricted from the internet                                                                                                              |\n| GCP CIS 3.8    | Ensure that VPC Flow Logs is enabled for every subnet in a VPC Network                                                                                              |\n| GCP CIS 3.9    | Ensure no HTTPS or SSL proxy load balancers permit SSL policies with weak cipher suites                                                                             |\n| GCP CIS 3.10   | Use Identity Aware Proxy (IAP) to Ensure Only Traffic From Google IP Addresses are 'Allowed'                                                                        |\n| GCP CIS 4.1    | Ensure that instances are not configured to use the default service account                                                                                         |\n| GCP CIS 4.2    | Ensure that instances are not configured to use the default service account with full access to all Cloud APIs                                                      |\n| GCP CIS 4.3    | Ensure \"Block Project-wide SSH keys\" is enabled for VM instances                                                                                                    |\n| GCP CIS 4.4    | Ensure oslogin is enabled for a Project                                                                                                                             |\n| GCP CIS 4.5    | Ensure 'Enable connecting to serial ports' is not enabled for VM Instance                                                                                           |\n| GCP CIS 4.6    | Ensure that IP forwarding is not enabled on Instances                                                                                                               |\n| GCP CIS 4.7    | Ensure VM disks for critical VMs are encrypted with Customer-Supplied Encryption Keys (CSEK)                                                                        |\n| GCP CIS 4.8    | Ensure Compute instances are launched with Shielded VM enabled                                                                                                      |\n| GCP CIS 4.9    | Ensure that Compute instances do not have public IP addresses                                                                                                       |\n| GCP CIS 4.10   | In order to maintain the highest level of security all connections to an application should be secure by default                                                    |\n| GCP CIS 4.11   | Ensure that Compute instances have Confidential Computing enabled                                                                                                   |\n| GCP CIS 4.12   | Ensure the Latest Operating System Updates Are Installed On Your Virtual Machines in All Projects                                                                   |\n| GCP CIS 5.1    | Ensure that Cloud Storage bucket is not anonymously or publicly accessible                                                                                          |\n| GCP CIS 5.2    | Ensure that Cloud Storage buckets have uniform bucket-level access enabled                                                                                          |\n| GCP CIS 6.1.1  | Ensure that a MySQL database instance does not allow anyone to connect with administrative privileges                                                               |\n| GCP CIS 6.1.2  | Ensure 'skip_show_database' database flag for Cloud SQL Mysql instance is set to 'on'                                                                               |\n| GCP CIS 6.1.3  | Ensure that the 'local_infile' database flag for a Cloud SQL Mysql instance is set to 'off'                                                                         |\n| GCP CIS 6.2.1  | Ensure 'log_error_verbosity' database flag for Cloud SQL PostgreSQL instance is set to 'DEFAULT' or stricter                                                        |\n| GCP CIS 6.2.2  | Ensure that the 'log_connections' database flag for Cloud SQL PostgreSQL instance is set to 'on'                                                                    |\n| GCP CIS 6.2.3  | Ensure that the 'log_disconnections' database flag for Cloud SQL PostgreSQL instance is set to 'on'                                                                 |\n| GCP CIS 6.2.4  | Ensure 'log_statement' database flag for Cloud SQL PostgreSQL instance is set appropriately                                                                         |\n| GCP CIS 6.2.5  | Ensure 'log_hostname' database flag for Cloud SQL PostgreSQL instance is set appropriately                                                                          |\n| GCP CIS 6.2.6  | Ensure that the 'log_min_messages' database flag for Cloud SQL PostgreSQL instance is set appropriately                                                             |\n| GCP CIS 6.2.7  | Ensure 'log_min_error_statement' database flag for Cloud SQL PostgreSQL instance is set to 'Error' or stricter                                                      |\n| GCP CIS 6.2.8  | Ensure that the 'log_min_duration_statement' database flag for Cloud SQL PostgreSQL instance is set to '-1' (disabled)                                              |\n| GCP CIS 6.2.9  | Ensure That 'cloudsql.enable_pgaudit' Database Flag for each Cloud Sql Postgresql Instance Is Set to 'on' For Centralized Logging                                   |\n| GCP CIS 6.3.1  | Ensure 'external scripts enabled' database flag for Cloud SQL SQL Server instance is set to 'off'                                                                   |\n| GCP CIS 6.3.2  | Ensure that the 'cross db ownership chaining' database flag for Cloud SQL SQL Server instance is set to 'off'                                                       |\n| GCP CIS 6.3.3  | Ensure 'user connections' database flag for Cloud SQL SQL Server instance is set as appropriate                                                                     |\n| GCP CIS 6.3.4  | Ensure 'user options' database flag for Cloud SQL SQL Server instance is not configured                                                                             |\n| GCP CIS 6.3.5  | Ensure 'remote access' database flag for Cloud SQL SQL Server instance is set to 'off'                                                                              |\n| GCP CIS 6.3.6  | Ensure '3625 (trace flag)' database flag for Cloud SQL SQL Server instance is set to 'off'                                                                          |\n| GCP CIS 6.3.7  | Ensure that the 'contained database authentication' database flag for Cloud SQL on the SQL Server instance is set to 'off'                                          |\n| GCP CIS 7.1    | Ensure that BigQuery datasets are not anonymously or publicly accessible                                                                                            |\n| GCP CIS 7.2    | Ensure that all BigQuery Tables are encrypted with Customer-managed encryption key                                                                                  |\n| GCP CIS 7.3    | Ensure that a Default Customer-managed encryption key (CMEK) is specified for all BigQuery Data Sets                                                                |\n","readmeFilename":"README.md","gitHead":"cbe41235649d562c05b902db8ee46a4a49de0fe1","_id":"@cloudgraph/policy-pack-gcp-cis-1.3.0@1.0.1-alpha.2","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-1EFpKLmfTvn1oyLohP8dHtjH1mmmGaEZGCQrpFaWsMDoV7PsCLXZnaHNYzdqSEZXsnzOsLmfkteXsnMLT7nnSg==","shasum":"7e460c73cce7159d21adbf226bdebf2073791a6d","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-gcp-cis-1.3.0/-/policy-pack-gcp-cis-1.3.0-1.0.1-alpha.2.tgz","fileCount":173,"unpackedSize":490595,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBfdL9/Ck3n0pyKmZrG6kSXJm8TVk2GQxHVdn4jx9ha3AiAhWf0bBwV9lpMVX354M4/2ghPnScvqJesuH9qQM4UvTQ=="}]},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-gcp-cis-1.3.0_1.0.1-alpha.2_1684337756304_0.585735446339122"},"_hasShrinkwrap":false}},"time":{"created":"2022-12-14T00:46:29.854Z","1.0.0-alpha.1":"2022-12-14T00:46:30.100Z","modified":"2023-05-17T15:35:56.602Z","1.0.0":"2023-04-28T17:00:34.237Z","1.0.1-alpha.1":"2023-05-17T14:13:06.192Z","1.0.1-alpha.2":"2023-05-17T15:35:56.473Z"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"description":"Policy pack implementing CIS Google Cloud Platform Foundations 1.3.0 Benchmark","homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"repository":{"url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/gcp/cis-1.2.0"},"author":{"name":"AutoCloud"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"license":"MPL-2.0","readme":"","readmeFilename":""}