{"_id":"@cloudgraph/policy-pack-gcp-nist-800-53-rev4","_rev":"6-8b4d5cbb2b3d9c34ee4d1461ad16c17c","name":"@cloudgraph/policy-pack-gcp-nist-800-53-rev4","dist-tags":{"latest":"1.2.0","alpha":"1.2.1-alpha.2"},"versions":{"1.0.0":{"name":"@cloudgraph/policy-pack-gcp-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Google Cloud services","version":"1.0.0","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/gcp/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.18.1","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"yarn prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","publish":"yarn npm publish","test":"NODE_ENV=test jest"},"gitHead":"9e67513c0bda301ea592f7a8c752c8bc9d81b5f2","_id":"@cloudgraph/policy-pack-gcp-nist-800-53-rev4@1.0.0","_nodeVersion":"16.15.0","_npmVersion":"8.10.0","dist":{"integrity":"sha512-4t8hqNHZboJKlwTghQH8C1BkgaleluEblLgENK07Ro32+Vajz7lnE9iodLaNbbwUnLpNvr9JWMSuUA8KNZqAUQ==","shasum":"e2990f4a20517dd057aa5d04384398dedada3238","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-gcp-nist-800-53-rev4/-/policy-pack-gcp-nist-800-53-rev4-1.0.0.tgz","fileCount":41,"unpackedSize":211286,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDnQm8TyRdNEqEWNZ2fDpMVmfB3kFvaecp6/TZxp8mTiQIgVFdpCWMGA7WRxAL9zs9EiWFiwgcpOilOt3+vfX/Rm1c="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJij+euACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp5nw/+IpEShOicDz/Hgmcw60UQCU0L2So/CCz3M0hr3Tmk1XfEYJ/N\r\n2PjLz4N1L8GYtyjYkdcnqb/74CzuIeMKAYmZahPn82f6W3mkFMB92gwCKfUZ\r\nbapGWh3JqgaNbe8zBZEp7XQJFM0c5w1U5wMU82ncXYOmHstDUoiKQTmHcLWb\r\n+gJTRApPDQr9DbOvD25uAQXGm96VMCHq2oAQbptuuInKFnFvvaULljZnWUPK\r\neU5tSp8KnGvhARga9RpDo4j6EoiObt07lr5K7Q4Li/Zhe/J0xrCoos3240yJ\r\nmwkmcf8lZ21Yjs+CB3ob4g8iwEIqzKvtgq1E1Wz+cOUEiZS0g0eyFW776ydP\r\nX/YJxDHSIWa1a+Y9bFT6Q6gUGtgr9f6ZYacRzw/sh5li4y/thYryRSSYYO4T\r\nkbYHhYG+vETmWf1CL66dkJ0dMF3olHwcvbQq7+R++TUIf13e8xmgSu9JtNeq\r\nbBoeFHMS9tU2H0FxsDNE0qeTj+E68aPN2AyU05ucb9MXIaGHrrxGFTgZOod0\r\n0IgCd7FGlkWkUgFttz3iOgI1Q88sap45GGjyk6KEY92C53CbSa5TU0yuuj+z\r\nmF8QW8LLOUctbzQ6YXPcMNZlUa3GC9JhwGhQGJ23Yjoxv3wqiRtNfcS5k6Cj\r\nmm0oGo2LkavhVoXb1tcebNuciu82U2bXbEU=\r\n=GnO1\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-gcp-nist-800-53-rev4_1.0.0_1653598126420_0.28856271537559697"},"_hasShrinkwrap":false},"1.1.0":{"name":"@cloudgraph/policy-pack-gcp-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Google Cloud services","version":"1.1.0","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/gcp/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.0","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"pnpm prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest"},"gitHead":"a524979546870ee3f72a453de54c7e884aaa620b","_id":"@cloudgraph/policy-pack-gcp-nist-800-53-rev4@1.1.0","_nodeVersion":"17.9.1","_npmVersion":"8.11.0","dist":{"integrity":"sha512-qNVLrQDvAq2gDDEDNhUnSg0x6ap2gDGpCBZ5xsFkBZb5IHHBLvih3x+aW+eitYdrP33W23BW+YTIyi0/a4Tm/w==","shasum":"c54a8b74b15135e86796e4bd72039b5115c7ee42","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-gcp-nist-800-53-rev4/-/policy-pack-gcp-nist-800-53-rev4-1.1.0.tgz","fileCount":41,"unpackedSize":52348,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEeDWWy3hTStTB/pIRC9+GaTt3Z52EHgW/PY/wHWHN1+AiAHos99Qg/crnk2F0mw/0xLZaFcsNj885IT6cO05vxApA=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJizFaUACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqAPA//VX8ftuwJpYLXXOXFlo0j/XS61nFdweAvEa9rZtk2hRNpobYZ\r\nD3f8EfvZQBbs4OGV894TJqwHT68stdcdLB/2wFcktZCAnjy51cJ+oEpl1qVs\r\nHPDQ/5V4Np9e7E/uXz8jBBQtfBkE2TcMFddSkq9RJ4DHMF5ZMh2AeFhSo+VT\r\nSrQpHFn7P9ylgSeM9QX+cOxuUPfL4fcA1CRQIZSsGjAkG0A2PAe5AsJymdSO\r\n0N4gKeC9tDxTaP0Bp0UIQqWW0zgIJ8Mi8Ue4Nc2gTx1hSSYQDtP1nr47zy6W\r\nFUkucBnXjTNrtLuq7zUyxAcW8mU5CEwnvRckUn1YtpfNBXUcDyDKn0tnKf6b\r\nUB9/dfy4j7K5IPnIehZ/B76uBIV4KisLKNFr+p3uf4Vjpfv4hXyK8dwzpnOq\r\nQATjFRQyhozEgsYSYNkgocaDjf1Tr60ZzLA8QOq8iM/WjAy8wWN5KNO70Klq\r\nzQMDxMkHV6pMguHVJ2hx200ItMRzUwRDMumCfoZwiYEzwLwMejhmvAf/wwT/\r\n4odsb7c3oQddMw1MA68wHin+1ph/27d1k1b74h5dqbQjkwFxxTpzg7zDZBA3\r\nmImlinIJr1HJ9hpeeriiewl2kqXkAAjNJTI2asskoR0BCyW1VIHEnBLRWql7\r\ndbDkyIrMyz/FLEjJB4nmKECNHNITz+ui8Zo=\r\n=Ekki\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-gcp-nist-800-53-rev4_1.1.0_1657558676426_0.4154868833848002"},"_hasShrinkwrap":false},"1.1.1":{"name":"@cloudgraph/policy-pack-gcp-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Google Cloud services","version":"1.1.1","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/gcp/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.0","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"pnpm prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest"},"gitHead":"e8b28dc637fb9b943dabbb2b127a8ce0bf82c2e3","_id":"@cloudgraph/policy-pack-gcp-nist-800-53-rev4@1.1.1","_nodeVersion":"17.9.1","_npmVersion":"8.11.0","dist":{"integrity":"sha512-E8MxwOA88MbJaZUh/hYwS4fy1ZNZQtNNkhTBk0NqV+3Isu/vTtt20eDQTtctKzbdvXW/o1XEYuBdHREBgad7bg==","shasum":"9d640ccc66f59296ee4fde8c9cb1b2cdc5a74ab9","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-gcp-nist-800-53-rev4/-/policy-pack-gcp-nist-800-53-rev4-1.1.1.tgz","fileCount":77,"unpackedSize":223052,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIB33L3Kx3+VWON2HBDAZPIVW+7j0C4Z0vlSEQxJm/GMsAiBAsbBhIIPFXlwWSbwgRtj1LN2Ar7/7L/OPbTCkE0rbOg=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJizJA0ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmra1w//cuOMoQUVA/062t0uUThIdPS95BwpM6hZT01b0jbqtKzIzOK/\r\nOJShU2cuOQEGaOjZ1+gYwJIPGs0eKqrgTXJl8Wn91Qz8pYdwWGKsba0NVUTI\r\n1to1Fumh5kIPPL8oxQY/jgn2D+KYSJYEFqf3JlayRWzQIVoR9qWXrLPcSZkG\r\nLtXrxBpcfIj9eMxjx/U3qvdALPhDWRolgfdHqolEK+BGUTF+xtT6HYp505Wb\r\n8IJE8BlP4VGlRmHynvtFPQ5vEgVlyCFTYujhHBM8o+GV7R5Lq8CgFTPn/9zT\r\nNvOXLv6a4PIj3S9D1S+1WSy8hEoAvzeBjpHG25kIeuQy+osQsuLW5pHXDFVH\r\nLSX6KDWmFtojOaaanumNyDjvIPM0MTA65Mj82jZXF9T7mR6eiIyq1u/jaldv\r\nyWH6LovYvOm0W/nnpG7qMXWs+UBMk6pICrq7n0KcV9Up+27rp8JLPkuPAxJK\r\nKLk4uG80reZDaOpkYnXvITn6GU1DS2eH+ZYG5iadvi5V+v/G97nXLbbHLFr+\r\nvxsjVBr9bCovt+zYcy8hID11BpR4f4v3JNfUqyBSp2SarSW4vdHXoe6seHAA\r\n0XN5dAiUOjEdiH+PFUKoUorzUj0zmBeiPCVYEB8/9ma7kry/AE77KQRZeq41\r\nLTP02Lyeh+5EFLsWth8ls49VW1GzD3Zc8vs=\r\n=yTvP\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-gcp-nist-800-53-rev4_1.1.1_1657573428617_0.3768865527484526"},"_hasShrinkwrap":false},"1.2.0-alpha.1":{"name":"@cloudgraph/policy-pack-gcp-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Google Cloud services","version":"1.2.0-alpha.1","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/gcp/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"npm run prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest","release":"npx semantic-release --no-ci -e semantic-release-monorepo"},"readme":"# NIST 800-53 Rev. 4 for Google Cloud Services\n\nPolicy Pack based on the [800-53 Rev. 4](https://csrc.nist.gov/publications/detail/sp/800-53/rev-4/archive/2015-01-22) benchmark provided by the [The National Institute of Standards and Technology (NIST)](https://www.nist.gov)\n\n## First Steps\n\n1. Install [Cloud Graph CLI](https://docs.cloudgraph.dev/quick-start).\n2. Set up the [GCP Provider](https://www.npmjs.com/package/@cloudgraph/cg-provider-gcp) for CG with the `cg init gcp` command.\n3. Add Policy Pack NIST 800-53 Rev. 4 for Google Cloud Services benchmark using `cg policy add gcp-nist-800-53-rev4` command.\n4. Execute the ruleset using the scan command `cg scan gcp`.\n5. Query the findings using the different options:\n\n   5a. Querying findings by provider:\n\n   ```graphql\n   query {\n     querygcpFindings {\n       NISTFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n   5b. Querying findings by specific benchmark:\n\n   ```graphql\n   query {\n     querygcpNISTFindings {\n       id\n       resourceId\n       result\n     }\n   }\n   ```\n\n   5c. Querying findings by resource:\n\n   ```graphql\n   query {\n     querygcpIamPolicy {\n       id\n       NISTFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n## Available Ruleset\n\n| Rule          | Description                                                                                                                        |\n| ------------- | ---------------------------------------------------------------------------------------------------------------------------------- |\n| GCP NIST 1.1  | Compute instances should not use the default service account                                                                       |\n| GCP NIST 1.2  | Compute instances should not use the default service account with full access to all Cloud APIs                                    |\n| GCP NIST 1.3  | Compute instance \"block-project-ssh-keys should be enabled                                                                         |\n| GCP NIST 1.4  | Compute instances should not have public IP addresses                                                                              |\n| GCP NIST 1.5  | Compute instances \"Enable connecting to serial ports\" should not be enabled                                                        |\n| GCP NIST 1.6  | SQL database instances should not permit access from 0.0.0.0/0                                                                     |\n| GCP NIST 1.7  | SQL database instances should not have public IPs                                                                                  |\n| GCP NIST 2.1  | DNS managed zone DNSSEC should be enabled                                                                                          |\n| GCP NIST 2.2  | DNS managed zone DNSSEC key-signing keys should not use RSASHA1                                                                    |\n| GCP NIST 2.3  | DNS managed zone DNSSEC zone-signing keys should not use RSASHA1                                                                   |\n| GCP NIST 3.1  | IAM default audit log config should not exempt any users                                                                           |\n| GCP NIST 3.2  | PostgreSQL database instance 'log_checkpoints' database flag should be set to 'on'                                                 |\n| GCP NIST 3.3  | PostgreSQL database instance 'log_connections' database flag should be set to 'on'                                                 |\n| GCP NIST 3.4  | PostgreSQL database instance 'log_disconnections' database flag should be set to 'on'                                              |\n| GCP NIST 3.5  | PostgreSQL database instance 'log_lock_waits' database flag should be set to 'on'                                                  |\n| GCP NIST 3.6  | PostgreSQL database instance 'log_min_error_statement' database flag should be set appropriately                                   |\n| GCP NIST 3.7  | PostgreSQL database instance 'log_temp_files' database flag should be set to '0' (on)                                              |\n| GCP NIST 3.8  | PostgreSQL database instance 'log_min_duration_statement' database flag should be set to '-1' (disabled)                           |\n| GCP NIST 3.9  | At least one project-level logging sink should be configured with an empty filter                                                  |\n| GCP NIST 3.10 | Network subnet flow logs should be enabled                                                                                         |\n| GCP NIST 3.11 | IAM default audit log config should include 'DATA_READ' and 'DATA_WRITE' log types                                                 |\n| GCP NIST 4.1  | Compute instance disks should be encrypted with customer-supplied encryption keys (CSEKs)                                          |\n| GCP NIST 4.2  | SQL database instances should require incoming connections to use SSL                                                              |\n| GCP NIST 5.1  | Logging metric filter and alert for project ownership assignments/changes should be configured                                     |\n| GCP NIST 5.2  | Logging metric filter and alert for audit configuration changes should be configured                                               |\n| GCP NIST 5.3  | Logging metric filter and alert for Custom Role changes should be configured                                                       |\n| GCP NIST 5.4  | Logging metric filter and alert for network firewall rule changes should be configured                                             |\n| GCP NIST 5.5  | Logging metric filter and alert for network route changes should be configured                                                     |\n| GCP NIST 5.6  | Logging metric filter and alert for network changes should be configured                                                           |\n| GCP NIST 5.7  | Logging metric filter and alert for SQL instance configuration changes should be configured                                        |\n| GCP NIST 5.8  | Logging storage bucket retention policies and Bucket Lock should be configured                                                     |\n| GCP NIST 6.1  | The default network for a project should be deleted                                                                                |\n| GCP NIST 6.2  | Network firewall rules should not permit ingress from 0.0.0.0/0 to port 22 (SSH)                                                   |\n| GCP NIST 6.3  | Network firewall rules should not permit ingress from 0.0.0.0/0 to port 3389 (RDP)                                                 |\n| GCP NIST 6.4  | Load balancer HTTPS or SSL proxy SSL policies should not have weak cipher suites                                                   |\n| GCP NIST 6.5  | Compute instances \"IP forwarding\" should not be enabled                                                                            |\n","readmeFilename":"README.md","gitHead":"0687edf79877bb96d6f94140ead9b7d4f58f24ab","_id":"@cloudgraph/policy-pack-gcp-nist-800-53-rev4@1.2.0-alpha.1","_nodeVersion":"18.12.1","_npmVersion":"8.19.3","dist":{"integrity":"sha512-S36+hfQcXi/s7FCkVh9O8t2wHLuv3A8b4ZZy1sfSQj01Ocp+v9GcxK3+K/j+NZ0GQUBhCO0pxu0mHa5T+J7Bww==","shasum":"67668cb6223a51f6fc5cd04a6cc2f6d946af5c48","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-gcp-nist-800-53-rev4/-/policy-pack-gcp-nist-800-53-rev4-1.2.0-alpha.1.tgz","fileCount":79,"unpackedSize":229211,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIAsI+WX/bnvhe9hXDcaXWCEhd4EbOGAfsssf+u14u7OEAiBf5P8K6MJzf2K6WVhHKXytecyTotYjO5HusWpkOTWRxg=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmRz8ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoM3BAAmQ0abcdaqPAbUqZ9zpXKlGnDlG9/EByBVWaWOXeuqKRzcPy+\r\n0LhBU6mQRFFOYrGY9j7eW2Hiq8vvW6wHAr7hFMMeZO5ZNPj/0Dc7q/N2NPoz\r\nG6QlVu5liy1IfDnCBDVSEnfrev/E0lQFhhZcKH42I7OILkiRXhn8N3RzBZfp\r\nya9PUKgRjrtr0ocJIVxEQLioB+uwvhGDquGQ0o8KTf4UMzxaUI15hx/4UuQ8\r\nMEYrjBzUEJ1lYxXHZbqEItEFR2mg9jaHq22jDO4tJM5GDPPLY/Sow43hMx0F\r\nTe+UxmrI4GnM+TfEVqWqSSqngQNZrfRAyq8hcxiIkjG1mP9EW3p9FBiDRtp+\r\na3UsQzH0B/TPa35ARp+OyZEaEAV66/53wnZq9+r/SOA3f0xqtjwP7gBjtpdY\r\nnnjLsjffExaLpgbhIhHZnOcob3NBGQAe7UXTTzfkl2hKHytPYAuPgJzuMhin\r\nu7m6A/Xz+1QXz70wqOtOHLDVyfCL7yngfITZBf+E/FcvE5CxLy0d1BG0tU94\r\n6ce4vH69D1IH2jhuEfODep8gDwgpNHSyGF23od9b81hBjbZu3xQR7m80gkv/\r\nmNSwf7+Tu4I/f5rOES4B9mkP6ZP+PxDlxb2YTvh+tfMR1XybL/3qclAq7kT8\r\nuDgUyWbW2yBL2zls90JHAZVJxjMT65CzqGE=\r\n=1CpG\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-gcp-nist-800-53-rev4_1.2.0-alpha.1_1670978811831_0.48061573702908755"},"_hasShrinkwrap":false},"1.2.0":{"name":"@cloudgraph/policy-pack-gcp-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Google Cloud services","version":"1.2.0","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/gcp/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"npm run prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest","release":"npx semantic-release --no-ci"},"gitHead":"1bd3cd120a5db5885fec6e1e4ff47472a4caa645","_id":"@cloudgraph/policy-pack-gcp-nist-800-53-rev4@1.2.0","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-w54meR+bpPD7PdajP77KGHu5zYJa9NRufo2Ad+A+WC9aLDaMlj3WAy7w0M+gWuWUOha7DhyWz7Tsr0py28to9g==","shasum":"e668a7b7ec2b9a4ccd2fa5196f2152bdb69317c9","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-gcp-nist-800-53-rev4/-/policy-pack-gcp-nist-800-53-rev4-1.2.0.tgz","fileCount":79,"unpackedSize":239603,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCQR555CXnQsICN4waW/Sf0hWdbQz8Rb9rc2NhvOpaR5wIgE0efhP4sfwXhox14DzsNjGBBCG0ZF6Ox5QGy99Bcjt0="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkS/vSACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq9tQ//ZOF+V27sXsZ44aNZqf7b3Bivsu9SgMEiYpHp+0snCv6sNptE\r\nwQKVuwVfqQWj6ArBNKE0vkHhUL0JbgrCaXDbd3u1hSCxzr9LK8ZCLDai7E4E\r\n/sA8ethTJEogiGzKqMImDDY7KshizSvSQu8WOwxdfPJNzN2WlNkBnvSy9Clk\r\nT3IWUevzIGx2T3s/MxyXiPNS2b+Dyj4ZKyHG4Ou0BG5+Smc/o88C8pBkgTZJ\r\nKbudWC674wVFm5OLHmv3xs5f8yUMoRhTDKUTNnRr05L3XprmayQy9j8Gofxe\r\nBvXHWgJVWR0DBepQ+VsDmxa03UVXzwS9JqcVrp1OzfyzSml5j99kGL2yPVFe\r\nvaRQCGcKdXhq2BUQPg+pVSHCmenDzAOtSx8/fDvy7i/GXQG4Rdz0gVbRvMKN\r\nAgo6p+q3XXUDsCsP3h7imdnJCI1CUJMFtBlVsj9wKfUPJaLAvDhfifgJm6/A\r\nQ6YHbyujkJc36UAC4pmKfRGnalsqP8mRaCbx5Ck0Yok+RRC1QThTY9ovx6ja\r\nbuTR1iLT20vI7gWyuyjICddnYCF02WTS3QcRz4GiMLQPAmYWtIaG8dLm0X/W\r\nNWlV9h2VH7jevPPVYuUbm2M3wfyxIQZ5fWJqoNvldJHb2QCpM+0SSaZgANg6\r\nAYDm8fe/6KdaSlySssUJQNHU5IIXPJM0PoA=\r\n=TtxJ\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-gcp-nist-800-53-rev4_1.2.0_1682701266580_0.24005952694875554"},"_hasShrinkwrap":false},"1.2.1-alpha.1":{"name":"@cloudgraph/policy-pack-gcp-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Google Cloud services","version":"1.2.1-alpha.1","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/gcp/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"npm run prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest","release":"npx semantic-release"},"readme":"# NIST 800-53 Rev. 4 for Google Cloud Services\n\nPolicy Pack based on the [800-53 Rev. 4](https://csrc.nist.gov/publications/detail/sp/800-53/rev-4/archive/2015-01-22) benchmark provided by the [The National Institute of Standards and Technology (NIST)](https://www.nist.gov)\n\n## First Steps\n\n1. Install [Cloud Graph CLI](https://docs.cloudgraph.dev/quick-start).\n2. Set up the [GCP Provider](https://www.npmjs.com/package/@cloudgraph/cg-provider-gcp) for CG with the `cg init gcp` command.\n3. Add Policy Pack NIST 800-53 Rev. 4 for Google Cloud Services benchmark using `cg policy add gcp-nist-800-53-rev4` command.\n4. Execute the ruleset using the scan command `cg scan gcp`.\n5. Query the findings using the different options:\n\n   5a. Querying findings by provider:\n\n   ```graphql\n   query {\n     querygcpFindings {\n       NISTFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n   5b. Querying findings by specific benchmark:\n\n   ```graphql\n   query {\n     querygcpNISTFindings {\n       id\n       resourceId\n       result\n     }\n   }\n   ```\n\n   5c. Querying findings by resource:\n\n   ```graphql\n   query {\n     querygcpIamPolicy {\n       id\n       NISTFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n## Available Ruleset\n\n| Rule          | Description                                                                                                                        |\n| ------------- | ---------------------------------------------------------------------------------------------------------------------------------- |\n| GCP NIST 1.1  | Compute instances should not use the default service account                                                                       |\n| GCP NIST 1.2  | Compute instances should not use the default service account with full access to all Cloud APIs                                    |\n| GCP NIST 1.3  | Compute instance \"block-project-ssh-keys should be enabled                                                                         |\n| GCP NIST 1.4  | Compute instances should not have public IP addresses                                                                              |\n| GCP NIST 1.5  | Compute instances \"Enable connecting to serial ports\" should not be enabled                                                        |\n| GCP NIST 1.6  | SQL database instances should not permit access from 0.0.0.0/0                                                                     |\n| GCP NIST 1.7  | SQL database instances should not have public IPs                                                                                  |\n| GCP NIST 2.1  | DNS managed zone DNSSEC should be enabled                                                                                          |\n| GCP NIST 2.2  | DNS managed zone DNSSEC key-signing keys should not use RSASHA1                                                                    |\n| GCP NIST 2.3  | DNS managed zone DNSSEC zone-signing keys should not use RSASHA1                                                                   |\n| GCP NIST 3.1  | IAM default audit log config should not exempt any users                                                                           |\n| GCP NIST 3.2  | PostgreSQL database instance 'log_checkpoints' database flag should be set to 'on'                                                 |\n| GCP NIST 3.3  | PostgreSQL database instance 'log_connections' database flag should be set to 'on'                                                 |\n| GCP NIST 3.4  | PostgreSQL database instance 'log_disconnections' database flag should be set to 'on'                                              |\n| GCP NIST 3.5  | PostgreSQL database instance 'log_lock_waits' database flag should be set to 'on'                                                  |\n| GCP NIST 3.6  | PostgreSQL database instance 'log_min_error_statement' database flag should be set appropriately                                   |\n| GCP NIST 3.7  | PostgreSQL database instance 'log_temp_files' database flag should be set to '0' (on)                                              |\n| GCP NIST 3.8  | PostgreSQL database instance 'log_min_duration_statement' database flag should be set to '-1' (disabled)                           |\n| GCP NIST 3.9  | At least one project-level logging sink should be configured with an empty filter                                                  |\n| GCP NIST 3.10 | Network subnet flow logs should be enabled                                                                                         |\n| GCP NIST 3.11 | IAM default audit log config should include 'DATA_READ' and 'DATA_WRITE' log types                                                 |\n| GCP NIST 4.1  | Compute instance disks should be encrypted with customer-supplied encryption keys (CSEKs)                                          |\n| GCP NIST 4.2  | SQL database instances should require incoming connections to use SSL                                                              |\n| GCP NIST 5.1  | Logging metric filter and alert for project ownership assignments/changes should be configured                                     |\n| GCP NIST 5.2  | Logging metric filter and alert for audit configuration changes should be configured                                               |\n| GCP NIST 5.3  | Logging metric filter and alert for Custom Role changes should be configured                                                       |\n| GCP NIST 5.4  | Logging metric filter and alert for network firewall rule changes should be configured                                             |\n| GCP NIST 5.5  | Logging metric filter and alert for network route changes should be configured                                                     |\n| GCP NIST 5.6  | Logging metric filter and alert for network changes should be configured                                                           |\n| GCP NIST 5.7  | Logging metric filter and alert for SQL instance configuration changes should be configured                                        |\n| GCP NIST 5.8  | Logging storage bucket retention policies and Bucket Lock should be configured                                                     |\n| GCP NIST 6.1  | The default network for a project should be deleted                                                                                |\n| GCP NIST 6.2  | Network firewall rules should not permit ingress from 0.0.0.0/0 to port 22 (SSH)                                                   |\n| GCP NIST 6.3  | Network firewall rules should not permit ingress from 0.0.0.0/0 to port 3389 (RDP)                                                 |\n| GCP NIST 6.4  | Load balancer HTTPS or SSL proxy SSL policies should not have weak cipher suites                                                   |\n| GCP NIST 6.5  | Compute instances \"IP forwarding\" should not be enabled                                                                            |\n","readmeFilename":"README.md","gitHead":"a9374a70bee52a964610073b21562d5e599b3615","_id":"@cloudgraph/policy-pack-gcp-nist-800-53-rev4@1.2.1-alpha.1","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-gDq6tBwtN11rYwqGjZmUgQ3JTOhe1sIrK9A54jcEQ8peIKgeju5dwGkWd5dIf4Icb0WYPRgXZHIa+po8BewPRw==","shasum":"8bf3fec94b50133e1fe1cb55fed6cf2f503b6cc3","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-gcp-nist-800-53-rev4/-/policy-pack-gcp-nist-800-53-rev4-1.2.1-alpha.1.tgz","fileCount":3,"unpackedSize":23378,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCX5w90hFtpdBZ8Clteecth/aPx9KojqkxWOpBTdcD1NQIgeD029d+XrQ/JlnPLeHeDoinlrACmW0n+FmT9aR6suSw="}]},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-gcp-nist-800-53-rev4_1.2.1-alpha.1_1684332800531_0.029149876006457687"},"_hasShrinkwrap":false},"1.2.1-alpha.2":{"name":"@cloudgraph/policy-pack-gcp-nist-800-53-rev4","description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Google Cloud services","version":"1.2.1-alpha.2","author":{"name":"AutoCloud"},"license":"MPL-2.0","main":"dist/index.js","types":"dist/index.d.ts","repository":{"url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/gcp/nist-800-53-rev4"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"publishConfig":{"access":"public"},"directories":{"test":"tests"},"devDependencies":{"@autocloud/eslint-config":"^0.1.0","@cloudgraph/sdk":"^0.21.1","@types/jest":"^27.4.0","@types/node":"^15.12.4","@types/pino":"^6.3.11","@typescript-eslint/eslint-plugin":"^4.28.5","@typescript-eslint/parser":"^4.28.5","cpx":"^1.5.0","cuid":"^2.1.8","eslint":"^7.25.0","eslint-config-airbnb-base":"14.2.1","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.4.0","jest":"^27.0.6","prettier":"^2.4.1","shx":"^0.3.3","ts-jest":"^27.0.4","tslib":"^1","typescript":"^4.3.5"},"engines":{"node":">=16.0.0"},"homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"prettier":{"semi":false,"singleQuote":true},"scripts":{"build":"npm run prepack","clean":"rm -rf dist","lint":"eslint","prepack":"rm -rf dist && tsc -b","test":"NODE_ENV=test jest","release":"npx semantic-release"},"readme":"# NIST 800-53 Rev. 4 for Google Cloud Services\n\nPolicy Pack based on the [800-53 Rev. 4](https://csrc.nist.gov/publications/detail/sp/800-53/rev-4/archive/2015-01-22) benchmark provided by the [The National Institute of Standards and Technology (NIST)](https://www.nist.gov)\n\n## First Steps\n\n1. Install [Cloud Graph CLI](https://docs.cloudgraph.dev/quick-start).\n2. Set up the [GCP Provider](https://www.npmjs.com/package/@cloudgraph/cg-provider-gcp) for CG with the `cg init gcp` command.\n3. Add Policy Pack NIST 800-53 Rev. 4 for Google Cloud Services benchmark using `cg policy add gcp-nist-800-53-rev4` command.\n4. Execute the ruleset using the scan command `cg scan gcp`.\n5. Query the findings using the different options:\n\n   5a. Querying findings by provider:\n\n   ```graphql\n   query {\n     querygcpFindings {\n       NISTFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n   5b. Querying findings by specific benchmark:\n\n   ```graphql\n   query {\n     querygcpNISTFindings {\n       id\n       resourceId\n       result\n     }\n   }\n   ```\n\n   5c. Querying findings by resource:\n\n   ```graphql\n   query {\n     querygcpIamPolicy {\n       id\n       NISTFindings {\n         id\n         resourceId\n         result\n       }\n     }\n   }\n   ```\n\n## Available Ruleset\n\n| Rule          | Description                                                                                                                        |\n| ------------- | ---------------------------------------------------------------------------------------------------------------------------------- |\n| GCP NIST 1.1  | Compute instances should not use the default service account                                                                       |\n| GCP NIST 1.2  | Compute instances should not use the default service account with full access to all Cloud APIs                                    |\n| GCP NIST 1.3  | Compute instance \"block-project-ssh-keys should be enabled                                                                         |\n| GCP NIST 1.4  | Compute instances should not have public IP addresses                                                                              |\n| GCP NIST 1.5  | Compute instances \"Enable connecting to serial ports\" should not be enabled                                                        |\n| GCP NIST 1.6  | SQL database instances should not permit access from 0.0.0.0/0                                                                     |\n| GCP NIST 1.7  | SQL database instances should not have public IPs                                                                                  |\n| GCP NIST 2.1  | DNS managed zone DNSSEC should be enabled                                                                                          |\n| GCP NIST 2.2  | DNS managed zone DNSSEC key-signing keys should not use RSASHA1                                                                    |\n| GCP NIST 2.3  | DNS managed zone DNSSEC zone-signing keys should not use RSASHA1                                                                   |\n| GCP NIST 3.1  | IAM default audit log config should not exempt any users                                                                           |\n| GCP NIST 3.2  | PostgreSQL database instance 'log_checkpoints' database flag should be set to 'on'                                                 |\n| GCP NIST 3.3  | PostgreSQL database instance 'log_connections' database flag should be set to 'on'                                                 |\n| GCP NIST 3.4  | PostgreSQL database instance 'log_disconnections' database flag should be set to 'on'                                              |\n| GCP NIST 3.5  | PostgreSQL database instance 'log_lock_waits' database flag should be set to 'on'                                                  |\n| GCP NIST 3.6  | PostgreSQL database instance 'log_min_error_statement' database flag should be set appropriately                                   |\n| GCP NIST 3.7  | PostgreSQL database instance 'log_temp_files' database flag should be set to '0' (on)                                              |\n| GCP NIST 3.8  | PostgreSQL database instance 'log_min_duration_statement' database flag should be set to '-1' (disabled)                           |\n| GCP NIST 3.9  | At least one project-level logging sink should be configured with an empty filter                                                  |\n| GCP NIST 3.10 | Network subnet flow logs should be enabled                                                                                         |\n| GCP NIST 3.11 | IAM default audit log config should include 'DATA_READ' and 'DATA_WRITE' log types                                                 |\n| GCP NIST 4.1  | Compute instance disks should be encrypted with customer-supplied encryption keys (CSEKs)                                          |\n| GCP NIST 4.2  | SQL database instances should require incoming connections to use SSL                                                              |\n| GCP NIST 5.1  | Logging metric filter and alert for project ownership assignments/changes should be configured                                     |\n| GCP NIST 5.2  | Logging metric filter and alert for audit configuration changes should be configured                                               |\n| GCP NIST 5.3  | Logging metric filter and alert for Custom Role changes should be configured                                                       |\n| GCP NIST 5.4  | Logging metric filter and alert for network firewall rule changes should be configured                                             |\n| GCP NIST 5.5  | Logging metric filter and alert for network route changes should be configured                                                     |\n| GCP NIST 5.6  | Logging metric filter and alert for network changes should be configured                                                           |\n| GCP NIST 5.7  | Logging metric filter and alert for SQL instance configuration changes should be configured                                        |\n| GCP NIST 5.8  | Logging storage bucket retention policies and Bucket Lock should be configured                                                     |\n| GCP NIST 6.1  | The default network for a project should be deleted                                                                                |\n| GCP NIST 6.2  | Network firewall rules should not permit ingress from 0.0.0.0/0 to port 22 (SSH)                                                   |\n| GCP NIST 6.3  | Network firewall rules should not permit ingress from 0.0.0.0/0 to port 3389 (RDP)                                                 |\n| GCP NIST 6.4  | Load balancer HTTPS or SSL proxy SSL policies should not have weak cipher suites                                                   |\n| GCP NIST 6.5  | Compute instances \"IP forwarding\" should not be enabled                                                                            |\n","readmeFilename":"README.md","gitHead":"09650a32df7e9056a19349a0eded6b77bb9d6aab","_id":"@cloudgraph/policy-pack-gcp-nist-800-53-rev4@1.2.1-alpha.2","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-ym8ASzAAPj8aFhKh0qeVbAgcXW7dm8KW69olzMoaSOP/nXxKrm4W1+9sQVAZnqfv0fZy33TbMPa+4WQaXQKDLQ==","shasum":"bf5497146611aa0dbccef0aa23de3a6ef61d91db","tarball":"https://registry.npmjs.org/@cloudgraph/policy-pack-gcp-nist-800-53-rev4/-/policy-pack-gcp-nist-800-53-rev4-1.2.1-alpha.2.tgz","fileCount":79,"unpackedSize":240398,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDSC38d1tHojQA5Hg0Ur4zjL556A1cSZTgGRP00zw+ZgQIhAKmAfZOXBN5h8xSUMgnVQGd7cWhvfKQYjV41G6GfrjmO"}]},"_npmUser":{"name":"ckoning","email":"chris@autocloud.dev"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/policy-pack-gcp-nist-800-53-rev4_1.2.1-alpha.2_1684337774101_0.29426426875330125"},"_hasShrinkwrap":false}},"time":{"created":"2022-05-26T20:48:46.367Z","1.0.0":"2022-05-26T20:48:46.626Z","modified":"2023-05-17T15:36:14.427Z","1.1.0":"2022-07-11T16:57:56.599Z","1.1.1":"2022-07-11T21:03:48.792Z","1.2.0-alpha.1":"2022-12-14T00:46:52.022Z","1.2.0":"2023-04-28T17:01:06.767Z","1.2.1-alpha.1":"2023-05-17T14:13:20.671Z","1.2.1-alpha.2":"2023-05-17T15:36:14.293Z"},"maintainers":[{"name":"ckoning","email":"chris@autocloud.dev"}],"description":"Policy pack implementing The National Institute of Standards and Technology 800-53 Rev. 4 Benchmark for Google Cloud services","homepage":"https://www.cloudgraph.dev/","keywords":["cloudgraph"],"repository":{"url":"git+https://github.com/cloudgraphdev/cloudgraph-policy-packs.git","directory":"src/gcp/nist-800-53-rev4"},"author":{"name":"AutoCloud"},"bugs":{"url":"https://github.com/cloudgraphdev/cloudgraph-policy-packs/issues"},"license":"MPL-2.0","readme":"","readmeFilename":""}