Assured Workloads frameworks
This page provides reference content for the built-in frameworks that are included in Assured Workloads and Audit Manager.
Google Recommended AI Essentials - Gemini Enterprise Agent Platform
Supported cloud provider: Google Cloud
This framework outlines Google recommended security best practices for Gemini Enterprise Agent Platform workloads, providing a prescriptive collection of essential preventative and detective policies. When you acctivate AI Protection within the Security Command Center, a detailed security compliance assessment against this framework is automatically displayed on the Agent Platform Security dashboard.
This framework includes the following cloud controls:
- Block Default VPC Network for Agent Platform Workbench Instances
- Block File Downloading in JupyterLab Console
- Block Internet Access for Runtime Templates in Agent Platform Colab Enterprise
- Block Internet Access for Runtime Templates in Agent Platform Colab Enterprise
- Block Public IP Address for Agent Platform Workbench Instances
- Block Root Access on Agent Platform Workbench Instances
- Define Secret Manager Replication Policy
- Enable Audit Logging for Agent Platform
- Enable Automatic Upgrades for Agent Platform WorkBench Instances
- Enable CMEK for Agent Platform Custom Jobs
- Enable CMEK for Agent Platform Datasets
- Enable CMEK for Agent Platform Feature Store
- Enable CMEK for Agent Platform Hyperparameter Tuning Jobs
- Enable CMEK for Agent Platform instances
- Enable CMEK for Agent Platform Metadata Stores
- Enable CMEK for Agent Platform Model Endpoints
- Enable CMEK for Agent Platform Models
- Enable CMEK for Agent Platform TensorBoard
- Enable CMEK for Agent Platform Training Pipelines
- Enable CMEK for Agent Platform Workbench Instance Disks
- Enable CMEK for Runtime Templates in Agent Platform Colab Enterprise
- Enable Delete to Trash Feature for Agent Platform Workbench Instances
- Enable Integrity Monitoring for Agent Platform Workbench Instances
- Enable Model Armor
- Enable Secure Boot for Agent Platform Workbench Instances
- Enable Secure Boot for Runtime Templates in Agent Platform Colab Enterprise
- Enable vTPM on Agent Platform Workbench Instances
- Restrict the Use of Default Service Account for Agent Platform Workbench Instances
- Use labels for Agent Platform agents
CIS GCP Foundations Benchmark v3.0
Supported cloud provider: Google Cloud
Prescriptive guidance for establishing a secure baseline configuration for Google Cloud Platform. This benchmark provides technical best practices for hardening foundational services like IAM, Logging, Networking, and Storage.
This framework includes the following cloud controls:
- Avoid RSASHA1 for DNSSEC Signing
- Block Generic Access to RDP Ports
- Block Generic Access to SSH Ports
- Block Project-Wide SSH Keys on Compute Engine Instances
- Block Public IP Addresses for Cloud SQL Instances
- Block Serial Ports for Compute Engine Instances
- Define Essential Contacts
- Don't Use User Connections Flag for SQL Server
- Don't Use User Options Flag for SQL Server
- Enable 3625 Trace Database Flag for SQL Server
- Enable Automatic Backups for Cloud SQL Databases
- Enable Cloud Asset Inventory Service
- Enable CMEK for BigQuery Datasets
- Enable CMEK for BigQuery Tables
- Enable Confidential Computing for Compute Engine Instances
- Enable CSEK On Compute Engine Persistent Disks
- Enable DNSSEC for Cloud DNS
- Enable Flow Logs for VPC Subnet
- Enable Load Balancer Logging
- Enable Log Connections Flag for PostgreSQL
- Enable Log Disconnections Flag for PostgreSQL
- Enable Log Error Verbosity Flag for PostgreSQL
- Enable Log Min Error Statement Flag for PostgreSQL
- Enable Log Min Messages Flag for PostgreSQL
- Enable Log Statement Flag for PostgreSQL
- Enable Shielded VM for Compute Engine Instances
- Enable Skip Show Database Flag for MySQL
- Enable Uniform Bucket-Level Access on Cloud Storage Buckets
- Lock Storage Bucket Retention Policies
- Prevent IP Forwarding on Compute Engine Instances
- Require CMEK on Dataproc Clusters
- Require Rotation of API Key
- Require Service Account Key Rotation
- Restrict API Access to Google Cloud APIs for Compute Engine Instances
- Restrict API Keys for Required APIs Only
- Restrict Insecure SSL Policies for Compute Engine Instances
- Restrict Public Access to BigQuery Datasets
- Restrict Public Access to Cloud SQL Database Instances
- Restrict Public Access to Cloud Storage Buckets
- Restrict Public IP Addresses to Compute Engine Instances
- Restrict User Managed Service Account Keys
- Set Application Restriction on API Keys
- Turn Off Contained Database Authentication Flag for SQL Server
- Turn Off Cross Database Ownership Chaining Flag for SQL Server
- Turn Off External Scripts Flag for SQL Server
- Turn Off Local Infile Flag for MySQL
- Turn Off Log Min Duration Statement Flag for PostgreSQL
- Turn Off Remote Access Flag for SQL Server
- Use Custom Service Accounts for Compute Engine Instances
- Use Custom VPC Networks
CIS GKE 1.7
Supported cloud provider: Google Cloud
The CIS GKE Benchmark is a set of security recommendations and best practices specifically tailored for Google Kubernetes Engine (GKE) clusters. The benchmark aims to enhance the security posture of GKE environments.
This framework includes the following cloud controls:
- Block Legacy Authorization on GKE Clusters
- Disable Alpha Features on GKE Clusters
- Disable Client Certificate Authentication for GKE
- Disable Legacy Metadata Server Endpoints on Compute Engine
- Don't Use Kubernetes Web UI
- Enable Auto Repair for GKE Clusters
- Enable Auto Upgrade on GKE Clusters
- Enable Cloud Logging on GKE Clusters
- Enable Cloud Monitoring on GKE Clusters
- Enable CMEK on GKE Node Pool Boot Disks
- Enable Control Plane Authorized Networks on GKE Clusters
- Enable Encryption on GKE Clusters
- Enable Integrity Monitoring on GKE Clusters
- Enable Intranode Visibility for GKE Clusters
- Enable IP Alias Range for GKE Clusters
- Enable Network Policy on GKE Clusters
- Enable PodSecurityPolicies for GKE Clusters
- Enable Private Clusters for GKE
- Enable Secure Boot for Shielded GKE Nodes
- Enable Shielded GKE Nodes on a Cluster
- Enable Workload Identity Federation for GKE on clusters
- Require Container-Optimized OS for a GKE Cluster
- Require GKE Sandbox for GKE clusters
- Require Private Nodes in GKE Clusters
- Require Workload Identity Federation for GKE and the GKE Metadata Server
- Subscribe a GKE Cluster to a Release Channel
- Use Google Groups for Kubernetes RBAC
- Use Least Privilege Service Accounts for GKE Clusters
CIS Critical Security Controls v8
Supported cloud provider: Google Cloud
A prioritized set of safeguards to protect against prevalent cyber threats. It offers a practical approach to cyber defense, tiered into Implementation Groups (IG1, IG2, IG3) to suit organizations of varying maturity.
This framework includes the cloud control groups and cloud controls in the following sections.
cis-controls-1-1
Establish and maintain an accurate, detailed, and up-to-date inventory of all enterprise assets with the potential to store or process data, to include: end-user devices (including portable and mobile), network devices, non-computing/IoT devices, and servers. Ensure the inventory records the network address (if static), hardware address, machine name, enterprise asset owner, department for each asset, and whether the asset has been approved to connect to the network. For mobile end-user devices, MDM type tools can support this process, where appropriate. This inventory includes assets connected to the infrastructure physically, virtually, remotely, and those within cloud environments. Additionally, it includes assets that are regularly connected to the enterprise’s network infrastructure, even if they are not under control of the enterprise. Review and update the inventory of all enterprise assets bi-annually, or more frequently.
- Create and Manage Asymmetric Keys
- Define Set Storage Class Lifestyle Action on Bucket
- Enable Cloud Asset Inventory Service
cis-controls-10-2
Configure automatic updates for anti-malware signature files on all enterprise assets.
- Enable Object Versioning on Buckets
- Enable Subnet Flow Logs
- Enable VPC Flow Logs for Compute Engine Instances
cis-controls-10-3
Disable autorun and autoplay auto-execute functionality for removable media.
cis-controls-10-6
Centrally manage anti-malware software.