Skip to main content
Technology areas
close
AI and ML
Application development
Application hosting
Compute
Data analytics and pipelines
Databases
Distributed, hybrid, and multicloud
Industry solutions
Migration
Networking
Observability and monitoring
Security
Storage
Cross-product tools
close
Access and resources management
Costs and usage management
Infrastructure as code
SDK, languages, frameworks, and tools
/
Console
English
Deutsch
Español
Español – América Latina
Français
Indonesia
Italiano
Português
Português – Brasil
עברית
中文 – 简体
中文 – 繁體
日本語
한국어
Sign in
Security Command Center
Start free
Overview
Guides
Reference
Samples
Resources
Technology areas
More
Overview
Guides
Reference
Samples
Resources
Cross-product tools
More
Console
Discover
Product overview
Service tiers
Activate Security Command Center
Overview of activating Security Command Center
Standard tier enhanced and automatically activated for some customers
Plan for the activation
Data and infrastructure security overview
Data residency
Plan for data residency
Security Command Center regional endpoints
Control access with IAM
Access control with IAM
Control access with organization-level activations
Control access with project-level activations
Configure custom organization policies
Enable CMEK for Security Command Center
Overview of VPC Service Controls and Security Command Center
Best practices
Security Command Center best practices
Cryptomining detection best practices
Activate Security Command Center Standard or Premium
Activate Security Command Center Standard tier for an organization
Activate Security Command Center Premium tier for an organization
Activate Security Command Center Standard or Premium for a project
Features available with project-level activations
Activate Security Command Center Enterprise for an organization
Activate Security Command Center Enterprise
Modify Security Command Center Enterprise tier
Connect to AWS for configuration and resource data collection
Connect to Azure for configuration and resource data collection
Control access to features in SecOps console pages
Map and authenticate users to enable SOAR-related features
Integrate Security Command Center Enterprise with ticketing systems
Connect to AWS for log data collection
Connect to Microsoft Azure for log data collection
Advanced configuration for threat management
Update the Enterprise use case for SOAR
Manage SOAR settings
Configure additional security services
Choose the services to enable
Configure security services
Provision Security Command Center resources with Terraform
Modify Security Command Center Standard or Premium tier
Modify the Security Command Center Standard tier
Modify the Security Command Center Premium tier
Modify data residency or data encryption configuration
Investigate findings, issues, and assets
Use Security Command Center in the Google Cloud console
Assess risk using Risk overview dashboards
Work with issues
Issues overview
Manage and remediate issues
Predefined security graph rules
Work with findings
Overview of findings
When to expect findings
Findings classes
Finding severities
Finding states
Review and manage findings in the console
Edit findings queries
Mute findings in Security Command Center
Mute findings overview
Manage mute rules
Mute individual findings
Migrate from static to dynamic mute rules
Annotate findings with security marks
Configure exports and notifications
Export Security Command Center data
Enable Pub/Sub notifications
Stream findings to BigQuery
Bulk export findings to BigQuery
Export logs to Cloud Logging
Enable real-time chat notifications
Work with assets and resources
Assets and resources overview
Inspect assets monitored by Security Command Center
Annotate assets with security marks
Explore the security graph using queries
Generate risk reports
Risk reports overview
Download risk reports
Gemini in Security Command Center
Manage security posture and compliance
Compliance Manager
Compliance Manager overview
Enable Compliance Manager
Manage frameworks
Framework reference
Manage cloud controls
Write rules for custom cloud controls
Cloud control reference
Cloud controls that support batch scanning only
Monitor your frameworks for compliance
Audit your environment
Audit locations for Compliance Manager
Use Compliance Manager with VPC Service Controls
Assess compliance without Compliance Manager (legacy)
Data security posture management
Data security posture management overview
Data security posture management in the Standard tier
Use data security posture management
Monitor your data security posture
Security posture service
Security posture overview
Manage a security posture
Manage security posture resources using custom constraints
Posture templates
BigQuery, essential
Cloud Storage, essential
Cloud Storage, extended
Secure by default, essential
Secure by default, extended
Secure AI, essential
Secure AI, extended
VPC networking, essential
VPC networking, extended
Compliance standards
CIS Benchmark 2.0
ISO 27001
NIST 800-53
PCI DSS
Detect vulnerabilities and misconfigurations
Services that detect software vulnerabilities
Detect possible attack paths with Risk Engine
Toxic combinations and chokepoints overview
Investigate toxic combinations and chokepoints
Overview of attack exposure scores and attack paths
Risk Engine feature support
Define and manage your high-value resource set
Security Health Analytics
Overview
Use Security Health Analytics
Remediate Security Health Analytics findings
Custom modules for Security Health Analytics
Overview of custom modules for Security Health Analytics
Use custom modules with Security Health Analytics
Code a custom module for Security Health Analytics
Test custom modules for Security Health Analytics
Artifact Registry vulnerability assessment
Cloud Infrastructure Entitlement Management (CIEM)
CIEM overview
Enable the CIEM detection service
Investigate identity and access findings
Review cases for identity and access issues
Vulnerability Assessment for Google Cloud
Enable and use Vulnerability Assessment for Google Cloud
Allow Vulnerability Assessment to access VPC Service Controls perimeters
Vulnerability Assessment for AWS
Overview
Enable and use Vulnerability Assessment for AWS
Modify or disable Vulnerability Assessment for AWS
Role policy for using Vulnerability Assessment with AWS
Sensitive data discovery
Sensitive data discovery overview
Enable and use sensitive data discovery
Web Security Scanner
Web Security Scanner overview
Use Web Security Scanner
Set up custom scans using Web Security Scanner
Remediate Web Security Scanner findings
Validate your infrastructure against organization policies
Validate IaC against organization policies
Supported asset types and policies for IaC validation
Integrate IaC validation with Cloud Build
Integrate IaC validation with Jenkins
Integrate IaC validation with GitHub Actions
Create a sample IaC validation report
Detect exposed resources
Investigate vulnerabilities
View vulnerability findings
Prioritize the remediation of vulnerabilities
Protect AI workloads and applications
Protect AI workloads with AI Protection
AI Protection overview
Configure AI Protection
Review AI security
Protect AI applications with Model Armor
Detect and respond to threats
Detect threats
Threat detection in Security Command Center
Detect threats to GKE containers
Container Threat Detection overview
Test Container Threat Detection
Use Container Threat Detection
Detect threats to Cloud Run containers
Cloud Run Threat Detection overview
Test Cloud Run Threat Detection
Use Cloud Run Threat Detection
Detect threats to agentic workloads
Agent Platform Threat Detection overview
Test Agent Platform Threat Detection
Use Agent Platform Threat Detection
Detect threats from event logging
Event Threat Detection overview
Test Event Threat Detection
Use Event Threat Detection
Allow Event Threat Detection to access VPC Service Controls perimeters
Custom modules for Event Threat Detection
Overview of custom modules for Event Threat Detection
Create and manage custom modules
Detect and review sensitive actions
Sensitive Actions Service overview
Test Sensitive Actions
Use Sensitive Actions
Detect threats to VMs
Virtual Machine Threat Detection overview
Use Virtual Machine Threat Detection