Skip to main content
Google Cloud Documentation
Technology areas
  • AI and ML
  • Application development
  • Application hosting
  • Compute
  • Data analytics and pipelines
  • Databases
  • Distributed, hybrid, and multicloud
  • Industry solutions
  • Migration
  • Networking
  • Observability and monitoring
  • Security
  • Storage
Cross-product tools
  • Access and resources management
  • Costs and usage management
  • Infrastructure as code
  • SDK, languages, frameworks, and tools
/
Console
  • English
  • Deutsch
  • Español
  • Español – América Latina
  • Français
  • Indonesia
  • Italiano
  • Português
  • Português – Brasil
  • עברית
  • 中文 – 简体
  • 中文 – 繁體
  • 日本語
  • 한국어
Sign in
  • Security Command Center
Start free
Overview Guides Reference Samples Resources
Google Cloud Documentation
  • Technology areas
    • More
    • Overview
    • Guides
    • Reference
    • Samples
    • Resources
  • Cross-product tools
    • More
  • Console
  • Discover
  • Product overview
  • Service tiers
  • Activate Security Command Center
  • Overview of activating Security Command Center
  • Standard tier enhanced and automatically activated for some customers
  • Plan for the activation
    • Data and infrastructure security overview
    • Data residency
      • Plan for data residency
      • Security Command Center regional endpoints
    • Control access with IAM
      • Access control with IAM
      • Control access with organization-level activations
      • Control access with project-level activations
    • Configure custom organization policies
    • Enable CMEK for Security Command Center
    • Overview of VPC Service Controls and Security Command Center
    • Best practices
      • Security Command Center best practices
      • Cryptomining detection best practices
  • Activate Security Command Center Standard or Premium
    • Activate Security Command Center Standard tier for an organization
    • Activate Security Command Center Premium tier for an organization
    • Activate Security Command Center Standard or Premium for a project
    • Features available with project-level activations
  • Activate Security Command Center Enterprise for an organization
    • Activate Security Command Center Enterprise
    • Modify Security Command Center Enterprise tier
    • Connect to AWS for configuration and resource data collection
    • Connect to Azure for configuration and resource data collection
    • Control access to features in SecOps console pages
    • Map and authenticate users to enable SOAR-related features
    • Integrate Security Command Center Enterprise with ticketing systems
    • Connect to AWS for log data collection
    • Connect to Microsoft Azure for log data collection
    • Advanced configuration for threat management
    • Update the Enterprise use case for SOAR
    • Manage SOAR settings
  • Configure additional security services
    • Choose the services to enable
    • Configure security services
    • Provision Security Command Center resources with Terraform
  • Modify Security Command Center Standard or Premium tier
    • Modify the Security Command Center Standard tier
    • Modify the Security Command Center Premium tier
    • Modify data residency or data encryption configuration
  • Investigate findings, issues, and assets
  • Use Security Command Center in the Google Cloud console
  • Assess risk using Risk overview dashboards
  • Work with issues
    • Issues overview
    • Manage and remediate issues
    • Predefined security graph rules
  • Work with findings
    • Overview of findings
      • When to expect findings
      • Findings classes
      • Finding severities
      • Finding states
    • Review and manage findings in the console
    • Edit findings queries
    • Mute findings in Security Command Center
      • Mute findings overview
      • Manage mute rules
      • Mute individual findings
      • Migrate from static to dynamic mute rules
    • Annotate findings with security marks
  • Configure exports and notifications
    • Export Security Command Center data
    • Enable Pub/Sub notifications
    • Stream findings to BigQuery
    • Bulk export findings to BigQuery
    • Export logs to Cloud Logging
    • Enable real-time chat notifications
  • Work with assets and resources
    • Assets and resources overview
    • Inspect assets monitored by Security Command Center
    • Annotate assets with security marks
  • Explore the security graph using queries
  • Generate risk reports
    • Risk reports overview
    • Download risk reports
  • Gemini in Security Command Center
  • Manage security posture and compliance
  • Compliance Manager
    • Compliance Manager overview
    • Enable Compliance Manager
    • Manage frameworks
    • Framework reference
    • Manage cloud controls
    • Write rules for custom cloud controls
    • Cloud control reference
    • Cloud controls that support batch scanning only
    • Monitor your frameworks for compliance
    • Audit your environment
    • Audit locations for Compliance Manager
    • Use Compliance Manager with VPC Service Controls
    • Assess compliance without Compliance Manager (legacy)
  • Data security posture management
    • Data security posture management overview
    • Data security posture management in the Standard tier
    • Use data security posture management
    • Monitor your data security posture
  • Security posture service
    • Security posture overview
    • Manage a security posture
    • Manage security posture resources using custom constraints
    • Posture templates
      • BigQuery, essential
      • Cloud Storage, essential
      • Cloud Storage, extended
      • Secure by default, essential
      • Secure by default, extended
      • Secure AI, essential
      • Secure AI, extended
      • VPC networking, essential
      • VPC networking, extended
    • Compliance standards
      • CIS Benchmark 2.0
      • ISO 27001
      • NIST 800-53
      • PCI DSS
  • Detect vulnerabilities and misconfigurations
  • Services that detect software vulnerabilities
  • Detect possible attack paths with Risk Engine
    • Toxic combinations and chokepoints overview
    • Investigate toxic combinations and chokepoints
    • Overview of attack exposure scores and attack paths
    • Risk Engine feature support
    • Define and manage your high-value resource set
  • Security Health Analytics
    • Overview
    • Use Security Health Analytics
    • Remediate Security Health Analytics findings
    • Custom modules for Security Health Analytics
      • Overview of custom modules for Security Health Analytics
      • Use custom modules with Security Health Analytics
      • Code a custom module for Security Health Analytics
      • Test custom modules for Security Health Analytics
  • Artifact Registry vulnerability assessment
  • Cloud Infrastructure Entitlement Management (CIEM)
    • CIEM overview
    • Enable the CIEM detection service
    • Investigate identity and access findings
    • Review cases for identity and access issues
  • Vulnerability Assessment for Google Cloud
    • Enable and use Vulnerability Assessment for Google Cloud
    • Allow Vulnerability Assessment to access VPC Service Controls perimeters
  • Vulnerability Assessment for AWS
    • Overview
    • Enable and use Vulnerability Assessment for AWS
    • Modify or disable Vulnerability Assessment for AWS
    • Role policy for using Vulnerability Assessment with AWS
  • Sensitive data discovery
    • Sensitive data discovery overview
    • Enable and use sensitive data discovery
  • Web Security Scanner
    • Web Security Scanner overview
    • Use Web Security Scanner
    • Set up custom scans using Web Security Scanner
    • Remediate Web Security Scanner findings
  • Validate your infrastructure against organization policies
    • Validate IaC against organization policies
    • Supported asset types and policies for IaC validation
    • Integrate IaC validation with Cloud Build
    • Integrate IaC validation with Jenkins
    • Integrate IaC validation with GitHub Actions
    • Create a sample IaC validation report
  • Detect exposed resources
  • Investigate vulnerabilities
    • View vulnerability findings
    • Prioritize the remediation of vulnerabilities
  • Protect AI workloads and applications
  • Protect AI workloads with AI Protection
    • AI Protection overview
    • Configure AI Protection
    • Review AI security
  • Protect AI applications with Model Armor
  • Detect and respond to threats
  • Detect threats
    • Threat detection in Security Command Center
    • Detect threats to GKE containers
      • Container Threat Detection overview
      • Test Container Threat Detection
      • Use Container Threat Detection
    • Detect threats to Cloud Run containers
      • Cloud Run Threat Detection overview
      • Test Cloud Run Threat Detection
      • Use Cloud Run Threat Detection
    • Detect threats to agentic workloads
      • Agent Platform Threat Detection overview
      • Test Agent Platform Threat Detection
      • Use Agent Platform Threat Detection
    • Detect threats from event logging
      • Event Threat Detection overview
      • Test Event Threat Detection
      • Use Event Threat Detection
      • Allow Event Threat Detection to access VPC Service Controls perimeters
      • Custom modules for Event Threat Detection
        • Overview of custom modules for Event Threat Detection
        • Create and manage custom modules
    • Detect and review sensitive actions
      • Sensitive Actions Service overview
      • Test Sensitive Actions
      • Use Sensitive Actions
    • Detect threats to VMs
      • Virtual Machine Threat Detection overview
      • Use Virtual Machine Threat Detection