cloud-guardrails
cloud-guardrails copied to clipboard
Automate GR 1 and 2 MFA evidence collection via IdP API calls
Unfortunately GR 1, 2 are tricky and fully manual (not part of the guardrails code yet) - but they can be via Workspace API calls (like GCP Asset Inventory calls for services) Yes, these are usually via the federated IdP (azure ad for example or directly in Workspace) but for now the check is manual - verify MFA on the break glass accounts and MFA on the org is set via screen caps
any change/updates to this we should put in our evidence collection doc https://github.com/GoogleCloudPlatform/pbmm-on-gcp-onboarding/blob/main/docs/google-cloud-security-controls.md#01-protect-root--global-admins-account
or directly on the GR notes (1-2 weeks propagation time) https://github.com/canada-ca/cloud-guardrails/blob/master/EN/01_Protect-Root-Account.md