專案層級啟用後可用的功能

在專案層級啟用 Security Command Center 後,您就能管理個別專案中的安全性發現項目。不過,部分偵測服務和尋找類別需要超出單一專案範圍的存取權。在父項機構層級啟用標準層級,即可開啟特定跨專案功能,但如要使用其他機構層級功能,則須在機構層級啟用 Premium 層級。

在上層機構啟用標準層級後可使用的功能

本節列出在父項機構中啟用 Security Command Center Standard 方案後,可為專案層級啟用的 Security Command Center Premium 方案啟用的功能。

安全狀態分析發現項目

如要在專案層級啟用 Security Command Center Premium 時啟用下列發現項目類別,請在父項機構中啟用 Security Command Center Standard 方案,這樣機構中的所有專案都會啟用發現項目:

  • MFA not enforced
  • Public log bucket

在專案層級啟用 Security Command Center Premium 時,您可以透過在父項機構啟用標準層級,啟用下列進階層級的發現項目類別:

  • Audit config not monitored
  • Bucket IAM not monitored
  • Cluster private Google access disabled
  • CUSTOM_ORG_POLICY_VIOLATION
  • Custom role not monitored
  • Default network
  • DNS logging disabled
  • Egress deny rule not set
  • Firewall not monitored
  • HTTP load balancer
  • KMS project has owner
  • Legacy network
  • Locked retention policy not set
  • Log not exported
  • Network not monitored
  • Object versioning disabled
  • Org policy Confidential VM policy
  • Org policy location restriction
  • OS login disabled
  • Owner not monitored
  • Pod security policy disabled
  • Route not monitored
  • SQL instance not monitored
  • Too many KMS users
  • Weak SSL policy

如需安全狀態分析發現項目的完整清單,請參閱「安全漏洞發現項目」。

Event Threat Detection 發現項目

在專案層級啟用 Security Command Center 進階方案時,只要在父項機構中啟用 Security Command Center 標準方案,即可啟用下列進階方案的發現項目類別:

  • Exfiltration: BigQuery data extraction
  • Exfiltration: CloudSQL data exfiltration

如需 Event Threat Detection 發現項目類別的完整清單,請參閱「Event Threat Detection 規則」。

整合式 Google Cloud 服務

如要在專案層級啟用 Security Command Center Premium,並發布下列整合式Google Cloud 服務的調查結果,請在父項機構啟用 Standard 方案,這樣一來,機構中的所有專案都會啟用這些服務:

如要在專案層級啟用 Premium 方案,並發布下列整合式 Premium 方案 Google Cloud 服務的發現項目,請在父項機構啟用 Security Command Center Standard:

與第三方服務整合

如要在專案層級啟用,請在父項機構中啟用 Security Command Center Standard 級別,即可發布第三方服務的發現項目。

專案層級啟用 Premium 方案後無法使用的功能

本節列出的功能屬於進階級功能,需要啟用機構層級的 Security Command Center Premium 才能使用。這些功能不適用於專案層級的 Premium 方案啟用。

專案層級啟用時無法使用的安全狀態分析結果類別

如要查看下列安全狀態分析發現項目,必須在機構層級啟用 Security Command Center 進階版:

  • Audit logging disabled
  • KMS role separation
  • Redis role used on org
  • Service account role separation

如需安全狀態分析發現項目的完整清單,請參閱「安全漏洞發現項目」。

在專案層級啟用時,無法使用 Event Threat Detection 發現項目類別

如要查看下列 Event Threat Detection 發現項目,必須在機構層級啟用 Security Command Center 進階版:

  • Defense evasion: modify VPC service control
  • Initial access: account disabled hijacked
  • Initial access: disabled password leak
  • Initial access: government based attack
  • Initial access: suspicious login blocked
  • Persistence: new geography
  • Persistence: new user agent
  • Persistence: SSO enablement toggle
  • Persistence: SSO settings changed
  • Persistence: strong authentication disabled
  • Persistence: two step verification disabled
  • Privilege escalation: external member added to privileged group
  • Privilege escalation: privileged group opened to public
  • Privilege escalation: sensitive role granted to hybrid group
  • Privilege escalation: suspicious cross-project permission use
  • Privilege escalation: suspicious token generation

如需 Event Threat Detection 發現項目類別的完整清單,請參閱「Event Threat Detection 規則」。

在專案層級啟用時,無法使用「敏感動作服務」發現項目類別

如要查看下列敏感動作服務發現項目,必須在機構層級啟用 Security Command Center 進階方案:

  • Defense Evasion: Organization Policy Changed
  • Defense Evasion: Remove Billing Admin
  • Persistence: Add Sensitive Role

如需敏感動作服務發現項目的完整類別清單,請參閱「敏感動作服務發現項目」。

攻擊路徑模擬

攻擊路徑模擬是進階級的功能,如果是在專案層級啟用 Security Command Center,就無法使用這項功能。攻擊路徑模擬會針對安全漏洞和錯誤設定的發現項目,產生受攻擊風險分數和攻擊路徑。

圖表搜尋

圖表搜尋是進階級功能,無法在專案層級啟用 Security Command Center 時使用。安全圖譜搜尋功能可讓您建立自訂查詢,探索安全圖譜,找出環境中潛在的安全性問題。

資安態勢

資安態勢管理是進階級的功能,如果是在專案層級啟用 Security Command Center,就無法使用這項功能。您可以透過資安態勢服務,定義、評估及監控Google Cloud的整體安全狀態。

資料落地設定

Security Command Center 在專案層級啟用時,不支援資料落地。您可以透過資料落地設定,指定部分 Security Command Center 資料在靜態、使用中和傳輸中的儲存位置。

Artifact Registry 安全漏洞評估

如要使用 Artifact Registry 安全漏洞評估功能,您必須在機構層級啟用 Security Command Center。