部分 Security Command Center 功能 (例如偵測服務和發現項目類別) 無法在專案層級啟用,因為這些功能需要存取單一專案範圍外的記錄、資料、資源或其他服務。
如要在父項組織中啟用 Security Command Center Standard 級別,不過,專案層級啟用時,無法使用部分列出的功能。
啟用免費的 Security Command Center Standard 後,整個機構 (包括所有專案) 都能使用 Standard 級別的功能。
下列各節列出 Security Command Center 服務和發現項目類別,這些項目必須在組織層級啟用,才能使用服務層級。
在父機構中啟用「標準」層級後可使用的功能
本節列出您為專案層級啟用 Security Command Center Premium 時,可以啟用的功能。方法是在父項機構中啟用 Security Command Center Standard 方案。
安全狀態分析發現項目
如要在專案層級啟用 Security Command Center Premium,並啟用下列發現項目類別,請在父項組織中啟用 Security Command Center Standard 級別,這樣就能為組織中的所有專案啟用發現項目:
MFA not enforcedPublic log bucket
在專案層級啟用 Security Command Center 進階方案時,您可以透過在父項機構中啟用標準方案,啟用下列進階層級的發現項目類別:
Audit config not monitoredBucket IAM not monitoredCluster private Google access disabledCUSTOM_ORG_POLICY_VIOLATIONCustom role not monitoredDefault networkDNS logging disabledEgress deny rule not setFirewall not monitoredHTTP load balancerKMS project has ownerLegacy networkLocked retention policy not setLog not exportedNetwork not monitoredObject versioning disabledOrg policy Confidential VM policyOrg policy location restrictionOS login disabledOwner not monitoredPod security policy disabledRoute not monitoredSQL instance not monitoredToo many KMS usersWeak SSL policy
如需安全狀態分析發現項目的完整清單,請參閱「安全漏洞發現項目」。
Event Threat Detection 發現項目
在父項機構啟用 Security Command Center Standard 後,您就能在專案層級啟用 Security Command Center Premium 時,啟用下列進階級發現項目類別:
Exfiltration: BigQuery data extractionExfiltration: CloudSQL data exfiltration
如需 Event Threat Detection 發現項目類別的完整清單,請參閱「Event Threat Detection 規則」。
整合式 Google Cloud 服務
如要在專案層級啟用 Security Command Center Premium,並發布下列整合式Google Cloud 服務的調查結果,請在父項機構中啟用 Standard 方案,這樣一來,機構中的所有專案都會啟用這些服務:
如要在專案層級啟用進階方案,並發布下列整合式進階方案 Google Cloud 服務的發現項目,請在父項機構啟用 Security Command Center Standard:
與第三方服務整合
如要在專案層級啟用,請在父項機構中啟用 Security Command Center Standard 級別,即可發布第三方服務的調查結果。
專案層級啟用 Premium 方案後無法使用的功能
本節列出的功能屬於進階層級,必須在機構層級啟用 Security Command Center Premium 才能使用。這些功能不適用於專案層級的 Premium 方案啟用。
專案層級啟用時無法使用的安全狀態分析發現項目類別
如要查看下列安全狀態分析發現項目,必須在機構層級啟用 Security Command Center Premium:
Audit logging disabledKMS role separationRedis role used on orgService account role separation
如需安全狀態分析發現項目的完整清單,請參閱「安全漏洞發現項目」。
專案層級啟用時無法使用的 Event Threat Detection 發現項目類別
如要查看下列 Event Threat Detection 發現結果,必須在機構層級啟用 Security Command Center Premium:
Defense evasion: modify VPC service controlInitial access: account disabled hijackedInitial access: disabled password leakInitial access: government based attackInitial access: suspicious login blockedPersistence: new geographyPersistence: new user agentPersistence: SSO enablement togglePersistence: SSO settings changedPersistence: strong authentication disabledPersistence: two step verification disabledPrivilege escalation: external member added to privileged groupPrivilege escalation: privileged group opened to publicPrivilege escalation: sensitive role granted to hybrid groupPrivilege escalation: suspicious cross-project permission usePrivilege escalation: suspicious token generation
如需 Event Threat Detection 發現項目類別的完整清單,請參閱「Event Threat Detection 規則」。
在專案層級啟用時,無法使用「敏感動作服務」發現項目類別
如要查看下列 Sensitive Actions Service 發現項目,必須在機構層級啟用 Security Command Center 進階版:
Defense Evasion: Organization Policy ChangedDefense Evasion: Remove Billing AdminPersistence: Add Sensitive Role
如需敏感操作服務發現項目類別的完整清單,請參閱「敏感操作服務發現項目」。
攻擊路徑模擬
攻擊路徑模擬是進階方案的功能,無法在專案層級啟用 Security Command Center 時使用。攻擊路徑模擬會針對安全漏洞和錯誤設定發現項目,產生受攻擊風險分數和攻擊路徑。
圖表搜尋
圖表搜尋是進階方案的功能,無法在專案層級啟用 Security Command Center 時使用。圖表搜尋功能可讓您建立自訂查詢,探索安全性圖表,找出環境中潛在的安全疑慮。
安全防護機制
資安態勢管理是進階方案的功能,無法在專案層級啟用 Security Command Center。您可以透過資安態勢服務,定義、評估及監控Google Cloud的整體安全狀態。
資料落地設定
Security Command Center 在專案層級啟用時,不支援資料落地。您可以透過資料落地設定,指定部分 Security Command Center 資料在靜態、使用中和傳輸中的儲存位置。
Artifact Registry 安全漏洞評估
如要使用 Artifact Registry 安全漏洞評估功能,您必須在機構層級啟用 Security Command Center。