Skip to content

Latest commit

 

History

History
112 lines (110 loc) · 9.67 KB

File metadata and controls

112 lines (110 loc) · 9.67 KB

Security Controls

Security Control File Name Resource Name
AC-1 ./namespaces/project-id-tier3.yaml cnrm-viewer-project-id-tier3
AC-1 ./namespaces/project-id-tier3.yaml cnrm-viewer-project-id-tier3
AC-1 ./namespaces/project-id-tier3.yaml cnrm-viewer-project-id-tier3
AC-1 ./namespaces/project-id-tier3.yaml cnrm-viewer-project-id-tier3
AC-1 ./namespaces/project-id-tier3.yaml project-id-tier3-sa
AC-1 ./namespaces/project-id-tier3.yaml project-id-tier3-sa-compute-public-ip-admin-project-id-permissions
AC-1 ./namespaces/project-id-tier3.yaml project-id-tier3-sa-compute-security-admin-project-id-permissions
AC-1 ./namespaces/project-id-tier3.yaml project-id-tier3-sa-securityadmin-project-id-permissions
AC-1 ./namespaces/project-id-tier3.yaml project-id-tier3-sa-serviceaccountadmin-project-id-permissions
AC-1 ./namespaces/project-id-tier3.yaml project-id-tier3-sa-tier3-dnsrecord-admin-dns-project-id-permissions
AC-1 ./namespaces/project-id-tier3.yaml project-id-tier3-sa-workload-identity-binding
AC-1 ./namespaces/project-id-tier3.yaml syncs-repo
AC-1 ./namespaces/project-id-tier4.yaml cnrm-viewer-project-id-tier4
AC-1 ./namespaces/project-id-tier4.yaml cnrm-viewer-project-id-tier4
AC-1 ./namespaces/project-id-tier4.yaml project-id-tier4-sa
AC-1 ./namespaces/project-id-tier4.yaml project-id-tier4-sa-workload-identity-binding
AC-1 ./namespaces/project-id-tier4.yaml syncs-repo
AC-1 ./project-iam.yaml client-name-config-control-sa-iamserviceaccountadmin-project-id-permissions
AC-1 ./project-iam.yaml client-name-config-control-sa-iamserviceaccountadmin-project-id-permissions
AC-1 ./shared-vpc/namespaces/project-id-tier3.yaml project-id-tier3-sa-tier3-firewallrule-admin-app-infra-class-folder-permissions
AC-1 ./shared-vpc/namespaces/project-id-tier3.yaml project-id-tier3-sa-tier3-firewallrule-admin-app-infra-class-folder-permissions
AC-1 ./shared-vpc/namespaces/project-id-tier4.yaml project-id-tier4-sa-networkuser-allowed-nane1-main-subnet-permissions
AC-1 ./shared-vpc/namespaces/project-id-tier4.yaml project-id-tier4-sa-networkuser-allowed-nane1-main-subnet-permissions
AC-1 ./shared-vpc/namespaces/project-id-tier4.yaml project-id-tier4-sa-networkuser-allowed-nane2-main-subnet-permissions
AC-16(2) ./namespaces/project-id-tier3.yaml cnrm-viewer-project-id-tier3
AC-16(2) ./namespaces/project-id-tier3.yaml cnrm-viewer-project-id-tier3
AC-16(2) ./namespaces/project-id-tier3.yaml cnrm-viewer-project-id-tier3
AC-16(2) ./namespaces/project-id-tier3.yaml cnrm-viewer-project-id-tier3
AC-16(2) ./namespaces/project-id-tier3.yaml configconnectorcontext.core.cnrm.cloud.google.com
AC-16(2) ./namespaces/project-id-tier3.yaml project-id-tier3-sa
AC-16(2) ./namespaces/project-id-tier3.yaml project-id-tier3-sa
AC-16(2) ./namespaces/project-id-tier3.yaml project-id-tier3-sa-compute-public-ip-admin-project-id-permissions
AC-16(2) ./namespaces/project-id-tier3.yaml project-id-tier3-sa-compute-security-admin-project-id-permissions
AC-16(2) ./namespaces/project-id-tier3.yaml project-id-tier3-sa-securityadmin-project-id-permissions
AC-16(2) ./namespaces/project-id-tier3.yaml project-id-tier3-sa-serviceaccountadmin-project-id-permissions
AC-16(2) ./namespaces/project-id-tier3.yaml project-id-tier3-sa-tier3-dnsrecord-admin-dns-project-id-permissions
AC-16(2) ./namespaces/project-id-tier3.yaml project-id-tier3-sa-workload-identity-binding
AC-16(2) ./namespaces/project-id-tier3.yaml syncs-repo
AC-16(2) ./namespaces/project-id-tier4.yaml cnrm-viewer-project-id-tier4
AC-16(2) ./namespaces/project-id-tier4.yaml cnrm-viewer-project-id-tier4
AC-16(2) ./namespaces/project-id-tier4.yaml configconnectorcontext.core.cnrm.cloud.google.com
AC-16(2) ./namespaces/project-id-tier4.yaml project-id-tier4-sa
AC-16(2) ./namespaces/project-id-tier4.yaml project-id-tier4-sa-workload-identity-binding
AC-16(2) ./namespaces/project-id-tier4.yaml syncs-repo
AC-16(2) ./project-iam.yaml client-name-config-control-sa-iamserviceaccountadmin-project-id-permissions
AC-16(2) ./project-iam.yaml client-name-config-control-sa-iamserviceaccountadmin-project-id-permissions
AC-16(2) ./shared-vpc/namespaces/project-id-tier3.yaml project-id-tier3-sa-tier3-firewallrule-admin-app-infra-class-folder-permissions
AC-16(2) ./shared-vpc/namespaces/project-id-tier3.yaml project-id-tier3-sa-tier3-firewallrule-admin-app-infra-class-folder-permissions
AC-16(2) ./shared-vpc/namespaces/project-id-tier4.yaml project-id-tier4-sa-networkuser-allowed-nane1-main-subnet-permissions
AC-16(2) ./shared-vpc/namespaces/project-id-tier4.yaml project-id-tier4-sa-networkuser-allowed-nane1-main-subnet-permissions
AC-16(2) ./shared-vpc/namespaces/project-id-tier4.yaml project-id-tier4-sa-networkuser-allowed-nane2-main-subnet-permissions
AC-3 ./namespaces/project-id-tier3.yaml cnrm-viewer-project-id-tier3
AC-3 ./namespaces/project-id-tier3.yaml cnrm-viewer-project-id-tier3
AC-3 ./namespaces/project-id-tier3.yaml cnrm-viewer-project-id-tier3
AC-3 ./namespaces/project-id-tier3.yaml cnrm-viewer-project-id-tier3
AC-3 ./namespaces/project-id-tier3.yaml configconnectorcontext.core.cnrm.cloud.google.com
AC-3 ./namespaces/project-id-tier3.yaml project-id-tier3-sa
AC-3 ./namespaces/project-id-tier3.yaml project-id-tier3-sa
AC-3 ./namespaces/project-id-tier3.yaml project-id-tier3-sa-compute-public-ip-admin-project-id-permissions
AC-3 ./namespaces/project-id-tier3.yaml project-id-tier3-sa-compute-security-admin-project-id-permissions
AC-3 ./namespaces/project-id-tier3.yaml project-id-tier3-sa-securityadmin-project-id-permissions
AC-3 ./namespaces/project-id-tier3.yaml project-id-tier3-sa-serviceaccountadmin-project-id-permissions
AC-3 ./namespaces/project-id-tier3.yaml project-id-tier3-sa-tier3-dnsrecord-admin-dns-project-id-permissions
AC-3 ./namespaces/project-id-tier3.yaml project-id-tier3-sa-workload-identity-binding
AC-3 ./namespaces/project-id-tier3.yaml syncs-repo
AC-3 ./namespaces/project-id-tier4.yaml cnrm-viewer-project-id-tier4
AC-3 ./namespaces/project-id-tier4.yaml cnrm-viewer-project-id-tier4
AC-3 ./namespaces/project-id-tier4.yaml configconnectorcontext.core.cnrm.cloud.google.com
AC-3 ./namespaces/project-id-tier4.yaml project-id-tier4-sa
AC-3 ./namespaces/project-id-tier4.yaml project-id-tier4-sa-workload-identity-binding
AC-3 ./namespaces/project-id-tier4.yaml syncs-repo
AC-3 ./project-iam.yaml client-name-config-control-sa-iamserviceaccountadmin-project-id-permissions
AC-3 ./project-iam.yaml client-name-config-control-sa-iamserviceaccountadmin-project-id-permissions
AC-3 ./shared-vpc/namespaces/project-id-tier3.yaml project-id-tier3-sa-tier3-firewallrule-admin-app-infra-class-folder-permissions
AC-3 ./shared-vpc/namespaces/project-id-tier3.yaml project-id-tier3-sa-tier3-firewallrule-admin-app-infra-class-folder-permissions
AC-3 ./shared-vpc/namespaces/project-id-tier4.yaml project-id-tier4-sa-networkuser-allowed-nane1-main-subnet-permissions
AC-3 ./shared-vpc/namespaces/project-id-tier4.yaml project-id-tier4-sa-networkuser-allowed-nane1-main-subnet-permissions
AC-3 ./shared-vpc/namespaces/project-id-tier4.yaml project-id-tier4-sa-networkuser-allowed-nane2-main-subnet-permissions
AC-3(7) ./namespaces/project-id-tier3.yaml cnrm-viewer-project-id-tier3
AC-3(7) ./namespaces/project-id-tier3.yaml cnrm-viewer-project-id-tier3
AC-3(7) ./namespaces/project-id-tier3.yaml cnrm-viewer-project-id-tier3
AC-3(7) ./namespaces/project-id-tier3.yaml cnrm-viewer-project-id-tier3
AC-3(7) ./namespaces/project-id-tier3.yaml configconnectorcontext.core.cnrm.cloud.google.com
AC-3(7) ./namespaces/project-id-tier3.yaml project-id-tier3-sa
AC-3(7) ./namespaces/project-id-tier3.yaml project-id-tier3-sa
AC-3(7) ./namespaces/project-id-tier3.yaml project-id-tier3-sa-compute-public-ip-admin-project-id-permissions
AC-3(7) ./namespaces/project-id-tier3.yaml project-id-tier3-sa-compute-security-admin-project-id-permissions
AC-3(7) ./namespaces/project-id-tier3.yaml project-id-tier3-sa-securityadmin-project-id-permissions
AC-3(7) ./namespaces/project-id-tier3.yaml project-id-tier3-sa-serviceaccountadmin-project-id-permissions
AC-3(7) ./namespaces/project-id-tier3.yaml project-id-tier3-sa-tier3-dnsrecord-admin-dns-project-id-permissions
AC-3(7) ./namespaces/project-id-tier3.yaml project-id-tier3-sa-workload-identity-binding
AC-3(7) ./namespaces/project-id-tier3.yaml syncs-repo
AC-3(7) ./namespaces/project-id-tier4.yaml cnrm-viewer-project-id-tier4
AC-3(7) ./namespaces/project-id-tier4.yaml cnrm-viewer-project-id-tier4
AC-3(7) ./namespaces/project-id-tier4.yaml configconnectorcontext.core.cnrm.cloud.google.com
AC-3(7) ./namespaces/project-id-tier4.yaml project-id-tier4-sa
AC-3(7) ./namespaces/project-id-tier4.yaml project-id-tier4-sa-workload-identity-binding
AC-3(7) ./namespaces/project-id-tier4.yaml syncs-repo
AC-3(7) ./project-iam.yaml client-name-config-control-sa-iamserviceaccountadmin-project-id-permissions
AC-3(7) ./project-iam.yaml client-name-config-control-sa-iamserviceaccountadmin-project-id-permissions
AC-3(7) ./shared-vpc/namespaces/project-id-tier3.yaml project-id-tier3-sa-tier3-firewallrule-admin-app-infra-class-folder-permissions
AC-3(7) ./shared-vpc/namespaces/project-id-tier3.yaml project-id-tier3-sa-tier3-firewallrule-admin-app-infra-class-folder-permissions
AC-3(7) ./shared-vpc/namespaces/project-id-tier4.yaml project-id-tier4-sa-networkuser-allowed-nane1-main-subnet-permissions
AC-3(7) ./shared-vpc/namespaces/project-id-tier4.yaml project-id-tier4-sa-networkuser-allowed-nane1-main-subnet-permissions
AC-3(7) ./shared-vpc/namespaces/project-id-tier4.yaml project-id-tier4-sa-networkuser-allowed-nane2-main-subnet-permissions