---
title: Cloud Asset Inventory should be enabled
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: Docs > Datadog Security > OOTB Rules > Cloud Asset Inventory should be enabled
---

# Cloud Asset Inventory should be enabled
 
## Description{% #description %}

GCP Cloud Asset Inventory is a service that provides a historical view of GCP resources and IAM policies through a time-series database. The information recorded includes metadata on Google Cloud resources, metadata on policies set on Google Cloud projects or resources, and runtime information gathered within a Google Cloud resource.

## Rationale{% #rationale %}

The GCP resources and IAM policies captured by GCP Cloud Asset Inventory enables security analysis, resource change tracking, and compliance auditing. It is recommended GCP Cloud Asset Inventory be enabled for all GCP projects.

### Additional Information{% #additional-information %}

- Cloud Asset Inventory only keeps a five-week history of Google Cloud asset metadata. If you need a longer history, consider building automation to export the history to Cloud Storage or BigQuery.

### Default Value{% #default-value %}

The Cloud Asset Inventory API is disabled by default in each project.

## Remediation{% #remediation %}

### From the console{% #from-the-console %}

1. Go to **API & Services/Library** by visiting [https://console.cloud.google.com/apis/library](https://cloud.google.com/asset-inventory/docs)
1. Search for `Cloud Asset API` and select the result for Cloud Asset API
1. Click the **ENABLE** button.

### From the command line{% #from-the-command-line %}

1. Enable the Cloud Asset API through the services interface
   ```
   gcloud services enable cloudasset.googleapis.com
   ```

## References{% #references %}

1. [https://cloud.google.com/asset-inventory/docs](https://console.cloud.google.com/apis/library)
