GCP Cloud SQL Database Modified
Security Monitoring is now available Security Monitoring is now available
<  Back to rules search

GCP Cloud SQL Database Modified

gcp

Classification:

compliance

Set up the gcp integration.

Overview

Goal

Detect when a Cloud SQL DB has been modified.

Strategy

This rule lets you monitor GCP Cloud SQL admin activity audit logs to determine when one of the following methods are invoked:

  • cloudsql.instances.create
  • cloudsql.instances.create
  • cloudsql.users.update

Triage & Response

  1. Review the Cloud SQL DB and ensure it is configured properly with the correct permissions.