GCP Bucket modified
Incident Management is now generally available! Incident Management is now generally available!
<  Back to rules search

GCP Bucket modified

gcp

Classification:

compliance

Set up the gcp integration.

Overview

Goal

Detect when an administrative change to a GCS Bucket has been made. This could change the retention policy or bucket lock. For more information, see the GCS Bucket Lock docs.

Strategy

This rule lets you monitor GCS bucket admin activity audit logs to determine if a bucket has been updated with the following method:

  • storage.buckets.update

Triage & Response

  1. Review the bucket to ensure that it is properly configured.