<  Back to rules search

GCP Cloud SQL database modified

gcp

Classification:

compliance

Goal

Detect when a Cloud SQL DB has been modified.

Strategy

This rule lets you monitor GCP Cloud SQL admin activity audit logs to determine when one of the following methods are invoked:

  • cloudsql.instances.create
  • cloudsql.instances.create
  • cloudsql.users.update

Triage and response

  1. Review the Cloud SQL DB and ensure it is configured properly with the correct permissions.