Skip to main content
Technology areas
close
AI and ML
Application development
Application hosting
Compute
Data analytics and pipelines
Databases
Distributed, hybrid, and multicloud
Industry solutions
Migration
Networking
Observability and monitoring
Security
Storage
Cross-product tools
close
Access and resources management
Costs and usage management
Infrastructure as code
SDK, languages, frameworks, and tools
/
Console
English
Deutsch
Español – América Latina
Français
Indonesia
Italiano
Português – Brasil
עברית
中文 – 简体
中文 – 繁體
日本語
한국어
Sign in
Security Command Center
Start free
Overview
Guides
Reference
Samples
Resources
Technology areas
More
Overview
Guides
Reference
Samples
Resources
Cross-product tools
More
Console
Discover
Product overview
Service tiers
Activate Security Command Center
Overview of activating Security Command Center
Standard tier enhanced and automatically activated for some customers
Plan for the activation
Data and infrastructure security overview
Data residency
Plan for data residency
Security Command Center regional endpoints
Control access with IAM
Access control with IAM
Control access with organization-level activations
Control access with project-level activations
Configure custom organization policies
Enable CMEK for Security Command Center
Overview of VPC Service Controls and Security Command Center
Best practices
Security Command Center best practices
Cryptomining detection best practices
Activate Security Command Center Standard or Premium
Activate Security Command Center Standard tier for an organization
Activate Security Command Center Premium tier for an organization
Activate Security Command Center Standard or Premium for a project
Features available with project-level activations
Activate Security Command Center Enterprise for an organization
Activate Security Command Center Enterprise
Modify Security Command Center Enterprise tier
Connect to AWS for configuration and resource data collection
Connect to Azure for configuration and resource data collection
Control access to features in SecOps console pages
Map and authenticate users to enable SOAR-related features
Integrate Security Command Center Enterprise with ticketing systems
Connect to AWS for log data collection
Connect to Microsoft Azure for log data collection
Advanced configuration for threat management
Update the Enterprise use case for SOAR
Manage SOAR settings
Configure additional security services
Choose the services to enable
Configure security services
Provision Security Command Center resources with Terraform
Modify Security Command Center Standard or Premium tier
Modify the Security Command Center Standard tier
Modify the Security Command Center Premium tier
Modify data residency or data encryption configuration
Investigate findings, issues, and assets
Use Security Command Center in the Google Cloud console
Assess risk using Risk overview dashboards
Work with issues
Issues overview
Manage and remediate issues
Predefined security graph rules
Work with findings
Overview of findings
When to expect findings
Findings classes
Finding severities
Finding states
Review and manage findings in the console
Edit findings queries
Mute findings in Security Command Center
Mute findings overview
Manage mute rules
Mute individual findings
Migrate from static to dynamic mute rules
Annotate findings with security marks
Configure exports and notifications
Export Security Command Center data
Enable Pub/Sub notifications
Stream findings to BigQuery
Bulk export findings to BigQuery
Export logs to Cloud Logging
Enable real-time chat notifications
Work with assets and resources
Assets and resources overview
Inspect assets monitored by Security Command Center
Annotate assets with security marks
Explore the security graph using queries
Generate risk reports
Risk reports overview
Download risk reports
Gemini in Security Command Center
Manage security posture and compliance
Compliance Manager
Compliance Manager overview
Enable Compliance Manager
Manage frameworks
Framework reference
Manage cloud controls
Write rules for custom cloud controls
Cloud control reference
Cloud controls that support batch scanning only
Monitor your frameworks for compliance
Audit your environment
Audit locations for Compliance Manager
Use Compliance Manager with VPC Service Controls
Assess compliance without Compliance Manager (legacy)
Data security posture management
Data security posture management overview
Data security posture management in the Standard tier
Use data security posture management
Monitor your data security posture
Security posture service
Security posture overview
Manage a security posture
Manage security posture resources using custom constraints
Posture templates
BigQuery, essential
Cloud Storage, essential
Cloud Storage, extended
Secure by default, essential
Secure by default, extended
Secure AI, essential
Secure AI, extended
VPC networking, essential
VPC networking, extended
Compliance standards
CIS Benchmark 2.0
ISO 27001
NIST 800-53
PCI DSS
Detect vulnerabilities and misconfigurations
Services that detect software vulnerabilities
Detect possible attack paths with Risk Engine
Toxic combinations and chokepoints overview
Investigate toxic combinations and chokepoints
Overview of attack exposure scores and attack paths
Risk Engine feature support
Define and manage your high-value resource set
Security Health Analytics
Overview
Use Security Health Analytics
Remediate Security Health Analytics findings
Custom modules for Security Health Analytics
Overview of custom modules for Security Health Analytics
Use custom modules with Security Health Analytics
Code a custom module for Security Health Analytics
Test custom modules for Security Health Analytics
Artifact Registry vulnerability assessment
Cloud Infrastructure Entitlement Management (CIEM)
CIEM overview
Enable the CIEM detection service
Investigate identity and access findings
Review cases for identity and access issues
Vulnerability Assessment for Google Cloud
Enable and use Vulnerability Assessment for Google Cloud
Allow Vulnerability Assessment to access VPC Service Controls perimeters
Vulnerability Assessment for AWS
Overview
Enable and use Vulnerability Assessment for AWS
Modify or disable Vulnerability Assessment for AWS
Role policy for using Vulnerability Assessment with AWS
Sensitive data discovery
Sensitive data discovery overview
Enable and use sensitive data discovery
Web Security Scanner
Web Security Scanner overview
Use Web Security Scanner
Set up custom scans using Web Security Scanner
Remediate Web Security Scanner findings
Validate your infrastructure against organization policies
Validate IaC against organization policies
Supported asset types and policies for IaC validation
Integrate IaC validation with Cloud Build
Integrate IaC validation with Jenkins
Integrate IaC validation with GitHub Actions
Create a sample IaC validation report
Detect exposed resources
Investigate vulnerabilities
View vulnerability findings
Prioritize the remediation of vulnerabilities
Protect AI workloads and applications
Protect AI workloads with AI Protection
AI Protection overview
Configure AI Protection
Review AI security
Protect AI applications with Model Armor
Detect and respond to threats
Detect threats
Threat detection in Security Command Center
Detect threats to GKE containers
Container Threat Detection overview
Test Container Threat Detection
Use Container Threat Detection
Detect threats to Cloud Run containers
Cloud Run Threat Detection overview
Test Cloud Run Threat Detection
Use Cloud Run Threat Detection
Detect threats to agentic workloads
Agent Platform Threat Detection overview
Test Agent Platform Threat Detection
Use Agent Platform Threat Detection
Detect threats from event logging
Event Threat Detection overview
Test Event Threat Detection
Use Event Threat Detection
Allow Event Threat Detection to access VPC Service Controls perimeters
Custom modules for Event Threat Detection
Overview of custom modules for Event Threat Detection
Create and manage custom modules
Detect and review sensitive actions
Sensitive Actions Service overview
Test Sensitive Actions
Use Sensitive Actions
Detect threats to VMs
Virtual Machine Threat Detection overview
Use Virtual Machine Threat Detection
Allow VM Threat Detection to access VPC Service Controls perimeters
Enable Virtual Machine Threat Detection for AWS
Inspect a VM for signs of kernel memory tampering
Detect external anomalies
Identify correlated threats
Correlated Threats overview
Test Correlated Threats
Investigate and respond to threats
Overview
Respond to AI threats
Respond to Cloud Run threats
Respond to Compute Engine threats
Respond to Google Kubernetes Engine threats
Respond to Google Workspace threats
Respond to network threats
Investigate threats with curated detections
Secure code and integrate with CI/CD
Assured Open Source Software (Assured OSS) for code security
Integrate with Assured OSS for code security
Configure Assured OSS support for VPC Service Controls
Configure and download packages from a remote repository
Download packages from Artifact Registry
Download Go packages
Download Java packages
Download NPM packages
Download Python packages
Access security metadata and verify packages
Security metadata fields
Supported packages
List of supported Go packages
List of supported Java and Python packages
List of supported NPM packages
Create Artifact Guard policies
Overview of Artifact Guard
Configure CI/CD integration
Configure Artifact Guard policies
Artifact guard roles and permissions
Detect package vulnerabilities in Colab Enterprise notebooks
Enable and use Notebook Security Scanner
View Python package vulnerabilities
Additional configuration
Integrate with other products
Google Security Operations SOAR
Cortex XSOAR
Elastic Stack
Elastic Stack using Docker
Jira
QRadar
ServiceNow
Snyk
Splunk
Connect to other cloud providers in the Enterprise tier
Amazon Web Services (AWS)
Connect to AWS for configuration and resource data collection
Modify the connector for AWS
Microsoft Azure
Connect to Azure for configuration and resource data collection
Modify the connector for Azure
Use Mandiant Attack Surface Management with VPC Service Controls
Work with cases in the Enterprise tier
Work with cases
Cases overview
Using the workdesk
Determine ownership for posture findings
Group findings in cases
Mute findings in cases
Assign tickets in cases
Working with alerts
Work with playbooks
Playbooks overview
Automate IAM recommendations using playbooks
Enable public bucket remediation
Use the Security Command Center API
Create and manage findings
List security findings
Create and manage security findings
Manage security marks on findings and assets
Create, manage, and filter Notification Configs
Create and manage Notification Configs
Filter notifications
Create and manage security sources
Discover and list assets
Configure asset discovery
List assets
Monitor and troubleshoot
View audit logs
Security Command Center
Security Command Center Management
Compliance Manager
Web Security Scanner
Security Posture
Assured Open Source Software
Troubleshooting steps
Error messages
Frequently asked questions
AI and ML
Application development
Application hosting
Compute
Data analytics and pipelines
Databases
Distributed, hybrid, and multicloud
Industry solutions
Migration
Networking
Observability and monitoring
Security