Google Cloud Platform (GCP) logo

Google Cloud Platform (GCP)

AccessVulnerabilities
Cloud Provider

Mycroft tests your Google Cloud projects daily for IAM bindings, encryption keys, firewall rules and audit log coverage.

A broad role granted at the organization node reaches every project beneath it, which is what access reviews exist to catch. Mycroft reads configuration at organization or folder scope and ingests Security Command Center findings.

How Mycroft connects to Google Cloud

How it connects
You create a service account for the project you want covered and give Mycroft its key.
What Mycroft can access
Read-only. Mycroft reads project configuration and IAM policy through the service account, and does not write back.

Which controls Google Cloud evidence maps to

Each row is a control an auditor tests and the specific artifact Mycroft collects from Google Cloud to satisfy it. Collection runs on a schedule and every result is timestamped.

Google Cloud Platform (GCP) compliance control mappings and the evidence Mycroft collects for each
FrameworkControlWhat it requiresEvidence collected from Google Cloud
SOC 2CC6.1Logical access controls restrict access to information assets.IAM policy bindings at organization, folder and project scope, with primitive Owner and Editor grants and externally-owned members called out.
SOC 2CC6.3Access follows least privilege and is removed when no longer required.Service account inventory with key age and last-authentication time, plus user bindings reconciled against Google Workspace and your HR roster.
SOC 2CC6.6Access measures protect against external threats.VPC firewall rules with unrestricted ingress flagged; Cloud Storage buckets granting allUsers or allAuthenticatedUsers; public IP assignment on Compute instances and Cloud SQL.
SOC 2CC7.1Monitoring identifies configuration changes and vulnerabilities.Cloud Audit Logs configuration including Data Access log enablement, plus Security Command Center findings with severity and age.
ISO 27001A.5.23Information security for the use of cloud services is managed.Per-project configuration baseline across IAM, encryption, networking and logging, re-tested daily with results attributed to the project.
ISO 27001A.8.15Logs are produced, stored and protected against tampering.Log sink destinations, retention settings and bucket lock status on the log storage.
ISO 27001A.8.24Cryptographic controls protect information appropriately.Customer-managed encryption key usage on buckets, disks and Cloud SQL, with Cloud KMS rotation periods for each key.
HIPAA§164.312(a)(2)(iv)Encryption of ePHI at rest.Encryption state and key management for Cloud Storage buckets, persistent disks and Cloud SQL instances holding regulated workloads.
HIPAA§164.308(a)(1)(ii)(D)Regular review of information system activity records.Proof that Admin Activity and Data Access audit logs are enabled and retained for the projects in scope.

What Mycroft collects automatically

Gathered from Google Cloud on a schedule, dated and stored against the controls above.

  • IAM policy bindings at organization, folder and project level, including primitive role grants
  • Service account inventory with user-managed key age and last-use timestamps
  • Cloud Storage bucket public access, uniform bucket-level access and encryption configuration
  • VPC firewall rules with unrestricted ingress ranges identified
  • Cloud Audit Logs configuration, log sink destinations and retention
  • Cloud KMS key inventory with rotation periods
  • Security Command Center findings with severity, age and remediation state

Manual work this removes

The tasks that disappear from someone's quarter once Google Cloud is connected.

  • Enumerating IAM bindings project by project before each access review
  • Finding service account keys created for one-off tasks and never removed
  • Confirming Data Access audit logs are still enabled after org policy changes
  • Maintaining a bucket-by-bucket public access spreadsheet
  • Exporting Security Command Center findings to show they were reviewed

Google Cloud and Mycroft: frequently asked questions

A Google Cloud service account key you generate for the project you nominate. Mycroft reads project configuration and IAM policy through that service account and does not write back.
Yes, and that is the usual setup. Access granted at the organization or folder node means projects created afterwards inherit coverage automatically, which closes the most common evidence gap: a project spun up mid-period that nobody added to the review scope.
Google encrypts at rest by default, so the audit question is really about key management. Mycroft records which resources use customer-managed encryption keys, which Cloud KMS keys back them, and what rotation period each key carries. Those are the specifics an auditor asks for under ISO 27001 A.8.24 and HIPAA §164.312(a)(2)(iv).
No. Google Workspace is a separate identity integration covering users, groups, 2-Step Verification enforcement and admin roles, which is the workforce and account inventory behind access reviews. GCP covers cloud infrastructure. Teams on Google typically connect both.

We turn the compliance nightmare into a dream

Talk to us