
Google Cloud Platform (GCP)
AccessVulnerabilities
Cloud Provider
Mycroft tests your Google Cloud projects daily for IAM bindings, encryption keys, firewall rules and audit log coverage.
A broad role granted at the organization node reaches every project beneath it, which is what access reviews exist to catch. Mycroft reads configuration at organization or folder scope and ingests Security Command Center findings.
How Mycroft connects to Google Cloud
- How it connects
- You create a service account for the project you want covered and give Mycroft its key.
- What Mycroft can access
- Read-only. Mycroft reads project configuration and IAM policy through the service account, and does not write back.
Which controls Google Cloud evidence maps to
Each row is a control an auditor tests and the specific artifact Mycroft collects from Google Cloud to satisfy it. Collection runs on a schedule and every result is timestamped.
| Framework | Control | What it requires | Evidence collected from Google Cloud |
|---|---|---|---|
| SOC 2 | CC6.1 | Logical access controls restrict access to information assets. | IAM policy bindings at organization, folder and project scope, with primitive Owner and Editor grants and externally-owned members called out. |
| SOC 2 | CC6.3 | Access follows least privilege and is removed when no longer required. | Service account inventory with key age and last-authentication time, plus user bindings reconciled against Google Workspace and your HR roster. |
| SOC 2 | CC6.6 | Access measures protect against external threats. | VPC firewall rules with unrestricted ingress flagged; Cloud Storage buckets granting allUsers or allAuthenticatedUsers; public IP assignment on Compute instances and Cloud SQL. |
| SOC 2 | CC7.1 | Monitoring identifies configuration changes and vulnerabilities. | Cloud Audit Logs configuration including Data Access log enablement, plus Security Command Center findings with severity and age. |
| ISO 27001 | A.5.23 | Information security for the use of cloud services is managed. | Per-project configuration baseline across IAM, encryption, networking and logging, re-tested daily with results attributed to the project. |
| ISO 27001 | A.8.15 | Logs are produced, stored and protected against tampering. | Log sink destinations, retention settings and bucket lock status on the log storage. |
| ISO 27001 | A.8.24 | Cryptographic controls protect information appropriately. | Customer-managed encryption key usage on buckets, disks and Cloud SQL, with Cloud KMS rotation periods for each key. |
| HIPAA | §164.312(a)(2)(iv) | Encryption of ePHI at rest. | Encryption state and key management for Cloud Storage buckets, persistent disks and Cloud SQL instances holding regulated workloads. |
| HIPAA | §164.308(a)(1)(ii)(D) | Regular review of information system activity records. | Proof that Admin Activity and Data Access audit logs are enabled and retained for the projects in scope. |
What Mycroft collects automatically
Gathered from Google Cloud on a schedule, dated and stored against the controls above.
- IAM policy bindings at organization, folder and project level, including primitive role grants
- Service account inventory with user-managed key age and last-use timestamps
- Cloud Storage bucket public access, uniform bucket-level access and encryption configuration
- VPC firewall rules with unrestricted ingress ranges identified
- Cloud Audit Logs configuration, log sink destinations and retention
- Cloud KMS key inventory with rotation periods
- Security Command Center findings with severity, age and remediation state
Manual work this removes
The tasks that disappear from someone's quarter once Google Cloud is connected.
- Enumerating IAM bindings project by project before each access review
- Finding service account keys created for one-off tasks and never removed
- Confirming Data Access audit logs are still enabled after org policy changes
- Maintaining a bucket-by-bucket public access spreadsheet
- Exporting Security Command Center findings to show they were reviewed
Google Cloud and Mycroft: frequently asked questions
What GCP permissions does Mycroft require?
Does connecting at the organization level cover new projects?
How does Mycroft evidence encryption in GCP?
Is Google Workspace the same integration?
We turn the compliance nightmare into a dream
Talk to us


