Interpretation of the Columns in Benchmark Compliance Rules:
Rule ID: A unique identifier for the specific security rule or check
Title: A brief description of the security issue or misconfiguration
Severity — Low to High: Determines the risk of being exposed to attacks
Service Type: The AWS service affected or evaluated by the rule
Resource Type: The specific AWS resource being audited
| Rule ID | Title | Severity | Service Type | Resource Type |
|---|---|---|---|---|
| CSPM-GCP-2025-0001 | Enable Deletion Protection for VM Instances | Medium | ComputeEngine | VMInstances |
| CSPM-GCP-2025-0003 | Datasets Publicly Accessible | Critical | BigQuery | Datasets |
| CSPM-GCP-2025-0006 | Cloud SQL Instances without Automated Backup Configuration | Medium | Cloud SQL | Instances |
| CSPM-GCP-2025-0007 | Cloud SQL Instances accessible from Public Ranges | Critical | Cloud SQL | Instances |
| CSPM-GCP-2025-0010 | Cloud SQL Instances not enforcing TLS/SSL client connections | High | Cloud SQL | Instances |
| CSPM-GCP-2025-0035 | Block Project-Wide SSH Keys is not enabled | Medium | ComputeEngine | VMInstances |
| CSPM-GCP-2025-0036 | Serial Port Access is enabled | High | ComputeEngine | VMInstances |
| CSPM-GCP-2025-0037 | Instances configured to use Default Service Account | High | ComputeEngine | VMInstances |
| CSPM-GCP-2025-0056 | Cloud Functions not enforcing HTTPS-Only Access | Medium | Cloud Functions | Functions |
| CSPM-GCP-2025-0058 | Cloud Functions Accessible by “_ARG_0_” | Critical | Cloud Functions | Functions |
| CSPM-GCP-2025-0075 | GKE Clusters with Basic Authentication enabled | Medium | Kubernetes Engine | Clusters |
| CSPM-GCP-2025-0082 | GKE Clusters without Master Authorized Networks Protection | Critical | Kubernetes Engine | Clusters |
| CSPM-GCP-2025-0094 | GKE Clusters using Legacy Authorization Mode | Critical | Kubernetes Engine | Clusters |
| CSPM-GCP-2025-0103 | Redis Instance does not have AUTH enabled | Critical | Cloud Memorystore | RedisInstances |
| CSPM-GCP-2025-0122 | Confidential Computing Disabled | Medium | ComputeEngine | VMInstances |
| CSPM-GCP-2025-0131 | Dataproc Cluster VM disk encryption with customer-managed keys (gcePdKmsKeyName) Not Configured | High | Dataproc | DataprocClusters |
| CSPM-GCP-2025-0154 | GKE Clusters without gVisor Sandbox Protection | Medium | Kubernetes Engine | NodePools |
| CSPM-GCP-2025-0307 | Redis Cluster has Deletion Protection disabled | High | Cloud Memorystore | RedisClusters |
