Interpretation of the Columns in Benchmark Compliance Rules:
Rule ID: A unique identifier for the specific security rule or check
Title: A brief description of the security issue or misconfiguration
Severity — Low to High: Determines the risk of being exposed to attacks
Service Type: The AWS service affected or evaluated by the rule
Resource Type: The specific AWS resource being audited
| Rule ID | Title | Severity | Service Type | Resource Type |
|---|---|---|---|---|
| CSPM-GCP-2025-0001 | Enable Deletion Protection for VM Instances | High | ComputeEngine | VMInstances |
| CSPM-GCP-2025-0002-01 | OS Login Disabled on Compute Instances | Medium | ComputeEngine | VMInstances |
| CSPM-GCP-2025-0002-02 | OS Login Disabled on Project Metadata | Medium | ComputeEngineGlobal | VMInstances |
| CSPM-GCP-2025-0003 | Datasets Publicly Accessible | Critical | BigQuery | Datasets |
| CSPM-GCP-2025-0004 | Dataset Not Encrypted with CMKs | Medium | BigQuery | Datasets |
| CSPM-GCP-2025-0005 | Instance Allows Root Login from Any Host | Critical | Cloud SQL Global | CloudSQL Users |
| CSPM-GCP-2025-0006 | Cloud SQL Missing Automated Backup | Medium | Cloud SQL | Instances |
| CSPM-GCP-2025-0007 | Cloud SQL Accessible from Public Ranges | Critical | Cloud SQL | Instances |
| CSPM-GCP-2025-0008 | Cloud SQL Public Internet Access | Critical | Cloud SQL | Instances |
| CSPM-GCP-2025-0010 | Cloud SQL Not Enforcing TLS/SSL | High | Cloud SQL | Instances |
| CSPM-GCP-2025-0011 | Missing Backup Protection | High | Cloud SQL | Instances |
| CSPM-GCP-2025-0012 | Cloud SQL Public Internet Access | Critical | Cloud SQL | Instances |
| CSPM-GCP-2025-0013 | MySQL Local Infile Enabled | High | Cloud SQL | Instances |
| CSPM-GCP-2025-0015 | PostgreSQL Log Connections Off | Medium | Cloud SQL | Instances |
| CSPM-GCP-2025-0018 | Log Min Duration Statement Not Set | Medium | Cloud SQL | Instances |
| CSPM-GCP-2025-0020 | SQL Server Remote Access Enabled | High | Cloud SQL | Instances |
| CSPM-GCP-2025-0021 | Contained DB Authentication Enabled | High | Cloud SQL | Instances |
| CSPM-GCP-2025-0022 | Cross DB Ownership Chaining Enabled | High | Cloud SQL | Instances |
| CSPM-GCP-2025-0023 | Storage Bucket Public Access | Critical | Cloud Storage Global | BucketPolicy |
| CSPM-GCP-2025-0027 | Uniform Bucket Access Disabled | High | Cloud Storage | Buckets |
| CSPM-GCP-2025-0028 | Insecure Default Firewall Rules | High | Network Security | Firewalls |
| CSPM-GCP-2025-0029 | Firewall Allows All Ports | Critical | Network Security | Firewalls |
| CSPM-GCP-2025-0030 | Unrestricted DNS Firewall Access | High | Network Security | Firewalls |
| CSPM-GCP-2025-0031 | Unrestricted FTP Firewall Access | High | Network Security | Firewalls |
| CSPM-GCP-2025-0035 | Project-wide SSH Keys Enabled | High | ComputeEngine | VMInstances |
| CSPM-GCP-2025-0036 | Serial Port Access Enabled | High | ComputeEngine | VMInstances |
| CSPM-GCP-2025-0037 | Default Service Account Used | High | ComputeEngine | VMInstances |
| CSPM-GCP-2025-0041 | IP Forwarding Enabled | Medium | ComputeEngine | VMInstances |
| CSPM-GCP-2025-0044 | Shielded VM Disabled | High | ComputeEngine | VMInstances |
| CSPM-GCP-2025-0056 | Cloud Functions HTTP Access | Medium | Cloud Functions | Functions |
| CSPM-GCP-2025-0058 | Cloud Function Public Access | Critical | Cloud Functions | Functions |
| CSPM-GCP-2025-0062 | Non-Workspace Account in Use | Medium | IAM | Policies |
| CSPM-GCP-2025-0063 | Service Account Keys Not Rotated | High | IAM | Keys |
| CSPM-GCP-2025-0069 | Service Account Admin Privileges | Critical | IAM | IAM |
| CSPM-GCP-2025-0071 | User-Managed SA Keys | Critical | IAM | Keys |
| CSPM-GCP-2025-0073 | KMS Keys Publicly Accessible | Critical | Cloud KMS Global | Policies |
| CSPM-GCP-2025-0074 | KMS Rotation Missing | Medium | Cloud KMS | Keys |
| CSPM-GCP-2025-0075 | GKE Basic Auth Enabled | High | Kubernetes Engine | Clusters |
| CSPM-GCP-2025-0082 | Missing Master Authorized Networks | High | Kubernetes Engine | Clusters |
| CSPM-GCP-2025-0094 | GKE Legacy Authorization Enabled | High | Kubernetes Engine | Clusters |
| CSPM-GCP-2025-0103 | Redis AUTH Disabled | High | Cloud Memorystore | RedisInstances |
| CSPM-GCP-2025-0105 | Missing Log Metric (Audit Changes) | High | Logging | Metrics |
| CSPM-GCP-2025-0128 | Privileged SA Roles Assigned | Critical | IAM | IAM |
| CSPM-GCP-2025-0130 | Cloud Storage Public Bucket | Critical | Cloud Storage Global | BucketPolicy |
| CSPM-GCP-2025-0189 | Unrestricted SSH Port 22 | Critical | Network Security | Firewalls |
| CSPM-GCP-2025-0262 | Unrestricted RDP | Critical | Network Security | Firewalls |
| CSPM-GCP-2025-0275 | Unrestricted Egress All Ports | Critical | Network Security | Firewalls |
| CSPM-GCP-2025-0282 | Kubernetes API Server Exposed | Critical | Network Security | Firewalls |
| CSPM-GCP-2025-0113 | Ensure that sinks are configured for all Log Entries | Medium | Logging | Sinks |
| CSPM-GCP-2025-0114 | Alerts doesn’t exist for audit configuration changes | Medium | Monitoring | AlertPolicies |
| CSPM-GCP-2025-0115 | Alerts doesn’t exist for cloud storage IAM permission changes | Medium | Monitoring | AlertPolicies |
| CSPM-GCP-2025-0116 | Alerts doesn’t exist for Custom Role Changes | Medium | Monitoring | AlertPolicies |
| CSPM-GCP-2025-0117 | Alerts doesn’t exist for project ownership assignments/changes | High | Monitoring | AlertPolicies |
| CSPM-GCP-2025-0118 | Alerts doesn’t exist for SQL Instance Configuration Changes | Medium | Monitoring | AlertPolicies |
| CSPM-GCP-2025-0119 | Alerts don’t exist for VPC Network Changes | Medium | Monitoring | AlertPolicies |
| CSPM-GCP-2025-0120 | Alerts don’t exist for VPC Network Firewall Rule Changes | Medium | Monitoring | AlertPolicies |
| CSPM-GCP-2025-0121 | Alerts don’t exist for VPC Network Route Changes | Medium | Monitoring | AlertPolicies |
| CSPM-GCP-2025-0071 | User-Managed Service Account Keys | Critical | IAM | Keys |
| CSPM-GCP-2025-0114 | Alerts doesn’t exist for Audit Configuration changes | Medium | Monitoring | AlertPolicies |
| CSPM-GCP-2025-0113 | Ensure that sinks are Configured for All Log Entries | Medium | Logging | Sinks |
| CSPM-GCP-2025-0115 | Alerts doesn’t exist for Cloud Storage IAM Permission Changes | Medium | Monitoring | AlertPolicies |
| CSPM-GCP-2025-0116 | Alerts doesn’t exist for Custom Role changes | Medium | Monitoring | AlertPolicies |
| CSPM-GCP-2025-0117 | Alerts don’t exist for Project Ownership Assignments/Changes | High | Monitoring | AlertPolicies |
| CSPM-GCP-2025-0118 | Alerts don’t exist for SQL Instance Configuration Changes | Medium | Monitoring | AlertPolicies |
| CSPM-GCP-2025-0119 | Alerts Don’t exist for VPC Network Changes | Medium | Monitoring | AlertPolicies |
| CSPM-GCP-2025-0120 | Alerts don’t exist for VPC Network Firewall Rule Changes | Medium | Monitoring | AlertPolicies |
| CSPM-GCP-2025-0121 | Alerts don’t exist for VPC Network Route Changes | Medium | Monitoring | AlertPolicies |
