Skip to content

Latest commit

 

History

History
19 lines (13 loc) · 787 Bytes

service-account-separation.md

File metadata and controls

19 lines (13 loc) · 787 Bytes

CloudSploit

GOOGLE / IAM / Service Account Separation

Quick Info

Plugin Title Service Account Separation
Cloud GOOGLE
Category IAM
Description Ensures that no users have both the Service Account User and Service Account Admin role.
More Info Ensuring that no users have both roles follows separation of duties, where no user should have access to resources out of the scope of duty.
GOOGLE Link https://cloud.google.com/iam/docs/overview
Recommended Action Ensure that no service accounts have both the Service Account User and Service Account Admin role attached.

Detailed Remediation Steps