בדף הזה מוסבר איך להשתמש בניהול זהויות והרשאות גישה (IAM) כדי לשלוט בגישה למשאבים בהפעלה של Security Command Center ברמת הפרויקט. צריך לעיין בדף הזה רק אם Security Command Center לא מופעל בארגון שלכם.
אם אחד מהתנאים הבאים מתקיים, כדאי לעיין במאמר IAM להפעלות ברמת הארגון במקום בדף הזה:
- Security Command Center מופעל ברמת הארגון ולא ברמת הפרויקט.
- מהדורת Standard של Security Command Center כבר מופעלת ברמת הארגון. בנוסף, הפעלתם את Security Command Center Premium בפרויקט אחד או יותר.
ב-Security Command Center נעשה שימוש בתפקידי IAM כדי לקבוע למי תהיה גישה לנכסים, לממצאים ולמקורות אבטחה בסביבת Security Command Center, ומה הם יוכלו לעשות איתם. אתם נותנים תפקידים לאנשים ולאפליקציות, וכל תפקיד מספק הרשאות ספציפיות.
הרשאות
כדי להגדיר את Security Command Center או לשנות את ההגדרה של הפרויקט, צריך את שני התפקידים הבאים:
- אדמין IAM בפרויקט (
roles/resourcemanager.projectIamAdmin) - אדמין של Security Center (
roles/securitycenter.admin)
אם משתמש לא צריך הרשאות עריכה, כדאי להקצות לו תפקידי צפייה.
כדי להציג את כל הנכסים והממצאים ב-Security Command Center, המשתמשים צריכים את התפקיד 'צפייה באדמין של Security Center' (roles/securitycenter.adminViewer). משתמשים שצריכים גם לראות את ההגדרות צריכים את התפקיד 'בעל הרשאת הצגה של הגדרות מרכז האבטחה' (roles/securitycenter.settingsViewer).
אפשר להגדיר את כל התפקידים האלה בכל רמה בהיררכיית המשאבים, אבל מומלץ להגדיר אותם ברמת הפרויקט. השיטה הזו תואמת להעקרון של הרשאות מינימליות.
הוראות לניהול תפקידים והרשאות מופיעות במאמר ניהול הגישה לפרויקטים, לתיקיות ולארגונים.
גישה שעוברת בירושה להפעלות של Security Command Center ברמת הפרויקט
פרויקט יורש את כל הקשרים בין תפקידים למשתמשים שהוגדרו ברמת התיקיות והארגון שמכילים את הפרויקט הזה. לדוגמה, אם לחשבון משתמש יש את התפקיד 'עריכת ממצאים ב-Security Center' (roles/securitycenter.findingsEditor) ברמת הארגון, לחשבון המשתמש הזה יש את אותו התפקיד ברמת הפרויקט.
אותו חשבון משתמש יכול להציג ולערוך ממצאים בכל הפרויקטים של הארגון שבהם Cloud Security Command Center פעיל.
באיור הבא מוצגת היררכיית משאבים של Security Command Center עם תפקידים שניתנו ברמת הארגון.
כדי לראות רשימה של חשבונות משתמשים שיש להם גישה לפרויקט, כולל אלה שקיבלו הרשאות בירושה, אפשר לעיין במאמר הצגת הגישה הנוכחית.
תפקידים ב-Security Command Center
אלה תפקידי ה-IAM שזמינים ל-Security Command Center. אפשר לתת את התפקידים האלה ברמת הארגון, התיקייה או הפרויקט.
| Role | Permissions |
|---|---|
Security Center Admin( Admin(super user) access to security center Lowest-level resources where you can grant this role:
|
|
Security Center Admin Editor( Admin Read-write access to security center Lowest-level resources where you can grant this role:
|
|
Security Center Admin Viewer( Admin Read access to security center Lowest-level resources where you can grant this role:
|
|
Security Center Asset Security Marks Writer( Write access to asset security marks Lowest-level resources where you can grant this role:
|
|
Security Center Assets Discovery Runner( Run asset discovery access to assets Lowest-level resources where you can grant this role:
|
|
Security Center Assets Viewer( Read access to assets Lowest-level resources where you can grant this role:
|
|
Security Center Attack Paths Reader( Read access to security center attack paths |
|
Security Center BigQuery Exports Editor( Read-Write access to security center BigQuery Exports |
|
Security Center BigQuery Exports Viewer( Read access to security center BigQuery Exports |
|
Security Center Compliance Reports Viewer Beta( Read access to security center compliance reports |
|
Security Center Compliance Snapshots Viewer Beta( Read access to security center compliance snapshots |
|
Security Center External Systems Editor( Write access to security center external systems |
|
Security Center Finding Security Marks Writer( Write access to finding security marks Lowest-level resources where you can grant this role:
|
|
Security Center Findings Bulk Mute Editor( Ability to mute findings in bulk |
|
Security Center Findings Editor( Read-write access to findings Lowest-level resources where you can grant this role:
|
|
Security Center Findings Mute Setter( Set mute access to findings |
|
Security Center Findings State Setter( Set state access to findings Lowest-level resources where you can grant this role:
|
|
Security Center Findings Viewer( Read access to findings Lowest-level resources where you can grant this role:
|
|
Security Center Findings Workflow State Setter Beta( Set workflow state access to findings Lowest-level resources where you can grant this role:
|
|
Security Center Issues Editor( Write access to security center issues |
|
Security Center Issues Viewer( Read access to security center issues |
|
Security Center Mute Configurations Editor( Read-Write access to security center mute configurations |
|
Security Center Mute Configurations Viewer( Read access to security center mute configurations |
|
Security Center Notification Configurations Editor( Write access to notification configurations Lowest-level resources where you can grant this role:
|
|
Security Center Notification Configurations Viewer( Read access to notification configurations Lowest-level resources where you can grant this role:
|
|
Security Center Resource Value Configurations Editor( Read-Write access to security center resource value configurations |
|
Security Center Resource Value Configurations Viewer( Read access to security center resource value configurations |
|
Security Center Risk Reports Viewer( Read access to security center risk reports |
|
Security Health Analytics Custom Modules Tester( Test access to Security Health Analytics Custom Modules |
|
Security Center Settings Admin( Admin(super user) access to security center settings Lowest-level resources where you can grant this role:
|
|
Security Center Settings Editor( Read-Write access to security center settings Lowest-level resources where you can grant this role:
|
|
Security Center Settings Viewer( Read access to security center settings Lowest-level resources where you can grant this role:
|
|
Security Center Simulations Reader( Read access to security center simulations |
|
Security Center Sources Admin( Admin access to sources Lowest-level resources where you can grant this role:
|
|
Security Center Sources Editor( Read-write access to sources Lowest-level resources where you can grant this role:
|
|
Security Center Sources Viewer( Read access to sources Lowest-level resources where you can grant this role:
|
|
Security Center Valued Resources Reader( Read access to security center valued resources |
|
Service agent roles
Service agent roles should only be granted to service agents.
| Role | Permissions |
|---|---|
Attack Surface Management Scanner Service Agent( Gives Mandiant Attack Surface Management the ability to scan Cloud Platform resources. |
|
Security Center Automation Service Agent( Security Center automation service agent can configure GCP resources to enable security scanning. |
|
Security Center Control Service Agent( Security Center Control service agent can monitor and configure GCP resources and import security findings. |
|
Security Center Integration Executor Service Agent( Gives Security Center access to execute Integrations. |
|
Security Center Notification Service Agent( Security Center service agent can publish notifications to Pub/Sub topics. |
|
Security Health Analytics Service Agent( Security Health Analytics service agent can scan GCP resource metadata to find security vulnerabilities. |
|
Google Cloud Security Response Service Agent( Gives Playbook Runner permissions to execute all Google authored Playbooks. This role will keep evolving as we add more playbooks |
|
Security Center Service Agent( Security Center service agent can scan GCP resources and import security scans. |
|
תפקידים ב-Security Command Center Management API
אלה תפקידי ה-IAM שזמינים ל-Security Command Center Management API. אפשר לתת את התפקידים האלה ברמת הארגון, התיקייה או הפרויקט.
| Role | Permissions |
|---|---|
Security Center Management Admin( Full access to manage Cloud Security Command Center services and custom modules configuration. |
|
Security Center Management Editor( Editor role for Security Center Management |
|
Security Center Management Viewer( Readonly access to Cloud Security Command Center services and custom modules configuration. |
|
Security Center Management Custom Modules Editor( Full access to manage Cloud Security Command Center custom modules. |
|
Security Center Management Custom Modules Viewer( Readonly access to Cloud Security Command Center custom modules. |
|
Security Center Management Custom ETD Modules Editor( Full access to manage Cloud Security Command Center ETD custom modules. |
|
Security Center Management ETD Custom Modules Viewer( Readonly access to Cloud Security Command Center ETD custom modules. |
|
Security Center Management Services Editor( Full access to manage Cloud Security Command Center services configuration. |
|
Security Center Management Services Viewer( Readonly access to Cloud Security Command Center services configuration. |
|
Security Center Management Settings Editor( Full access to manage Cloud Security Command Center settings |
|
Security Center Management Settings Viewer( Readonly access to Cloud Security Command Center settings |
|
Security Center Management SHA Custom Modules Editor( Full access to manage Cloud Security Command Center SHA custom modules. |
|
Security Center Management SHA Custom Modules Viewer( Readonly access to Cloud Security Command Center SHA custom modules. |
|
התפקידים של סוכן שירות
סוכן שירות מאפשר לשירות לגשת למשאבים שלכם.
אחרי שמפעילים את Security Command Center, נוצרים שני סוכני שירות, שהם סוג של חשבון שירות:
service-project-PROJECT_NUMBER@security-center-api..סוכן השירות הזה צריך את תפקיד ה-IAM
roles/securitycenter.serviceAgent.service-project-PROJECT_NUMBER@gcp-sa-ktd-hpsa..סוכן השירות הזה צריך את תפקיד ה-IAM
roles/containerthreatdetection.serviceAgent.
service-project-PROJECT_NUMBER@gcp-sa-csc-hpsa.(רק במסלול פרימיום)סוכן השירות הזה צריך את תפקיד ה-IAM
roles/cloudsecuritycompliance.serviceAgent.
כדי ש-Security Command Center יפעל, צריך להקצות לסוכני השירות את תפקידי ה-IAM הנדרשים. תתבקשו להעניק את התפקידים במהלך תהליך ההפעלה של Security Command Center.
כדי לראות את ההרשאות של כל תפקיד, אפשר לעיין במאמרים הבאים:
כדי להעניק את התפקידים, צריכה להיות לכם הרשאת roles/resourcemanager.projectIamAdmin
role.
אם אין לכם את התפקיד roles/resourcemanager.organizationAdmin, האדמין הארגוני יכול להקצות את התפקידים לסוכני השירות בשבילכם באמצעות הפקודה הבאה ב-CLI של gcloud:
gcloud organizations add-iam-policy-binding PROJECT_ID \
--member="SERVICE_ACCOUNT_NAME" \
--role="IAM_ROLE"
מחליפים את מה שכתוב בשדות הבאים:
-
PROJECT_ID: מזהה הפרויקט -
SERVICE_AGENT_NAME: השם של סוכן השירות שרוצים להעניק לו את התפקיד. השם הוא אחד משמות סוכני השירות הבאים:service-project-PROJECT_NUMBER@security-center-api.service-project-PROJECT_NUMBER@gcp-sa-ktd-hpsa.service-project-PROJECT_NUMBER@gcp-sa-csc-hpsa.
-
IAM_ROLE: התפקיד הנדרש הבא שמתאים לסוכן השירות שצוין:roles/securitycenter.serviceAgentroles/containerthreatdetection.serviceAgentroles/cloudsecuritycompliance.serviceAgent
במאמר איך מזהים פרויקטים מוסבר איך למצוא את מזהה הפרויקט ואת מספר הפרויקט.
מידע נוסף על תפקידים ב-IAM מופיע במאמר הסבר על תפקידים.
תפקידים ב-Web Security Scanner
התפקידים הבאים ב-IAM זמינים ל-Web Security Scanner. אפשר להעניק את התפקידים האלה ברמת הפרויקט.
| Role | Permissions |
|---|---|
Web Security Scanner Admin( Full access to all Web Security Scanner resources |
|
Web Security Scanner Editor( Full access to all Web Security Scanner resources Lowest-level resources where you can grant this role:
|
|
Web Security Scanner Viewer( Read access to all Web Security Scanner resources Lowest-level resources where you can grant this role:
|
|
Web Security Scanner Runner( Read access to Scan and ScanRun, plus the ability to start scans Lowest-level resources where you can grant this role:
|
|
Service agent roles
Service agent roles should only be granted to service agents.
| Role | Permissions |
|---|---|
Cloud Web Security Scanner Service Agent( Gives the Cloud Web Security Scanner service account access to compute engine details and app engine details. |
|