GCP · Security March 2026

GCP Security
Checklist

Practical controls for securing your Google Cloud Platform environment, from IAM hygiene to audit logging and beyond.

Identity & Access Management (IAM)

✓
Apply least privilege. Every user, group, and service account should have only the permissions required for their role. Avoid basic roles (Owner, Editor, Viewer) on production resources.
✓
Enable MFA for all human accounts. Especially for admin-level access. Use hardware keys for privileged users where possible.
✓
Review IAM bindings quarterly. Remove stale permissions. Former employees, old projects, and test accounts accumulate access over time.
✓
Use groups, not individuals. Bind roles to Google Groups, not personal emails. It's easier to manage and audit.

Service Accounts

Service accounts are one of the most common sources of GCP security incidents. Treat them like privileged identities.

✓
Never use default service accounts. Create dedicated service accounts per application with scoped permissions.
✓
Disable service account key creation where possible. Prefer Workload Identity Federation or short-lived tokens over long-lived JSON keys.
✓
Audit service account usage. Use Cloud Audit Logs to track which service accounts are being used, from where, and for what.
✓
Never grant service accounts Owner or Editor roles. Always use specific predefined or custom roles.
Real-world scenarioA service account with Editor role on a project is effectively a skeleton key. One leaked JSON key and an attacker can read, modify, or delete most resources. Scope it down, even if it's inconvenient.

Audit Logging

✓
Enable Data Access audit logs. Admin Activity logs are on by default. Data Read and Data Write logs must be explicitly enabled per service.
✓
Export logs to a separate project or SIEM. If an attacker compromises your project, you don't want them to be able to delete audit evidence.
✓
Set log retention policy. Default Cloud Logging retention is 30 days for most logs. Export to Cloud Storage or BigQuery for longer retention if required by compliance.

Network Controls

✓
Use VPC firewall rules with least privilege. Deny all by default. Allow only specific protocols, ports, and source ranges that are needed.
✓
Restrict external IPs. Use Private Google Access and VPC Service Controls to keep traffic inside Google's network where possible.
✓
Enable VPC Flow Logs. Essential for detecting unusual traffic patterns and investigating incidents.

Google Workspace Integration

If you use GCP alongside Google Workspace (Gmail, Drive, Calendar), security controls apply across both.

✓
Audit OAuth app access. Third-party apps connected to Workspace can access emails, files, and calendars. Review and restrict via Admin Console → Security → API Controls.
✓
Monitor Drive sharing. Use service accounts and Drive API to detect files shared outside your domain. This is a common data leakage vector.
✓
Enable Google Workspace alert policies. Suspicious login, account compromise, and data exfiltration alerts are available and should be routed to your security team.
Bottom lineGCP gives you the tools, IAM Recommender, Security Command Center, Policy Analyzer. The challenge isn't capability, it's discipline: reviewing, rotating, restricting. Build these checks into your monthly ops routine, not your annual audit.