Google Cloud Asset Inventory Updates | May 13th, 2021
ASSET SERVICES
GA launch: Asset Insights
As part of the effort in bringing more insights into your assets for you, Cloud Asset Inventory just launched 7 types of Asset Insights through the Active Assist platform to GA. This initial set of asset insights focuses on proactively detecting anomalies within your organization’s IAM policies, which may be opportunities for improving security pasture. The insights can be aggregated from the Organization, Folder or Project level. [Documentation]
The 7 types of Asset Insights are:
External members in IAM policies.
External users that impersonate your service accounts.
External members as policy editors.
External users who can view cloud storage buckets.
Terminated users/groups that are still in IAM policies
IAM policies containing all users or all authenticated users.
Projects with only terminated users as owners.
GA launch: Policy Analyzer to support time based IAM Conditions
Policy Analyzer just got more powerful with the IAM Conditions support! You can set accessTime in your request to evaluate IAM access more accurately. For example, a user might only be granted access during a certain time each day. With the help of the new IAM condition support, you can successfully analyze the user’s access based on a specific time to reduce “false positives”. The Conditions support is currently only available through API and CLI. [Documentation]
ASSET COVERAGE
More Assets are available through Export, Realtime, Search and Analysis
The following resource types are now publicly available through the Export APIs (ExportAssets and BatchGetAssetsHistory) and the Feed API:
Cloud AI Platform (Unified)
Cloud Document AI
The following resource types are now publicly available through the resource search API (SearchAllResources) and policy search API (SearchAllIamPolicies):
Service Usage
Cloud Data Fusion
The following resource types are now publicly available through the analyze policy APIs (AnalyzeIamPolicy and AnalyzeIamPolicyLongrunning):
Cloud Composer
Cloud Run
Cloud TPU
Cloud Storage
If you have any questions or feedback, please email gcp-asset-inventory...@googlegroups.com.
To receive product updates from Asset Inventory, please join our mailing list here.
Thanks very much,
Google Cloud Asset Inventory team