IAM pour les activations au niveau de l'organisation

Cette page explique comment utiliser Identity and Access Management (IAM) pour contrôler l'accès aux ressources dans une activation de Security Command Center au niveau de l'organisation. Cette page vous concerne si l'une des conditions suivantes s'applique :

  • Security Command Center est activé au niveau de l'organisation, et non au niveau du projet.
  • Security Command Center Standard est déjà activé au niveau de l'organisation. De plus, vous avez activé Security Command Center Premium sur un ou plusieurs projets.

Si vous avez activé Security Command Center au niveau du projet et non au niveau de l'organisation, consultez plutôt IAM pour les activations au niveau du projet.

Lorsque vous activez Security Command Center au niveau de l'organisation, vous pouvez contrôler l'accès aux ressources à différents niveaux de la hiérarchie des ressources. Security Command Center utilise les rôles IAM pour vous permettre de contrôler qui peut faire quoi avec les éléments, les résultats et les sources de sécurité au sein de votre environnement Security Command Center. Vous attribuez des rôles à des personnes physiques et à des applications, et chaque rôle donne des autorisations spécifiques.

Autorisations

Pour configurer Security Command Center ou modifier la configuration de votre organisation, vous avez besoin des deux rôles suivants au niveau de l'organisation :

  • Administrateur de l'organisation (roles/resourcemanager.organizationAdmin)
  • Administrateur du centre de sécurité (roles/securitycenter.admin)

Si un utilisateur ne nécessite pas de droits de modification, pensez à lui accorder des rôles de lecteur.

Pour afficher tous les éléments, résultats et chemins d'attaque dans Security Command Center, les utilisateurs doivent disposer du rôle Lecteur administrateur du centre de sécurité (roles/securitycenter.adminViewer) au niveau de l'organisation.

Pour afficher les paramètres, les utilisateurs doivent disposer du rôle Administrateur du centre de sécurité (roles/securitycenter.admin) au niveau de l'organisation.

Pour restreindre l'accès à des dossiers et projets individuels, n'attribuez pas tous les rôles au niveau de l'organisation. Accordez plutôt les rôles suivants au niveau du dossier ou du projet :

  • Lecteur d'éléments du centre de sécurité (roles/securitycenter.assetsViewer)
  • Lecteur de résultats du centre de sécurité (roles/securitycenter.findingsViewer)

Si vous utilisez Security Command Center Enterprise, consultez également Consoles Security Command Center Enterprise pour en savoir plus sur les rôles supplémentaires requis.

Rôles au niveau de l'organisation

Lorsque des rôles IAM sont appliqués au niveau de l'organisation, les projets et les dossiers de cette organisation héritent de ses liaisons de rôle.

La figure suivante illustre une hiérarchie de ressources Security Command Center classique avec des rôles accordés au niveau de l'organisation.

Hiérarchie des ressources et structure des autorisations de Security Command Center
Hiérarchie de ressources Security Command Center et rôles au niveau de l'organisation (cliquez pour agrandir)

Les rôles IAM incluent des autorisations permettant d'afficher, de modifier, de mettre à jour, de créer ou de supprimer des ressources. Les rôles attribués au niveau de l'organisation dans Security Command Center vous permettent d'appliquer des actions prescrites aux résultats, aux éléments et aux sources de sécurité dans l'ensemble de votre organisation. Par exemple, un utilisateur disposant du rôle Éditeur de résultats du centre de sécurité (roles/securitycenter.findingsEditor) peut afficher ou modifier les résultats associés à n'importe quelle ressource dans tout projet ou dossier de votre organisation. Avec cette structure, il n'est pas nécessaire d'attribuer des rôles aux utilisateurs dans chaque dossier ou projet.

Pour obtenir des instructions sur la gestion des rôles et des autorisations, consultez la page Gérer l'accès aux projets, aux dossiers et aux organisations.

Les rôles au niveau de l'organisation ne conviennent pas à tous les cas d'utilisation, en particulier pour les applications sensibles ou les normes de conformité qui nécessitent un contrôle des accès strict. Pour créer des règles d'accès précises, vous pouvez attribuer des rôles au niveau des dossiers et des projets.

Rôles au niveau des dossiers et des projets

Security Command Center vous permet d'accorder des rôles IAM pour Security Command Center dans des dossiers et des projets spécifiques, en créant plusieurs vues ou silos, au sein de votre organisation. Vous accordez aux utilisateurs et aux groupes différentes autorisations d'accès et de modification aux dossiers et aux projets de votre organisation.

La vidéo suivante explique comment attribuer des rôles au niveau des dossiers et des projets, et comment les gérer dans la console Security Command Center.

Grâce aux rôles de dossier et de projet, les utilisateurs disposant de rôles Security Command Center peuvent gérer les éléments et les résultats dans des projets ou des dossiers désignés. Par exemple, un ingénieur de la sécurité peut disposer d'un accès limité à certains dossiers et projets, tandis qu'un administrateur de la sécurité peut gérer toutes les ressources au niveau de l'organisation.

Les rôles liés aux dossiers et aux projets permettent d'appliquer des autorisations Security Command Center à des niveaux inférieurs de la hiérarchie de ressources de votre organisation. En revanche, ils ne modifient pas la hiérarchie. La figure suivante montre un utilisateur disposant des autorisations Security Command Center pour accéder aux résultats d'un projet spécifique.

Hiérarchie des ressources et structure des autorisations de Security Command Center
Hiérarchie des ressources Security Command Center et rôles au niveau du projet : les éléments en pointillés sont inaccessibles (cliquez pour agrandir)

Les utilisateurs disposant de rôles de dossier et de projet voient un sous-ensemble de ressources d'une organisation. Toutes les actions qu'ils effectuent sont limitées au même champ d'application. Par exemple, si un utilisateur est autorisé à accéder à un dossier, il peut accéder aux ressources de n'importe quel projet du dossier. Les autorisations associées à un projet permettent aux utilisateurs d'accéder aux ressources de ce projet.

Pour obtenir des instructions sur la gestion des rôles et des autorisations, consultez la page Gérer l'accès aux projets, aux dossiers et aux organisations.

Restrictions applicables aux rôles

En attribuant des rôles Security Command Center au niveau du dossier ou du projet, les administrateurs Security Command Center peuvent effectuer les opérations suivantes :

  • limiter les autorisations d'affichage ou de modification Security Command Center à des dossiers et des projets spécifiques ;
  • Accorder des autorisations d'affichage et de modification à des groupes d'éléments ou de résultats à des utilisateurs ou à des équipes spécifiques ;
  • Restreindre la possibilité d'afficher ou de modifier les détails des résultats, y compris les mises à jour des marques de sécurité et l'état des résultats, aux individus ou aux groupes ayant accès au résultat sous-jacent ;
  • Contrôler l'accès aux paramètres de Security Command Center, qui ne peuvent être consultés que par les personnes disposant de rôles au niveau de l'organisation.

Fonctions de Security Command Center

Les fonctions de Security Command Center sont également limitées en fonction des autorisations d'affichage et de modification.

Dans la console Google Cloud , Security Command Center permet aux personnes ne disposant pas d'autorisations au niveau de l'organisation de choisir uniquement les ressources auxquelles elles ont accès. Leur sélection met à jour tous les éléments de l'interface utilisateur, y compris les éléments, les résultats et les contrôles de paramètres. Les utilisateurs voient les droits associés à leurs rôles et s'ils peuvent accéder aux résultats ou les modifier dans leur champ d'application actuel.

L'API Security Command Center et Google Cloud CLI limitent également les fonctions aux dossiers et projets prescrits. Si des appels permettant de répertorier ou de regrouper des éléments et des résultats sont effectués par des utilisateurs disposant de rôles de dossier ou de projet, seuls les résultats ou les éléments associés à ces champs d'application sont renvoyés.

Pour les activations de Security Command Center au niveau de l'organisation, les appels permettant de créer ou de mettre à jour des résultats et de recevoir des notifications ne prennent en charge que le champ d'application de l'organisation. Vous devez disposer de rôles au niveau de l'organisation pour effectuer ces tâches.

Pour afficher les chemins d'attaque générés par les simulations de chemins d'attaque, les autorisations appropriées doivent être accordées au niveau de l'organisation et la vue de la console Google Cloud doit être définie sur l'organisation.

Ressources parentes des résultats

En règle générale, un résultat est associé à une ressource, telle qu'une machine virtuelle (VM) ou un pare-feu. Security Command Center associe les résultats au conteneur le plus immédiat pour la ressource qui a généré le résultat. Par exemple, si une VM génère un résultat, celui-ci est associé au projet contenant la VM. Les résultats qui ne sont pas associés à une ressource Google Cloud sont associés à l'organisation et sont visibles par toute personne disposant des autorisations Security Command Center au niveau de l'organisation.

Rôles Security Command Center

Les rôles IAM suivants sont disponibles pour Security Command Center. Vous pouvez attribuer ces rôles au niveau de l'organisation, d'un dossier ou d'un projet.

Role Permissions

(roles/securitycenter.admin)

Admin(super user) access to security center

Lowest-level resources where you can grant this role:

  • Project

appengine.applications.get

artifactregistry.attachments.get

artifactregistry.attachments.list

artifactregistry.dockerimages.*

  • artifactregistry.dockerimages.get
  • artifactregistry.dockerimages.list

artifactregistry.files.download

artifactregistry.files.get

artifactregistry.files.list

artifactregistry.locations.*

  • artifactregistry.locations.get
  • artifactregistry.locations.list

artifactregistry.mavenartifacts.*

  • artifactregistry.mavenartifacts.get
  • artifactregistry.mavenartifacts.list

artifactregistry.npmpackages.*

  • artifactregistry.npmpackages.get
  • artifactregistry.npmpackages.list

artifactregistry.packages.get

artifactregistry.packages.list

artifactregistry.projectsettings.get

artifactregistry.pythonpackages.*

  • artifactregistry.pythonpackages.get
  • artifactregistry.pythonpackages.list

artifactregistry.repositories.create

artifactregistry.repositories.downloadArtifacts

artifactregistry.repositories.get

artifactregistry.repositories.list

artifactregistry.repositories.listEffectiveTags

artifactregistry.repositories.listTagBindings

artifactregistry.repositories.readViaVirtualRepository

artifactregistry.rules.get

artifactregistry.rules.list

artifactregistry.tags.get

artifactregistry.tags.list

artifactregistry.versions.get

artifactregistry.versions.list

assuredoss.*

  • assuredoss.config.get
  • assuredoss.customers.create
  • assuredoss.locations.get
  • assuredoss.locations.list
  • assuredoss.metadata.get
  • assuredoss.metadata.list
  • assuredoss.operations.cancel
  • assuredoss.operations.delete
  • assuredoss.operations.get
  • assuredoss.operations.list

cloudasset.assets.exportIamPolicy

cloudasset.assets.exportOSInventories

cloudasset.assets.exportResource

cloudasset.assets.queryAccessPolicy

cloudasset.assets.queryIamPolicy

cloudasset.assets.queryOSInventories

cloudasset.assets.queryResource

cloudasset.assets.searchAllIamPolicies

cloudasset.assets.searchAllResources

cloudasset.assets.searchEnrichmentResourceOwners

cloudasset.othercloudconnections.get

cloudasset.othercloudconnections.list

cloudasset.othercloudconnections.verify

cloudsecurityscanner.*

  • cloudsecurityscanner.crawledurls.list
  • cloudsecurityscanner.results.get
  • cloudsecurityscanner.results.list
  • cloudsecurityscanner.scanruns.get
  • cloudsecurityscanner.scanruns.getSummary
  • cloudsecurityscanner.scanruns.list
  • cloudsecurityscanner.scanruns.stop
  • cloudsecurityscanner.scans.create
  • cloudsecurityscanner.scans.delete
  • cloudsecurityscanner.scans.get
  • cloudsecurityscanner.scans.list
  • cloudsecurityscanner.scans.run
  • cloudsecurityscanner.scans.update

compute.addresses.list

iam.serviceAccountKeys.create

iam.serviceAccounts.create

iam.serviceAccounts.get

pubsub.messageTransforms.validate

pubsub.schemas.get

pubsub.schemas.list

pubsub.schemas.listRevisions

pubsub.schemas.validate

pubsub.snapshots.get

pubsub.snapshots.list

pubsub.subscriptions.create

pubsub.subscriptions.get

pubsub.subscriptions.list

pubsub.subscriptions.update

pubsub.topics.get

pubsub.topics.list

resourcemanager.folders.get

resourcemanager.folders.list

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.list

resourcemanager.tagValues.get

securitycenter.*

  • securitycenter.assets.group
  • securitycenter.assets.list
  • securitycenter.assets.listAssetPropertyNames
  • securitycenter.assets.runDiscovery
  • securitycenter.assetsecuritymarks.update
  • securitycenter.attackpaths.list
  • securitycenter.bigQueryExports.create
  • securitycenter.bigQueryExports.delete
  • securitycenter.bigQueryExports.get
  • securitycenter.bigQueryExports.list
  • securitycenter.bigQueryExports.update
  • securitycenter.billingtier.update
  • securitycenter.complianceReports.aggregate
  • securitycenter.compliancesnapshots.list
  • securitycenter.containerthreatdetectionsettings.calculate
  • securitycenter.containerthreatdetectionsettings.get
  • securitycenter.containerthreatdetectionsettings.update
  • securitycenter.effectivesecurityhealthanalyticscustommodules.get
  • securitycenter.effectivesecurityhealthanalyticscustommodules.list
  • securitycenter.eventthreatdetectionsettings.calculate
  • securitycenter.eventthreatdetectionsettings.get
  • securitycenter.eventthreatdetectionsettings.update
  • securitycenter.exposurepathexplan.get
  • securitycenter.findingexplanations.get
  • securitycenter.findingexternalsystems.update
  • securitycenter.findings.bulkMuteUpdate
  • securitycenter.findings.group
  • securitycenter.findings.list
  • securitycenter.findings.listFindingPropertyNames
  • securitycenter.findings.setMute
  • securitycenter.findings.setState
  • securitycenter.findings.setWorkflowState
  • securitycenter.findings.update
  • securitycenter.findingsecuritymarks.update
  • securitycenter.integratedvulnerabilityscannersettings.calculate
  • securitycenter.integratedvulnerabilityscannersettings.get
  • securitycenter.integratedvulnerabilityscannersettings.update
  • securitycenter.issues.get
  • securitycenter.issues.group
  • securitycenter.issues.list
  • securitycenter.issues.listFilterValues
  • securitycenter.issues.mute
  • securitycenter.muteconfigs.create
  • securitycenter.muteconfigs.delete
  • securitycenter.muteconfigs.get
  • securitycenter.muteconfigs.list
  • securitycenter.muteconfigs.update
  • securitycenter.notificationconfig.create
  • securitycenter.notificationconfig.delete
  • securitycenter.notificationconfig.get
  • securitycenter.notificationconfig.list
  • securitycenter.notificationconfig.update
  • securitycenter.organizationsettings.get
  • securitycenter.organizationsettings.update
  • securitycenter.rapidvulnerabilitydetectionsettings.calculate
  • securitycenter.rapidvulnerabilitydetectionsettings.get
  • securitycenter.rapidvulnerabilitydetectionsettings.update
  • securitycenter.resourcevalueconfigs.create
  • securitycenter.resourcevalueconfigs.delete
  • securitycenter.resourcevalueconfigs.get
  • securitycenter.resourcevalueconfigs.list
  • securitycenter.resourcevalueconfigs.update
  • securitycenter.securitycentersettings.get
  • securitycenter.securitycentersettings.update
  • securitycenter.securityhealthanalyticscustommodules.create
  • securitycenter.securityhealthanalyticscustommodules.delete
  • securitycenter.securityhealthanalyticscustommodules.get
  • securitycenter.securityhealthanalyticscustommodules.list
  • securitycenter.securityhealthanalyticscustommodules.simulate
  • securitycenter.securityhealthanalyticscustommodules.test
  • securitycenter.securityhealthanalyticscustommodules.update
  • securitycenter.securityhealthanalyticssettings.calculate
  • securitycenter.securityhealthanalyticssettings.get
  • securitycenter.securityhealthanalyticssettings.update
  • securitycenter.simulations.get
  • securitycenter.sources.get
  • securitycenter.sources.getIamPolicy
  • securitycenter.sources.list
  • securitycenter.sources.setIamPolicy
  • securitycenter.sources.update
  • securitycenter.subscription.get
  • securitycenter.userinterfacemetadata.get
  • securitycenter.valuedresources.list
  • securitycenter.virtualmachinethreatdetectionsettings.calculate
  • securitycenter.virtualmachinethreatdetectionsettings.get
  • securitycenter.virtualmachinethreatdetectionsettings.update
  • securitycenter.vulnerabilitysnapshots.list
  • securitycenter.websecurityscannersettings.calculate
  • securitycenter.websecurityscannersettings.get
  • securitycenter.websecurityscannersettings.update

securitycentermanagement.*

  • securitycentermanagement.billingMetadata.get
  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.get
  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.list
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.get
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.list
  • securitycentermanagement.eventThreatDetectionCustomModules.create
  • securitycentermanagement.eventThreatDetectionCustomModules.delete
  • securitycentermanagement.eventThreatDetectionCustomModules.get
  • securitycentermanagement.eventThreatDetectionCustomModules.list
  • securitycentermanagement.eventThreatDetectionCustomModules.update
  • securitycentermanagement.eventThreatDetectionCustomModules.validate
  • securitycentermanagement.locations.get
  • securitycentermanagement.locations.list
  • securitycentermanagement.securityCenterServices.get
  • securitycentermanagement.securityCenterServices.list
  • securitycentermanagement.securityCenterServices.update
  • securitycentermanagement.securityCommandCenter.activate
  • securitycentermanagement.securityCommandCenter.checkActivationOperation
  • securitycentermanagement.securityCommandCenter.checkEligibility
  • securitycentermanagement.securityCommandCenter.checkOnboardingStatus
  • securitycentermanagement.securityCommandCenter.generateServiceAccounts
  • securitycentermanagement.securityCommandCenter.get
  • securitycentermanagement.securityCommandCenter.update
  • securitycentermanagement.securityHealthAnalyticsCustomModules.create
  • securitycentermanagement.securityHealthAnalyticsCustomModules.delete
  • securitycentermanagement.securityHealthAnalyticsCustomModules.get
  • securitycentermanagement.securityHealthAnalyticsCustomModules.list
  • securitycentermanagement.securityHealthAnalyticsCustomModules.simulate
  • securitycentermanagement.securityHealthAnalyticsCustomModules.test
  • securitycentermanagement.securityHealthAnalyticsCustomModules.update

serviceusage.quotas.get

serviceusage.services.enable

serviceusage.services.get

serviceusage.services.list

(roles/securitycenter.adminEditor)

Admin Read-write access to security center

Lowest-level resources where you can grant this role:

  • Project

appengine.applications.get

artifactregistry.attachments.get

artifactregistry.attachments.list

artifactregistry.dockerimages.*

  • artifactregistry.dockerimages.get
  • artifactregistry.dockerimages.list

artifactregistry.files.download

artifactregistry.files.get

artifactregistry.files.list

artifactregistry.locations.*

  • artifactregistry.locations.get
  • artifactregistry.locations.list

artifactregistry.mavenartifacts.*

  • artifactregistry.mavenartifacts.get
  • artifactregistry.mavenartifacts.list

artifactregistry.npmpackages.*

  • artifactregistry.npmpackages.get
  • artifactregistry.npmpackages.list

artifactregistry.packages.get

artifactregistry.packages.list

artifactregistry.projectsettings.get

artifactregistry.pythonpackages.*

  • artifactregistry.pythonpackages.get
  • artifactregistry.pythonpackages.list

artifactregistry.repositories.downloadArtifacts

artifactregistry.repositories.get

artifactregistry.repositories.list

artifactregistry.repositories.listEffectiveTags

artifactregistry.repositories.listTagBindings

artifactregistry.repositories.readViaVirtualRepository

artifactregistry.rules.get

artifactregistry.rules.list

artifactregistry.tags.get

artifactregistry.tags.list

artifactregistry.versions.get

artifactregistry.versions.list

assuredoss.config.get

assuredoss.locations.*

  • assuredoss.locations.get
  • assuredoss.locations.list

assuredoss.metadata.*

  • assuredoss.metadata.get
  • assuredoss.metadata.list

assuredoss.operations.get

assuredoss.operations.list

cloudasset.assets.exportIamPolicy

cloudasset.assets.exportOSInventories

cloudasset.assets.exportResource

cloudasset.assets.queryAccessPolicy

cloudasset.assets.queryIamPolicy

cloudasset.assets.queryOSInventories

cloudasset.assets.queryResource

cloudasset.assets.searchAllIamPolicies

cloudasset.assets.searchAllResources

cloudasset.assets.searchEnrichmentResourceOwners

cloudasset.othercloudconnections.get

cloudasset.othercloudconnections.list

cloudasset.othercloudconnections.verify

cloudsecurityscanner.*

  • cloudsecurityscanner.crawledurls.list
  • cloudsecurityscanner.results.get
  • cloudsecurityscanner.results.list
  • cloudsecurityscanner.scanruns.get
  • cloudsecurityscanner.scanruns.getSummary
  • cloudsecurityscanner.scanruns.list
  • cloudsecurityscanner.scanruns.stop
  • cloudsecurityscanner.scans.create
  • cloudsecurityscanner.scans.delete
  • cloudsecurityscanner.scans.get
  • cloudsecurityscanner.scans.list
  • cloudsecurityscanner.scans.run
  • cloudsecurityscanner.scans.update

compute.addresses.list

pubsub.messageTransforms.validate

pubsub.schemas.get

pubsub.schemas.list

pubsub.schemas.listRevisions

pubsub.schemas.validate

pubsub.snapshots.get

pubsub.snapshots.list

pubsub.subscriptions.get

pubsub.subscriptions.list

pubsub.topics.get

pubsub.topics.list

resourcemanager.folders.get

resourcemanager.folders.list

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.list

resourcemanager.tagValues.get

securitycenter.assets.*

  • securitycenter.assets.group
  • securitycenter.assets.list
  • securitycenter.assets.listAssetPropertyNames
  • securitycenter.assets.runDiscovery

securitycenter.assetsecuritymarks.update

securitycenter.attackpaths.list

securitycenter.bigQueryExports.*

  • securitycenter.bigQueryExports.create
  • securitycenter.bigQueryExports.delete
  • securitycenter.bigQueryExports.get
  • securitycenter.bigQueryExports.list
  • securitycenter.bigQueryExports.update

securitycenter.complianceReports.aggregate

securitycenter.compliancesnapshots.list

securitycenter.containerthreatdetectionsettings.calculate

securitycenter.containerthreatdetectionsettings.get

securitycenter.effectivesecurityhealthanalyticscustommodules.*

  • securitycenter.effectivesecurityhealthanalyticscustommodules.get
  • securitycenter.effectivesecurityhealthanalyticscustommodules.list

securitycenter.eventthreatdetectionsettings.calculate

securitycenter.eventthreatdetectionsettings.get

securitycenter.exposurepathexplan.get

securitycenter.findingexplanations.get

securitycenter.findingexternalsystems.update

securitycenter.findings.*

  • securitycenter.findings.bulkMuteUpdate
  • securitycenter.findings.group
  • securitycenter.findings.list
  • securitycenter.findings.listFindingPropertyNames
  • securitycenter.findings.setMute
  • securitycenter.findings.setState
  • securitycenter.findings.setWorkflowState
  • securitycenter.findings.update

securitycenter.findingsecuritymarks.update

securitycenter.integratedvulnerabilityscannersettings.calculate

securitycenter.integratedvulnerabilityscannersettings.get

securitycenter.issues.*

  • securitycenter.issues.get
  • securitycenter.issues.group
  • securitycenter.issues.list
  • securitycenter.issues.listFilterValues
  • securitycenter.issues.mute

securitycenter.muteconfigs.*

  • securitycenter.muteconfigs.create
  • securitycenter.muteconfigs.delete
  • securitycenter.muteconfigs.get
  • securitycenter.muteconfigs.list
  • securitycenter.muteconfigs.update

securitycenter.notificationconfig.*

  • securitycenter.notificationconfig.create
  • securitycenter.notificationconfig.delete
  • securitycenter.notificationconfig.get
  • securitycenter.notificationconfig.list
  • securitycenter.notificationconfig.update

securitycenter.organizationsettings.get

securitycenter.rapidvulnerabilitydetectionsettings.calculate

securitycenter.rapidvulnerabilitydetectionsettings.get

securitycenter.resourcevalueconfigs.*

  • securitycenter.resourcevalueconfigs.create
  • securitycenter.resourcevalueconfigs.delete
  • securitycenter.resourcevalueconfigs.get
  • securitycenter.resourcevalueconfigs.list
  • securitycenter.resourcevalueconfigs.update

securitycenter.securitycentersettings.get

securitycenter.securityhealthanalyticscustommodules.get

securitycenter.securityhealthanalyticscustommodules.list

securitycenter.securityhealthanalyticscustommodules.simulate

securitycenter.securityhealthanalyticscustommodules.test

securitycenter.securityhealthanalyticssettings.calculate

securitycenter.securityhealthanalyticssettings.get

securitycenter.simulations.get

securitycenter.sources.get

securitycenter.sources.list

securitycenter.sources.update

securitycenter.subscription.get

securitycenter.userinterfacemetadata.get

securitycenter.valuedresources.list

securitycenter.virtualmachinethreatdetectionsettings.calculate

securitycenter.virtualmachinethreatdetectionsettings.get

securitycenter.vulnerabilitysnapshots.list

securitycenter.websecurityscannersettings.calculate

securitycenter.websecurityscannersettings.get

securitycentermanagement.billingMetadata.get

securitycentermanagement.effectiveEventThreatDetectionCustomModules.*

  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.get
  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.list

securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.*

  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.get
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.list

securitycentermanagement.eventThreatDetectionCustomModules.get

securitycentermanagement.eventThreatDetectionCustomModules.list

securitycentermanagement.eventThreatDetectionCustomModules.validate

securitycentermanagement.locations.*

  • securitycentermanagement.locations.get
  • securitycentermanagement.locations.list

securitycentermanagement.securityCenterServices.get

securitycentermanagement.securityCenterServices.list

securitycentermanagement.securityCommandCenter.checkActivationOperation

securitycentermanagement.securityCommandCenter.checkOnboardingStatus

securitycentermanagement.securityCommandCenter.generateServiceAccounts

securitycentermanagement.securityCommandCenter.get

securitycentermanagement.securityCommandCenter.update

securitycentermanagement.securityHealthAnalyticsCustomModules.get

securitycentermanagement.securityHealthAnalyticsCustomModules.list

securitycentermanagement.securityHealthAnalyticsCustomModules.simulate

securitycentermanagement.securityHealthAnalyticsCustomModules.test

serviceusage.quotas.get

serviceusage.services.get

serviceusage.services.list

(roles/securitycenter.adminViewer)

Admin Read access to security center

Lowest-level resources where you can grant this role:

  • Project

artifactregistry.attachments.get

artifactregistry.attachments.list

artifactregistry.dockerimages.*

  • artifactregistry.dockerimages.get
  • artifactregistry.dockerimages.list

artifactregistry.files.download

artifactregistry.files.get

artifactregistry.files.list

artifactregistry.locations.*

  • artifactregistry.locations.get
  • artifactregistry.locations.list

artifactregistry.mavenartifacts.*

  • artifactregistry.mavenartifacts.get
  • artifactregistry.mavenartifacts.list

artifactregistry.npmpackages.*

  • artifactregistry.npmpackages.get
  • artifactregistry.npmpackages.list

artifactregistry.packages.get

artifactregistry.packages.list

artifactregistry.projectsettings.get

artifactregistry.pythonpackages.*

  • artifactregistry.pythonpackages.get
  • artifactregistry.pythonpackages.list

artifactregistry.repositories.downloadArtifacts

artifactregistry.repositories.get

artifactregistry.repositories.list

artifactregistry.repositories.listEffectiveTags

artifactregistry.repositories.listTagBindings

artifactregistry.repositories.readViaVirtualRepository

artifactregistry.rules.get

artifactregistry.rules.list

artifactregistry.tags.get

artifactregistry.tags.list

artifactregistry.versions.get

artifactregistry.versions.list

assuredoss.config.get

assuredoss.locations.*

  • assuredoss.locations.get
  • assuredoss.locations.list

assuredoss.metadata.*

  • assuredoss.metadata.get
  • assuredoss.metadata.list

assuredoss.operations.get

assuredoss.operations.list

cloudasset.assets.exportIamPolicy

cloudasset.assets.exportOSInventories

cloudasset.assets.exportResource

cloudasset.assets.queryAccessPolicy

cloudasset.assets.queryIamPolicy

cloudasset.assets.queryOSInventories

cloudasset.assets.queryResource

cloudasset.assets.searchAllIamPolicies

cloudasset.assets.searchAllResources

cloudasset.assets.searchEnrichmentResourceOwners

cloudasset.othercloudconnections.get

cloudasset.othercloudconnections.list

cloudasset.othercloudconnections.verify

cloudsecurityscanner.crawledurls.list

cloudsecurityscanner.results.*

  • cloudsecurityscanner.results.get
  • cloudsecurityscanner.results.list

cloudsecurityscanner.scanruns.get

cloudsecurityscanner.scanruns.getSummary

cloudsecurityscanner.scanruns.list

cloudsecurityscanner.scans.get

cloudsecurityscanner.scans.list

pubsub.messageTransforms.validate

pubsub.schemas.get

pubsub.schemas.list

pubsub.schemas.listRevisions

pubsub.schemas.validate

pubsub.snapshots.get

pubsub.snapshots.list

pubsub.subscriptions.get

pubsub.subscriptions.list

pubsub.topics.get

pubsub.topics.list

resourcemanager.folders.get

resourcemanager.folders.list

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.list

resourcemanager.tagValues.get

securitycenter.assets.group

securitycenter.assets.list

securitycenter.assets.listAssetPropertyNames

securitycenter.attackpaths.list

securitycenter.bigQueryExports.get

securitycenter.bigQueryExports.list

securitycenter.complianceReports.aggregate

securitycenter.compliancesnapshots.list

securitycenter.containerthreatdetectionsettings.calculate

securitycenter.containerthreatdetectionsettings.get

securitycenter.effectivesecurityhealthanalyticscustommodules.*

  • securitycenter.effectivesecurityhealthanalyticscustommodules.get
  • securitycenter.effectivesecurityhealthanalyticscustommodules.list

securitycenter.eventthreatdetectionsettings.calculate

securitycenter.eventthreatdetectionsettings.get

securitycenter.exposurepathexplan.get

securitycenter.findingexplanations.get

securitycenter.findings.group

securitycenter.findings.list

securitycenter.findings.listFindingPropertyNames

securitycenter.integratedvulnerabilityscannersettings.calculate

securitycenter.integratedvulnerabilityscannersettings.get

securitycenter.issues.get

securitycenter.issues.group

securitycenter.issues.list

securitycenter.issues.listFilterValues

securitycenter.muteconfigs.get

securitycenter.muteconfigs.list

securitycenter.notificationconfig.get

securitycenter.notificationconfig.list

securitycenter.organizationsettings.get

securitycenter.rapidvulnerabilitydetectionsettings.calculate

securitycenter.rapidvulnerabilitydetectionsettings.get

securitycenter.resourcevalueconfigs.get

securitycenter.resourcevalueconfigs.list

securitycenter.securitycentersettings.get

securitycenter.securityhealthanalyticscustommodules.get

securitycenter.securityhealthanalyticscustommodules.list

securitycenter.securityhealthanalyticscustommodules.simulate

securitycenter.securityhealthanalyticscustommodules.test

securitycenter.securityhealthanalyticssettings.calculate

securitycenter.securityhealthanalyticssettings.get

securitycenter.simulations.get

securitycenter.sources.get

securitycenter.sources.list

securitycenter.subscription.get

securitycenter.userinterfacemetadata.get

securitycenter.valuedresources.list

securitycenter.virtualmachinethreatdetectionsettings.calculate

securitycenter.virtualmachinethreatdetectionsettings.get

securitycenter.vulnerabilitysnapshots.list

securitycenter.websecurityscannersettings.calculate

securitycenter.websecurityscannersettings.get

securitycentermanagement.billingMetadata.get

securitycentermanagement.effectiveEventThreatDetectionCustomModules.*

  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.get
  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.list

securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.*

  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.get
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.list

securitycentermanagement.eventThreatDetectionCustomModules.get

securitycentermanagement.eventThreatDetectionCustomModules.list

securitycentermanagement.eventThreatDetectionCustomModules.validate

securitycentermanagement.locations.*

  • securitycentermanagement.locations.get
  • securitycentermanagement.locations.list

securitycentermanagement.securityCenterServices.get

securitycentermanagement.securityCenterServices.list

securitycentermanagement.securityCommandCenter.checkActivationOperation

securitycentermanagement.securityCommandCenter.checkOnboardingStatus

securitycentermanagement.securityCommandCenter.get

securitycentermanagement.securityHealthAnalyticsCustomModules.get

securitycentermanagement.securityHealthAnalyticsCustomModules.list

securitycentermanagement.securityHealthAnalyticsCustomModules.simulate

securitycentermanagement.securityHealthAnalyticsCustomModules.test

serviceusage.quotas.get

serviceusage.services.get

serviceusage.services.list

(roles/securitycenter.assetSecurityMarksWriter)

Write access to asset security marks

Lowest-level resources where you can grant this role:

  • Project

securitycenter.assetsecuritymarks.update

securitycenter.userinterfacemetadata.get

(roles/securitycenter.assetsDiscoveryRunner)

Run asset discovery access to assets

Lowest-level resources where you can grant this role:

  • Organization

securitycenter.assets.runDiscovery

securitycenter.userinterfacemetadata.get

(roles/securitycenter.assetsViewer)

Read access to assets

Lowest-level resources where you can grant this role:

  • Project

cloudasset.assets.exportIamPolicy

cloudasset.assets.exportOSInventories

cloudasset.assets.exportResource

cloudasset.assets.queryAccessPolicy

cloudasset.assets.queryIamPolicy

cloudasset.assets.queryOSInventories

cloudasset.assets.queryResource

cloudasset.assets.searchAllIamPolicies

cloudasset.assets.searchAllResources

cloudasset.assets.searchEnrichmentResourceOwners

cloudasset.othercloudconnections.get

cloudasset.othercloudconnections.list

cloudasset.othercloudconnections.verify

resourcemanager.folders.get

resourcemanager.organizations.get

resourcemanager.projects.get

securitycenter.assets.group

securitycenter.assets.list

securitycenter.assets.listAssetPropertyNames

securitycenter.userinterfacemetadata.get

(roles/securitycenter.attackPathsViewer)

Read access to security center attack paths

securitycenter.attackpaths.list

securitycenter.exposurepathexplan.get

(roles/securitycenter.attackSurfaceManagementScannerServiceAgent)

Gives Mandiant Attack Surface Management the ability to scan Cloud Platform resources.

apigateway.apiconfigs.get

cloudasset.assets.listResource

dns.managedZones.list

dns.resourceRecordSets.list

resourcemanager.projects.get

(roles/securitycenter.automationServiceAgent)

Security Center automation service agent can configure GCP resources to enable security scanning.

cloudasset.feeds.*

  • cloudasset.feeds.create
  • cloudasset.feeds.delete
  • cloudasset.feeds.get
  • cloudasset.feeds.list
  • cloudasset.feeds.update

resourcemanager.folders.get

resourcemanager.folders.list

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.getIamPolicy

resourcemanager.projects.list

serviceusage.services.enable

serviceusage.services.get

(roles/securitycenter.bigQueryExportsEditor)

Read-Write access to security center BigQuery Exports

resourcemanager.folders.get

resourcemanager.folders.list

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.list

securitycenter.bigQueryExports.*

  • securitycenter.bigQueryExports.create
  • securitycenter.bigQueryExports.delete
  • securitycenter.bigQueryExports.get
  • securitycenter.bigQueryExports.list
  • securitycenter.bigQueryExports.update

(roles/securitycenter.bigQueryExportsViewer)

Read access to security center BigQuery Exports

resourcemanager.folders.get

resourcemanager.folders.list

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.list

securitycenter.bigQueryExports.get

securitycenter.bigQueryExports.list

(roles/securitycenter.complianceReportsViewer)

Read access to security center compliance reports

securitycenter.complianceReports.aggregate

(roles/securitycenter.complianceSnapshotsViewer)

Read access to security center compliance snapshots

securitycenter.complianceReports.aggregate

securitycenter.compliancesnapshots.list

(roles/securitycenter.controlServiceAgent)

Security Center Control service agent can monitor and configure GCP resources and import security findings.

accesscontextmanager.gcpUserAccessBindings.get

accesscontextmanager.gcpUserAccessBindings.list

aiplatform.dataItems.list

aiplatform.datasets.list

bigquery.datasets.get

binaryauthorization.policy.get

cloudasset.assets.analyzeIamPolicy

cloudasset.assets.analyzeMove

cloudasset.assets.analyzeOrgPolicy

cloudasset.assets.exportAccessLevel

cloudasset.assets.exportAccessPolicy

cloudasset.assets.exportAiplatformBatchPredictionJobs

cloudasset.assets.exportAiplatformCustomJobs

cloudasset.assets.exportAiplatformDataLabelingJobs

cloudasset.assets.exportAiplatformDatasets

cloudasset.assets.exportAiplatformEndpoints

cloudasset.assets.exportAiplatformHyperparameterTuningJobs

cloudasset.assets.exportAiplatformMetadataStores

cloudasset.assets.exportAiplatformModelDeploymentMonitoringJobs

cloudasset.assets.exportAiplatformModels

cloudasset.assets.exportAiplatformPipelineJobs

cloudasset.assets.exportAiplatformSpecialistPools

cloudasset.assets.exportAiplatformTrainingPipelines

cloudasset.assets.exportAllAccessPolicy

cloudasset.assets.exportAnthosConnectedCluster

cloudasset.assets.exportAnthosedgeCluster

cloudasset.assets.exportApigatewayApi

cloudasset.assets.exportApigatewayApiConfig

cloudasset.assets.exportApigatewayGateway

cloudasset.assets.exportApikeysKeys

cloudasset.assets.exportAppengineApplications

cloudasset.assets.exportAppengineServices

cloudasset.assets.exportAppengineVersions

cloudasset.assets.exportArtifactregistryDockerImages

cloudasset.assets.exportArtifactregistryRepositories

cloudasset.assets.exportAssuredWorkloadsWorkloads

cloudasset.assets.exportBeyondCorpApiGateways

cloudasset.assets.exportBeyondCorpAppConnections

cloudasset.assets.exportBeyondCorpAppConnectors

cloudasset.assets.exportBeyondCorpAppGateways

cloudasset.assets.exportBeyondCorpClientConnectorServices

cloudasset.assets.exportBeyondCorpClientGateways

cloudasset.assets.exportBigqueryDatasets

cloudasset.assets.exportBigqueryModels

cloudasset.assets.exportBigqueryTables

cloudasset.assets.exportBigtableAppProfile

cloudasset.assets.exportBigtableBackup

cloudasset.assets.exportBigtableCluster

cloudasset.assets.exportBigtableInstance

cloudasset.assets.exportBigtableTable

cloudasset.assets.exportCloudAssetFeeds

cloudasset.assets.exportCloudDeployDeliveryPipelines

cloudasset.assets.exportCloudDeployReleases

cloudasset.assets.exportCloudDeployRollouts

cloudasset.assets.exportCloudDeployTargets

cloudasset.assets.exportCloudDocumentAIEvaluation

cloudasset.assets.exportCloudDocumentAIHumanReviewConfig

cloudasset.assets.exportCloudDocumentAILabelerPool

cloudasset.assets.exportCloudDocumentAIProcessor

cloudasset.assets.exportCloudDocumentAIProcessorVersion

cloudasset.assets.exportCloudbillingBillingAccounts

cloudasset.assets.exportCloudbillingProjectBillingInfos

cloudasset.assets.exportCloudfunctionsFunctions

cloudasset.assets.exportCloudfunctionsGen2Functions

cloudasset.assets.exportCloudkmsCryptoKeyVersions

cloudasset.assets.exportCloudkmsCryptoKeys

cloudasset.assets.exportCloudkmsEkmConnections

cloudasset.assets.exportCloudkmsImportJobs

cloudasset.assets.exportCloudkmsKeyRings

cloudasset.assets.exportCloudmemcacheInstances

cloudasset.assets.exportCloudresourcemanagerFolders

cloudasset.assets.exportCloudresourcemanagerOrganizations

cloudasset.assets.exportCloudresourcemanagerProjects

cloudasset.assets.exportCloudresourcemanagerTagBindings

cloudasset.assets.exportCloudresourcemanagerTagKeys

cloudasset.assets.exportCloudresourcemanagerTagValues

cloudasset.assets.exportComposerEnvironments

cloudasset.assets.exportComputeAddress

cloudasset.assets.exportComputeAutoscalers

cloudasset.assets.exportComputeBackendBuckets

cloudasset.assets.exportComputeBackendServices

cloudasset.assets.exportComputeCommitments

cloudasset.assets.exportComputeDisks

cloudasset.assets.exportComputeExternalVpnGateways

cloudasset.assets.exportComputeFirewallPolicies

cloudasset.assets.exportComputeFirewalls

cloudasset.assets.exportComputeForwardingRules

cloudasset.assets.exportComputeGlobalAddress

cloudasset.assets.exportComputeGlobalForwardingRules

cloudasset.assets.exportComputeHealthChecks

cloudasset.assets.exportComputeHttpHealthChecks

cloudasset.assets.exportComputeHttpsHealthChecks

cloudasset.assets.exportComputeImages

cloudasset.assets.exportComputeInstanceGroupManagers

cloudasset.assets.exportComputeInstanceGroups

cloudasset.assets.exportComputeInstanceTemplates

cloudasset.assets.exportComputeInstances

cloudasset.assets.exportComputeInterconnect

cloudasset.assets.exportComputeInterconnectAttachment

cloudasset.assets.exportComputeLicenses

cloudasset.assets.exportComputeNetworkEndpointGroups

cloudasset.assets.exportComputeNetworks

cloudasset.assets.exportComputeNodeGroups

cloudasset.assets.exportComputeNodeTemplates

cloudasset.assets.exportComputePacketMirrorings

cloudasset.assets.exportComputeProjects

cloudasset.assets.exportComputeRegionAutoscaler

cloudasset.assets.exportComputeRegionBackendServices

cloudasset.assets.exportComputeRegionDisk

cloudasset.assets.exportComputeRegionInstanceGroup

cloudasset.assets.exportComputeRegionInstanceGroupManager

cloudasset.assets.exportComputeReservations

cloudasset.assets.exportComputeResourcePolicies

cloudasset.assets.exportComputeRouters

cloudasset.assets.exportComputeRoutes

cloudasset.assets.exportComputeSecurityPolicy

cloudasset.assets.exportComputeServiceAttachments

cloudasset.assets.exportComputeSnapshots

cloudasset.assets.exportComputeSslCertificates

cloudasset.assets.exportComputeSslPolicies

cloudasset.assets.exportComputeSubnetworks

cloudasset.assets.exportComputeTargetHttpProxies

cloudasset.assets.exportComputeTargetHttpsProxies

cloudasset.assets.exportComputeTargetInstances

cloudasset.assets.exportComputeTargetPools

cloudasset.assets.exportComputeTargetSslProxies

cloudasset.assets.exportComputeTargetTcpProxies

cloudasset.assets.exportComputeTargetVpnGateways

cloudasset.assets.exportComputeUrlMaps

cloudasset.assets.exportComputeVpnGateways

cloudasset.assets.exportComputeVpnTunnels

cloudasset.assets.exportConnectorsConnections

cloudasset.assets.exportConnectorsConnectorVersions

cloudasset.assets.exportConnectorsConnectors

cloudasset.assets.exportConnectorsProviders

cloudasset.assets.exportConnectorsRuntimeConfigs

cloudasset.assets.exportContainerAppsDeployment

cloudasset.assets.exportContainerAppsReplicaSets

cloudasset.assets.exportContainerBatchJobs

cloudasset.assets.exportContainerClusterrole

cloudasset.assets.exportContainerClusterrolebinding

cloudasset.assets.exportContainerClusters

cloudasset.assets.exportContainerExtensionsIngresses

cloudasset.assets.exportContainerJobs

cloudasset.assets.exportContainerNamespace

cloudasset.assets.exportContainerNetworkingIngresses

cloudasset.assets.exportContainerNetworkingNetworkPolicies

cloudasset.assets.exportContainerNode

cloudasset.assets.exportContainerNodepool

cloudasset.assets.exportContainerPod

cloudasset.assets.exportContainerReplicaSets

cloudasset.assets.exportContainerRole

cloudasset.assets.exportContainerRolebinding

cloudasset.assets.exportContainerServices

cloudasset.assets.exportContainerregistryImage

cloudasset.assets.exportDataMigrationConnectionProfiles

cloudasset.assets.exportDataMigrationMigrationJobs

cloudasset.assets.exportDataflowJobs

cloudasset.assets.exportDatafusionInstance

cloudasset.assets.exportDataplexAssets

cloudasset.assets.exportDataplexLakes

cloudasset.assets.exportDataplexTasks

cloudasset.assets.exportDataplexZones

cloudasset.assets.exportDataprocAutoscalingPolicies

cloudasset.assets.exportDataprocBatches

cloudasset.assets.exportDataprocClusters

cloudasset.assets.exportDataprocJobs

cloudasset.assets.exportDataprocSessions

cloudasset.assets.exportDataprocWorkflowTemplates

cloudasset.assets.exportDatastreamConnectionProfile

cloudasset.assets.exportDatastreamPrivateConnection

cloudasset.assets.exportDatastreamStream

cloudasset.assets.exportDialogflowAgents

cloudasset.assets.exportDialogflowConversationProfiles

cloudasset.assets.exportDialogflowKnowledgeBases

cloudasset.assets.exportDialogflowLocationSettings

cloudasset.assets.exportDlpDeidentifyTemplates

cloudasset.assets.exportDlpDlpJobs

cloudasset.assets.exportDlpInspectTemplates

cloudasset.assets.exportDlpJobTriggers

cloudasset.assets.exportDlpStoredInfoTypes

cloudasset.assets.exportDnsManagedZones

cloudasset.assets.exportDnsPolicies

cloudasset.assets.exportDomainsRegistrations

cloudasset.assets.exportEventarcTriggers

cloudasset.assets.exportFileBackups

cloudasset.assets.exportFileInstances

cloudasset.assets.exportFirebaseAppInfos

cloudasset.assets.exportFirebaseProjects

cloudasset.assets.exportFirestoreDatabases

cloudasset.assets.exportGKEHubFeatures

cloudasset.assets.exportGKEHubMemberships

cloudasset.assets.exportGameservicesGameServerClusters

cloudasset.assets.exportGameservicesGameServerConfigs

cloudasset.assets.exportGameservicesGameServerDeployments

cloudasset.assets.exportGameservicesRealms

cloudasset.assets.exportGkeBackupBackupPlans

cloudasset.assets.exportGkeBackupBackups

cloudasset.assets.exportGkeBackupRestorePlans

cloudasset.assets.exportGkeBackupRestores

cloudasset.assets.exportGkeBackupVolumeBackups

cloudasset.assets.exportGkeBackupVolumeRestores

cloudasset.assets.exportHealthcareConsentStores

cloudasset.assets.exportHealthcareDatasets

cloudasset.assets.exportHealthcareDicomStores

cloudasset.assets.exportHealthcareFhirStores

cloudasset.assets.exportHealthcareHl7V2Stores

cloudasset.assets.exportIamPolicy

cloudasset.assets.exportIamRoles

cloudasset.assets.exportIamServiceAccountKeys

cloudasset.assets.exportIamServiceAccounts

cloudasset.assets.exportIapTunnel

cloudasset.assets.exportIapTunnelInstances

cloudasset.assets.exportIapTunnelZones

cloudasset.assets.exportIapWeb

cloudasset.assets.exportIapWebServiceVersion

cloudasset.assets.exportIapWebServices

cloudasset.assets.exportIapWebType

cloudasset.assets.exportIdsEndpoints

cloudasset.assets.exportIntegrationsAuthConfigs

cloudasset.assets.exportIntegrationsCertificates

cloudasset.assets.exportIntegrationsExecutions

cloudasset.assets.exportIntegrationsIntegrationVersions

cloudasset.assets.exportIntegrationsIntegrations

cloudasset.assets.exportIntegrationsSfdcChannels

cloudasset.assets.exportIntegrationsSfdcInstances

cloudasset.assets.exportIntegrationsSuspensions

cloudasset.assets.exportLoggingLogMetrics

cloudasset.assets.exportLoggingLogSinks

cloudasset.assets.exportManagedidentitiesDomain

cloudasset.assets.exportMetastoreBackups

cloudasset.assets.exportMetastoreMetadataImports

cloudasset.assets.exportMetastoreServices

cloudasset.assets.exportMonitoringAlertPolicies

cloudasset.assets.exportNetworkConnectivityHubs

cloudasset.assets.exportNetworkConnectivitySpokes

cloudasset.assets.exportNetworkManagementConnectivityTests

cloudasset.assets.exportNetworkServicesEndpointPolicies

cloudasset.assets.exportNetworkServicesGateways

cloudasset.assets.exportNetworkServicesGrpcRoutes

cloudasset.assets.exportNetworkServicesHttpRoutes

cloudasset.assets.exportNetworkServicesMeshes

cloudasset.assets.exportNetworkServicesServiceBindings

cloudasset.assets.exportNetworkServicesTcpRoutes

cloudasset.assets.exportNetworkServicesTlsRoutes

cloudasset.assets.exportOSConfigOSPolicyAssignmentReports

cloudasset.assets.exportOSConfigOSPolicyAssignments

cloudasset.assets.exportOSConfigVulnerabilityReports

cloudasset.assets.exportOSInventories

cloudasset.assets.exportOrgPolicy

cloudasset.assets.exportPatchDeployments

cloudasset.assets.exportPubsubSnapshots

cloudasset.assets.exportPubsubSubscriptions

cloudasset.assets.exportPubsubTopics

cloudasset.assets.exportRedisInstances

cloudasset.assets.exportResource

cloudasset.assets.exportSecretManagerSecretVersions

cloudasset.assets.exportSecretManagerSecrets

cloudasset.assets.exportServiceDirectoryNamespaces

cloudasset.assets.exportServicePerimeter

cloudasset.assets.exportServiceconsumermanagementConsumerProperty

cloudasset.assets.exportServiceconsumermanagementConsumerQuotaLimits

cloudasset.assets.exportServiceconsumermanagementConsumers

cloudasset.assets.exportServiceconsumermanagementProducerOverrides

cloudasset.assets.exportServiceconsumermanagementTenancyUnits

cloudasset.assets.exportServiceconsumermanagementVisibility

cloudasset.assets.exportServicemanagementServices

cloudasset.assets.exportServiceusageAdminOverrides

cloudasset.assets.exportServiceusageConsumerOverrides

cloudasset.assets.exportServiceusageServices

cloudasset.assets.exportSpannerBackups

cloudasset.assets.exportSpannerDatabases

cloudasset.assets.exportSpannerInstances

cloudasset.assets.exportSpeakerIdPhrases

cloudasset.assets.exportSpeakerIdSettings

cloudasset.assets.exportSpeakerIdSpeakers

cloudasset.assets.exportSpeechCustomClasses

cloudasset.assets.exportSpeechPhraseSets

cloudasset.assets.exportSqladminBackupRuns

cloudasset.assets.exportSqladminInstances

cloudasset.assets.exportStorageBuckets

cloudasset.assets.exportTpuNodes

cloudasset.assets.exportVpcaccessConnector

cloudasset.assets.listAccessLevel

cloudasset.assets.listAccessPolicy

cloudasset.assets.listAiplatformBatchPredictionJobs

cloudasset.assets.listAiplatformCustomJobs

cloudasset.assets.listAiplatformDataLabelingJobs

cloudasset.assets.listAiplatformDatasets

cloudasset.assets.listAiplatformEndpoints

cloudasset.assets.listAiplatformHyperparameterTuningJobs

cloudasset.assets.listAiplatformMetadataStores

cloudasset.assets.listAiplatformModelDeploymentMonitoringJobs

cloudasset.assets.listAiplatformModels

cloudasset.assets.listAiplatformPipelineJobs

cloudasset.assets.listAiplatformSpecialistPools

cloudasset.assets.listAiplatformTrainingPipelines

cloudasset.assets.listAllAccessPolicy

cloudasset.assets.listAnthosConnectedCluster

cloudasset.assets.listAnthosedgeCluster

cloudasset.assets.listApigatewayApi

cloudasset.assets.listApigatewayApiConfig

cloudasset.assets.listApigatewayGateway

cloudasset.assets.listApikeysKeys

cloudasset.assets.listAppengineApplications

cloudasset.assets.listAppengineServices

cloudasset.assets.listAppengineVersions

cloudasset.assets.listArtifactregistryDockerImages

cloudasset.assets.listArtifactregistryRepositories

cloudasset.assets.listAssuredWorkloadsWorkloads

cloudasset.assets.listBeyondCorpApiGateways

cloudasset.assets.listBeyondCorpAppConnections

cloudasset.assets.listBeyondCorpAppConnectors

cloudasset.assets.listBeyondCorpAppGateways

cloudasset.assets.listBeyondCorpClientConnectorServices

cloudasset.assets.listBeyondCorpClientGateways

cloudasset.assets.listBigqueryDatasets

cloudasset.assets.listBigqueryModels

cloudasset.assets.listBigqueryTables

cloudasset.assets.listBigtableAppProfile

cloudasset.assets.listBigtableBackup

cloudasset.assets.listBigtableCluster

cloudasset.assets.listBigtableInstance

cloudasset.assets.listBigtableTable

cloudasset.assets.listCloudAssetFeeds

cloudasset.assets.listCloudDeployDeliveryPipelines

cloudasset.assets.listCloudDeployReleases

cloudasset.assets.listCloudDeployRollouts

cloudasset.assets.listCloudDeployTargets

cloudasset.assets.listCloudDocumentAIEvaluation

cloudasset.assets.listCloudDocumentAIHumanReviewConfig

cloudasset.assets.listCloudDocumentAILabelerPool

cloudasset.assets.listCloudDocumentAIProcessor

cloudasset.assets.listCloudDocumentAIProcessorVersion

cloudasset.assets.listCloudbillingBillingAccounts

cloudasset.assets.listCloudbillingProjectBillingInfos

cloudasset.assets.listCloudfunctionsFunctions

cloudasset.assets.listCloudfunctionsGen2Functions

cloudasset.assets.listCloudkmsCryptoKeyVersions

cloudasset.assets.listCloudkmsCryptoKeys

cloudasset.assets.listCloudkmsEkmConnections

cloudasset.assets.listCloudkmsImportJobs

cloudasset.assets.listCloudkmsKeyRings

cloudasset.assets.listCloudmemcacheInstances

cloudasset.assets.listCloudresourcemanagerFolders

cloudasset.assets.listCloudresourcemanagerOrganizations

cloudasset.assets.listCloudresourcemanagerProjects

cloudasset.assets.listCloudresourcemanagerTagBindings

cloudasset.assets.listCloudresourcemanagerTagKeys

cloudasset.assets.listCloudresourcemanagerTagValues

cloudasset.assets.listComposerEnvironments

cloudasset.assets.listComputeAddress

cloudasset.assets.listComputeAutoscalers

cloudasset.assets.listComputeBackendBuckets

cloudasset.assets.listComputeBackendServices

cloudasset.assets.listComputeCommitments

cloudasset.assets.listComputeDisks

cloudasset.assets.listComputeExternalVpnGateways

cloudasset.assets.listComputeFirewallPolicies

cloudasset.assets.listComputeFirewalls

cloudasset.assets.listComputeForwardingRules

cloudasset.assets.listComputeGlobalAddress

cloudasset.assets.listComputeGlobalForwardingRules

cloudasset.assets.listComputeHealthChecks

cloudasset.assets.listComputeHttpHealthChecks

cloudasset.assets.listComputeHttpsHealthChecks

cloudasset.assets.listComputeImages

cloudasset.assets.listComputeInstanceGroupManagers

cloudasset.assets.listComputeInstanceGroups

cloudasset.assets.listComputeInstanceTemplates

cloudasset.assets.listComputeInstances

cloudasset.assets.listComputeInterconnect

cloudasset.assets.listComputeInterconnectAttachment

cloudasset.assets.listComputeLicenses

cloudasset.assets.listComputeNetworkEndpointGroups

cloudasset.assets.listComputeNetworks

cloudasset.assets.listComputeNodeGroups

cloudasset.assets.listComputeNodeTemplates

cloudasset.assets.listComputePacketMirrorings

cloudasset.assets.listComputeProjects

cloudasset.assets.listComputeRegionAutoscaler

cloudasset.assets.listComputeRegionBackendServices

cloudasset.assets.listComputeRegionDisk

cloudasset.assets.listComputeRegionInstanceGroup

cloudasset.assets.listComputeRegionInstanceGroupManager

cloudasset.assets.listComputeReservations

cloudasset.assets.listComputeResourcePolicies

cloudasset.assets.listComputeRouters

cloudasset.assets.listComputeRoutes

cloudasset.assets.listComputeSecurityPolicy

cloudasset.assets.listComputeServiceAttachments

cloudasset.assets.listComputeSnapshots

cloudasset.assets.listComputeSslCertificates

cloudasset.assets.listComputeSslPolicies

cloudasset.assets.listComputeSubnetworks

cloudasset.assets.listComputeTargetHttpProxies

cloudasset.assets.listComputeTargetHttpsProxies

cloudasset.assets.listComputeTargetInstances

cloudasset.assets.listComputeTargetPools

cloudasset.assets.listComputeTargetSslProxies

cloudasset.assets.listComputeTargetTcpProxies

cloudasset.assets.listComputeTargetVpnGateways

cloudasset.assets.listComputeUrlMaps

cloudasset.assets.listComputeVpnGateways

cloudasset.assets.listComputeVpnTunnels

cloudasset.assets.listConnectorsConnections

cloudasset.assets.listConnectorsConnectorVersions

cloudasset.assets.listConnectorsConnectors

cloudasset.assets.listConnectorsProviders

cloudasset.assets.listConnectorsRuntimeConfigs

cloudasset.assets.listContainerAppsDeployment

cloudasset.assets.listContainerAppsReplicaSets

cloudasset.assets.listContainerBatchJobs

cloudasset.assets.listContainerClusterrole

cloudasset.assets.listContainerClusterrolebinding

cloudasset.assets.listContainerClusters

cloudasset.assets.listContainerExtensionsIngresses

cloudasset.assets.listContainerJobs

cloudasset.assets.listContainerNamespace

cloudasset.assets.listContainerNetworkingIngresses

cloudasset.assets.listContainerNetworkingNetworkPolicies

cloudasset.assets.listContainerNode

cloudasset.assets.listContainerNodepool

cloudasset.assets.listContainerPod

cloudasset.assets.listContainerReplicaSets

cloudasset.assets.listContainerRole

cloudasset.assets.listContainerRolebinding

cloudasset.assets.listContainerServices

cloudasset.assets.listContainerregistryImage

cloudasset.assets.listDataMigrationConnectionProfiles

cloudasset.assets.listDataMigrationMigrationJobs

cloudasset.assets.listDataflowJobs

cloudasset.assets.listDatafusionInstance

cloudasset.assets.listDataplexAssets

cloudasset.assets.listDataplexLakes

cloudasset.assets.listDataplexTasks

cloudasset.assets.listDataplexZones

cloudasset.assets.listDataprocAutoscalingPolicies

cloudasset.assets.listDataprocBatches

cloudasset.assets.listDataprocClusters

cloudasset.assets.listDataprocJobs

cloudasset.assets.listDataprocSessions

cloudasset.assets.listDataprocWorkflowTemplates

cloudasset.assets.listDatastreamConnectionProfile

cloudasset.assets.listDatastreamPrivateConnection

cloudasset.assets.listDatastreamStream

cloudasset.assets.listDialogflowAgents

cloudasset.assets.listDialogflowConversationProfiles

cloudasset.assets.listDialogflowKnowledgeBases

cloudasset.assets.listDialogflowLocationSettings

cloudasset.assets.listDlpDeidentifyTemplates

cloudasset.assets.listDlpDlpJobs

cloudasset.assets.listDlpInspectTemplates

cloudasset.assets.listDlpJobTriggers

cloudasset.assets.listDlpStoredInfoTypes

cloudasset.assets.listDnsManagedZones

cloudasset.assets.listDnsPolicies

cloudasset.assets.listDomainsRegistrations

cloudasset.assets.listEventarcTriggers

cloudasset.assets.listFileBackups

cloudasset.assets.listFileInstances

cloudasset.assets.listFirebaseAppInfos

cloudasset.assets.listFirebaseProjects

cloudasset.assets.listFirestoreDatabases

cloudasset.assets.listGKEHubFeatures

cloudasset.assets.listGKEHubMemberships

cloudasset.assets.listGameservicesGameServerClusters

cloudasset.assets.listGameservicesGameServerConfigs

cloudasset.assets.listGameservicesGameServerDeployments

cloudasset.assets.listGameservicesRealms

cloudasset.assets.listGkeBackupBackupPlans

cloudasset.assets.listGkeBackupBackups

cloudasset.assets.listGkeBackupRestorePlans

cloudasset.assets.listGkeBackupRestores

cloudasset.assets.listGkeBackupVolumeBackups

cloudasset.assets.listGkeBackupVolumeRestores

cloudasset.assets.listHealthcareConsentStores

cloudasset.assets.listHealthcareDatasets

cloudasset.assets.listHealthcareDicomStores

cloudasset.assets.listHealthcareFhirStores

cloudasset.assets.listHealthcareHl7V2Stores

cloudasset.assets.listIamPolicy

cloudasset.assets.listIamRoles

cloudasset.assets.listIamServiceAccountKeys

cloudasset.assets.listIamServiceAccounts

cloudasset.assets.listIapTunnel

cloudasset.assets.listIapTunnelInstances

cloudasset.assets.listIapTunnelZones

cloudasset.assets.listIapWeb

cloudasset.assets.listIapWebServiceVersion

cloudasset.assets.listIapWebServices

cloudasset.assets.listIapWebType

cloudasset.assets.listIdsEndpoints

cloudasset.assets.listIntegrationsAuthConfigs

cloudasset.assets.listIntegrationsCertificates

cloudasset.assets.listIntegrationsExecutions

cloudasset.assets.listIntegrationsIntegrationVersions

cloudasset.assets.listIntegrationsIntegrations

cloudasset.assets.listIntegrationsSfdcChannels

cloudasset.assets.listIntegrationsSfdcInstances

cloudasset.assets.listIntegrationsSuspensions

cloudasset.assets.listLoggingLogMetrics

cloudasset.assets.listLoggingLogSinks

cloudasset.assets.listManagedidentitiesDomain

cloudasset.assets.listMetastoreBackups

cloudasset.assets.listMetastoreMetadataImports

cloudasset.assets.listMetastoreServices

cloudasset.assets.listMonitoringAlertPolicies

cloudasset.assets.listNetworkConnectivityHubs

cloudasset.assets.listNetworkConnectivitySpokes

cloudasset.assets.listNetworkManagementConnectivityTests

cloudasset.assets.listNetworkServicesEndpointPolicies

cloudasset.assets.listNetworkServicesGateways

cloudasset.assets.listNetworkServicesGrpcRoutes

cloudasset.assets.listNetworkServicesHttpRoutes

cloudasset.assets.listNetworkServicesMeshes

cloudasset.assets.listNetworkServicesServiceBindings

cloudasset.assets.listNetworkServicesTcpRoutes

cloudasset.assets.listNetworkServicesTlsRoutes

cloudasset.assets.listOSConfigOSPolicyAssignmentReports

cloudasset.assets.listOSConfigOSPolicyAssignments

cloudasset.assets.listOSConfigVulnerabilityReports

cloudasset.assets.listOSInventories

cloudasset.assets.listOrgPolicy

cloudasset.assets.listPatchDeployments

cloudasset.assets.listPubsubSnapshots

cloudasset.assets.listPubsubSubscriptions

cloudasset.assets.listPubsubTopics

cloudasset.assets.listRedisInstances

cloudasset.assets.listResource

cloudasset.assets.listRunDomainMapping

cloudasset.assets.listRunRevision

cloudasset.assets.listRunService

cloudasset.assets.listSecretManagerSecretVersions

cloudasset.assets.listSecretManagerSecrets

cloudasset.assets.listServiceDirectoryNamespaces

cloudasset.assets.listServicePerimeter

cloudasset.assets.listServiceconsumermanagementConsumerProperty

cloudasset.assets.listServiceconsumermanagementConsumerQuotaLimits

cloudasset.assets.listServiceconsumermanagementConsumers

cloudasset.assets.listServiceconsumermanagementProducerOverrides

cloudasset.assets.listServiceconsumermanagementTenancyUnits

cloudasset.assets.listServiceconsumermanagementVisibility

cloudasset.assets.listServicemanagementServices

cloudasset.assets.listServiceusageAdminOverrides

cloudasset.assets.listServiceusageConsumerOverrides

cloudasset.assets.listServiceusageServices

cloudasset.assets.listSpannerBackups

cloudasset.assets.listSpannerDatabases

cloudasset.assets.listSpannerInstances

cloudasset.assets.listSpeakerIdPhrases

cloudasset.assets.listSpeakerIdSettings

cloudasset.assets.listSpeakerIdSpeakers

cloudasset.assets.listSpeechCustomClasses

cloudasset.assets.listSpeechPhraseSets

cloudasset.assets.listSqladminBackupRuns

cloudasset.assets.listSqladminInstances

cloudasset.assets.listStorageBuckets

cloudasset.assets.listTpuNodes

cloudasset.assets.listVpcaccessConnector

cloudasset.assets.queryAccessPolicy

cloudasset.assets.queryIamPolicy

cloudasset.assets.queryOSInventories

cloudasset.assets.queryResource

cloudasset.assets.searchAllIamPolicies

cloudasset.assets.searchAllResources

cloudasset.feeds.*

  • cloudasset.feeds.create
  • cloudasset.feeds.delete
  • cloudasset.feeds.get
  • cloudasset.feeds.list
  • cloudasset.feeds.update

cloudasset.othercloudconnections.get

cloudasset.othercloudconnections.list

cloudasset.othercloudconnections.verify

cloudsql.instances.connect

cloudsql.users.list

compute.disks.useReadOnly

compute.globalOperations.get

compute.instances.get

compute.instances.list

compute.networkEndpointGroups.get

compute.projects.get

compute.regionOperations.get

compute.zoneOperations.get

container.clusters.get

iam.denypolicies.get

iam.denypolicies.list

iam.googleapis.com/workloadIdentityPoolProviders.list

iam.googleapis.com/workloadIdentityPools.list

logging.logEntries.list

monitoring.alertPolicies.list

monitoring.timeSeries.list

orgpolicy.policies.list

orgpolicy.policy.get

recommender.cloudAssetInsights.get

recommender.cloudAssetInsights.list

recommender.locations.*

  • recommender.locations.get
  • recommender.locations.list

resourcemanager.folders.get

resourcemanager.folders.list

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.getIamPolicy

resourcemanager.projects.list

resourcemanager.tagValues.get

securitycenter.assets.list

securitycenter.assetsecuritymarks.update

securitycenter.findings.list

securitycenter.notificationconfig.create

securitycenter.notificationconfig.delete

securitycenter.notificationconfig.update

securitycenter.organizationsettings.get

securitycenter.resourcevalueconfigs.get

securitycenter.resourcevalueconfigs.list

securitycenter.simulations.get

securitycenter.sources.list

securitycenter.valuedresources.list

securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.*

  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.get
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.list

securitycentermanagement.securityHealthAnalyticsCustomModules.create

securitycentermanagement.securityHealthAnalyticsCustomModules.delete

securitycentermanagement.securityHealthAnalyticsCustomModules.get

securitycentermanagement.securityHealthAnalyticsCustomModules.list

securitycentermanagement.securityHealthAnalyticsCustomModules.simulate

securitycentermanagement.securityHealthAnalyticsCustomModules.update

serviceusage.quotas.get

serviceusage.services.disable

serviceusage.services.enable

serviceusage.services.get

serviceusage.services.list

stackdriver.projects.get

storage.buckets.get

storage.buckets.getIamPolicy

storage.buckets.list

(roles/securitycenter.externalSystemsEditor)

Write access to security center external systems

securitycenter.findingexternalsystems.update

(roles/securitycenter.findingSecurityMarksWriter)

Write access to finding security marks

Lowest-level resources where you can grant this role:

  • Project

securitycenter.findingsecuritymarks.update

securitycenter.userinterfacemetadata.get

(roles/securitycenter.findingsBulkMuteEditor)

Ability to mute findings in bulk

securitycenter.findings.bulkMuteUpdate

(roles/securitycenter.findingsEditor)

Read-write access to findings

Lowest-level resources where you can grant this role:

  • Project

resourcemanager.folders.get

resourcemanager.organizations.get

resourcemanager.projects.get

securitycenter.complianceReports.aggregate

securitycenter.compliancesnapshots.list

securitycenter.findingexplanations.get

securitycenter.findings.bulkMuteUpdate

securitycenter.findings.group

securitycenter.findings.list

securitycenter.findings.listFindingPropertyNames

securitycenter.findings.setMute

securitycenter.findings.setState

securitycenter.findings.update

securitycenter.issues.*

  • securitycenter.issues.get
  • securitycenter.issues.group
  • securitycenter.issues.list
  • securitycenter.issues.listFilterValues
  • securitycenter.issues.mute

securitycenter.sources.get

securitycenter.sources.list

securitycenter.userinterfacemetadata.get

securitycenter.vulnerabilitysnapshots.list

(roles/securitycenter.findingsMuteSetter)

Set mute access to findings

securitycenter.findings.setMute

(roles/securitycenter.findingsStateSetter)

Set state access to findings

Lowest-level resources where you can grant this role:

  • Project

securitycenter.findings.setState

securitycenter.userinterfacemetadata.get

(roles/securitycenter.findingsViewer)

Read access to findings

Lowest-level resources where you can grant this role:

  • Project

resourcemanager.folders.get

resourcemanager.organizations.get

resourcemanager.projects.get

securitycenter.complianceReports.aggregate

securitycenter.compliancesnapshots.list

securitycenter.findingexplanations.get

securitycenter.findings.group

securitycenter.findings.list

securitycenter.findings.listFindingPropertyNames

securitycenter.issues.get

securitycenter.issues.group

securitycenter.issues.list

securitycenter.issues.listFilterValues

securitycenter.sources.get

securitycenter.sources.list

securitycenter.userinterfacemetadata.get

securitycenter.vulnerabilitysnapshots.list

(roles/securitycenter.findingsWorkflowStateSetter)

Set workflow state access to findings

Lowest-level resources where you can grant this role:

  • Project

securitycenter.findings.setWorkflowState

securitycenter.userinterfacemetadata.get

(roles/securitycenter.integrationExecutorServiceAgent)

Gives Security Center access to execute Integrations.

integrations.securityExecutions.cancel

integrations.securityExecutions.list

integrations.securityIntegrations.invoke

(roles/securitycenter.issuesEditor)

Write access to security center issues

securitycenter.issues.*

  • securitycenter.issues.get
  • securitycenter.issues.group
  • securitycenter.issues.list
  • securitycenter.issues.listFilterValues
  • securitycenter.issues.mute

(roles/securitycenter.issuesViewer)

Read access to security center issues

securitycenter.issues.get

securitycenter.issues.group

securitycenter.issues.list

securitycenter.issues.listFilterValues

(roles/securitycenter.muteConfigsEditor)

Read-Write access to security center mute configurations

securitycenter.muteconfigs.*

  • securitycenter.muteconfigs.create
  • securitycenter.muteconfigs.delete
  • securitycenter.muteconfigs.get
  • securitycenter.muteconfigs.list
  • securitycenter.muteconfigs.update

(roles/securitycenter.muteConfigsViewer)

Read access to security center mute configurations

securitycenter.muteconfigs.get

securitycenter.muteconfigs.list

(roles/securitycenter.notificationConfigEditor)

Write access to notification configurations

Lowest-level resources where you can grant this role:

  • Organization

securitycenter.notificationconfig.*

  • securitycenter.notificationconfig.create
  • securitycenter.notificationconfig.delete
  • securitycenter.notificationconfig.get
  • securitycenter.notificationconfig.list
  • securitycenter.notificationconfig.update

securitycenter.userinterfacemetadata.get

(roles/securitycenter.notificationConfigViewer)

Read access to notification configurations

Lowest-level resources where you can grant this role:

  • Organization

securitycenter.notificationconfig.get

securitycenter.notificationconfig.list

securitycenter.userinterfacemetadata.get

(roles/securitycenter.notificationServiceAgent)

Security Center service agent can publish notifications to Pub/Sub topics.

pubsub.topics.publish

(roles/securitycenter.resourceValueConfigsEditor)

Read-Write access to security center resource value configurations

resourcemanager.tagValues.get

securitycenter.resourcevalueconfigs.*

  • securitycenter.resourcevalueconfigs.create
  • securitycenter.resourcevalueconfigs.delete
  • securitycenter.resourcevalueconfigs.get
  • securitycenter.resourcevalueconfigs.list
  • securitycenter.resourcevalueconfigs.update

(roles/securitycenter.resourceValueConfigsViewer)

Read access to security center resource value configurations

resourcemanager.tagValues.get

securitycenter.resourcevalueconfigs.get

securitycenter.resourcevalueconfigs.list

(roles/securitycenter.securityHealthAnalyticsCustomModulesTester)

Test access to Security Health Analytics Custom Modules

securitycenter.securityhealthanalyticscustommodules.simulate

securitycenter.securityhealthanalyticscustommodules.test

securitycentermanagement.securityHealthAnalyticsCustomModules.simulate

securitycentermanagement.securityHealthAnalyticsCustomModules.test

(roles/securitycenter.securityHealthAnalyticsServiceAgent)

Security Health Analytics service agent can scan GCP resource metadata to find security vulnerabilities.

bigquery.datasets.get

binaryauthorization.policy.get

cloudasset.assets.analyzeIamPolicy

cloudasset.assets.analyzeMove

cloudasset.assets.analyzeOrgPolicy

cloudasset.assets.exportAccessLevel

cloudasset.assets.exportAccessPolicy

cloudasset.assets.exportAiplatformBatchPredictionJobs

cloudasset.assets.exportAiplatformCustomJobs

cloudasset.assets.exportAiplatformDataLabelingJobs

cloudasset.assets.exportAiplatformDatasets

cloudasset.assets.exportAiplatformEndpoints

cloudasset.assets.exportAiplatformHyperparameterTuningJobs

cloudasset.assets.exportAiplatformMetadataStores

cloudasset.assets.exportAiplatformModelDeploymentMonitoringJobs

cloudasset.assets.exportAiplatformModels

cloudasset.assets.exportAiplatformPipelineJobs

cloudasset.assets.exportAiplatformSpecialistPools

cloudasset.assets.exportAiplatformTrainingPipelines

cloudasset.assets.exportAllAccessPolicy

cloudasset.assets.exportAnthosConnectedCluster

cloudasset.assets.exportAnthosedgeCluster

cloudasset.assets.exportApigatewayApi

cloudasset.assets.exportApigatewayApiConfig

cloudasset.assets.exportApigatewayGateway

cloudasset.assets.exportApikeysKeys

cloudasset.assets.exportAppengineApplications

cloudasset.assets.exportAppengineServices

cloudasset.assets.exportAppengineVersions

cloudasset.assets.exportArtifactregistryDockerImages

cloudasset.assets.exportArtifactregistryRepositories

cloudasset.assets.exportAssuredWorkloadsWorkloads

cloudasset.assets.exportBeyondCorpApiGateways

cloudasset.assets.exportBeyondCorpAppConnections

cloudasset.assets.exportBeyondCorpAppConnectors

cloudasset.assets.exportBeyondCorpAppGateways

cloudasset.assets.exportBeyondCorpClientConnectorServices

cloudasset.assets.exportBeyondCorpClientGateways

cloudasset.assets.exportBigqueryDatasets

cloudasset.assets.exportBigqueryModels

cloudasset.assets.exportBigqueryTables

cloudasset.assets.exportBigtableAppProfile

cloudasset.assets.exportBigtableBackup

cloudasset.assets.exportBigtableCluster

cloudasset.assets.exportBigtableInstance

cloudasset.assets.exportBigtableTable

cloudasset.assets.exportCloudAssetFeeds

cloudasset.assets.exportCloudDeployDeliveryPipelines

cloudasset.assets.exportCloudDeployReleases

cloudasset.assets.exportCloudDeployRollouts

cloudasset.assets.exportCloudDeployTargets

cloudasset.assets.exportCloudDocumentAIEvaluation

cloudasset.assets.exportCloudDocumentAIHumanReviewConfig

cloudasset.assets.exportCloudDocumentAILabelerPool

cloudasset.assets.exportCloudDocumentAIProcessor

cloudasset.assets.exportCloudDocumentAIProcessorVersion

cloudasset.assets.exportCloudbillingBillingAccounts

cloudasset.assets.exportCloudbillingProjectBillingInfos

cloudasset.assets.exportCloudfunctionsFunctions

cloudasset.assets.exportCloudfunctionsGen2Functions

cloudasset.assets.exportCloudkmsCryptoKeyVersions

cloudasset.assets.exportCloudkmsCryptoKeys

cloudasset.assets.exportCloudkmsEkmConnections

cloudasset.assets.exportCloudkmsImportJobs

cloudasset.assets.exportCloudkmsKeyRings

cloudasset.assets.exportCloudmemcacheInstances

cloudasset.assets.exportCloudresourcemanagerFolders

cloudasset.assets.exportCloudresourcemanagerOrganizations

cloudasset.assets.exportCloudresourcemanagerProjects

cloudasset.assets.exportCloudresourcemanagerTagBindings

cloudasset.assets.exportCloudresourcemanagerTagKeys

cloudasset.assets.exportCloudresourcemanagerTagValues

cloudasset.assets.exportComposerEnvironments

cloudasset.assets.exportComputeAddress

cloudasset.assets.exportComputeAutoscalers

cloudasset.assets.exportComputeBackendBuckets

cloudasset.assets.exportComputeBackendServices

cloudasset.assets.exportComputeCommitments

cloudasset.assets.exportComputeDisks

cloudasset.assets.exportComputeExternalVpnGateways

cloudasset.assets.exportComputeFirewallPolicies

cloudasset.assets.exportComputeFirewalls

cloudasset.assets.exportComputeForwardingRules

cloudasset.assets.exportComputeGlobalAddress

cloudasset.assets.exportComputeGlobalForwardingRules

cloudasset.assets.exportComputeHealthChecks

cloudasset.assets.exportComputeHttpHealthChecks

cloudasset.assets.exportComputeHttpsHealthChecks

cloudasset.assets.exportComputeImages

cloudasset.assets.exportComputeInstanceGroupManagers

cloudasset.assets.exportComputeInstanceGroups

cloudasset.assets.exportComputeInstanceTemplates

cloudasset.assets.exportComputeInstances

cloudasset.assets.exportComputeInterconnect

cloudasset.assets.exportComputeInterconnectAttachment

cloudasset.assets.exportComputeLicenses

cloudasset.assets.exportComputeNetworkEndpointGroups

cloudasset.assets.exportComputeNetworks

cloudasset.assets.exportComputeNodeGroups

cloudasset.assets.exportComputeNodeTemplates

cloudasset.assets.exportComputePacketMirrorings

cloudasset.assets.exportComputeProjects

cloudasset.assets.exportComputeRegionAutoscaler

cloudasset.assets.exportComputeRegionBackendServices

cloudasset.assets.exportComputeRegionDisk

cloudasset.assets.exportComputeRegionInstanceGroup

cloudasset.assets.exportComputeRegionInstanceGroupManager

cloudasset.assets.exportComputeReservations

cloudasset.assets.exportComputeResourcePolicies

cloudasset.assets.exportComputeRouters

cloudasset.assets.exportComputeRoutes

cloudasset.assets.exportComputeSecurityPolicy

cloudasset.assets.exportComputeServiceAttachments

cloudasset.assets.exportComputeSnapshots

cloudasset.assets.exportComputeSslCertificates

cloudasset.assets.exportComputeSslPolicies

cloudasset.assets.exportComputeSubnetworks

cloudasset.assets.exportComputeTargetHttpProxies

cloudasset.assets.exportComputeTargetHttpsProxies

cloudasset.assets.exportComputeTargetInstances

cloudasset.assets.exportComputeTargetPools

cloudasset.assets.exportComputeTargetSslProxies

cloudasset.assets.exportComputeTargetTcpProxies

cloudasset.assets.exportComputeTargetVpnGateways

cloudasset.assets.exportComputeUrlMaps

cloudasset.assets.exportComputeVpnGateways

cloudasset.assets.exportComputeVpnTunnels

cloudasset.assets.exportConnectorsConnections

cloudasset.assets.exportConnectorsConnectorVersions

cloudasset.assets.exportConnectorsConnectors

cloudasset.assets.exportConnectorsProviders

cloudasset.assets.exportConnectorsRuntimeConfigs

cloudasset.assets.exportContainerAppsDeployment

cloudasset.assets.exportContainerAppsReplicaSets

cloudasset.assets.exportContainerBatchJobs

cloudasset.assets.exportContainerClusterrole

cloudasset.assets.exportContainerClusterrolebinding

cloudasset.assets.exportContainerClusters

cloudasset.assets.exportContainerExtensionsIngresses

cloudasset.assets.exportContainerJobs

cloudasset.assets.exportContainerNamespace

cloudasset.assets.exportContainerNetworkingIngresses

cloudasset.assets.exportContainerNetworkingNetworkPolicies

cloudasset.assets.exportContainerNode

cloudasset.assets.exportContainerNodepool

cloudasset.assets.exportContainerPod

cloudasset.assets.exportContainerReplicaSets

cloudasset.assets.exportContainerRole

cloudasset.assets.exportContainerRolebinding

cloudasset.assets.exportContainerServices

cloudasset.assets.exportContainerregistryImage

cloudasset.assets.exportDataMigrationConnectionProfiles

cloudasset.assets.exportDataMigrationMigrationJobs

cloudasset.assets.exportDataflowJobs

cloudasset.assets.exportDatafusionInstance

cloudasset.assets.exportDataplexAssets

cloudasset.assets.exportDataplexLakes

cloudasset.assets.exportDataplexTasks

cloudasset.assets.exportDataplexZones

cloudasset.assets.exportDataprocAutoscalingPolicies

cloudasset.assets.exportDataprocBatches

cloudasset.assets.exportDataprocClusters

cloudasset.assets.exportDataprocJobs

cloudasset.assets.exportDataprocSessions

cloudasset.assets.exportDataprocWorkflowTemplates

cloudasset.assets.exportDatastreamConnectionProfile

cloudasset.assets.exportDatastreamPrivateConnection

cloudasset.assets.exportDatastreamStream

cloudasset.assets.exportDialogflowAgents

cloudasset.assets.exportDialogflowConversationProfiles

cloudasset.assets.exportDialogflowKnowledgeBases

cloudasset.assets.exportDialogflowLocationSettings

cloudasset.assets.exportDlpDeidentifyTemplates

cloudasset.assets.exportDlpDlpJobs

cloudasset.assets.exportDlpInspectTemplates

cloudasset.assets.exportDlpJobTriggers

cloudasset.assets.exportDlpStoredInfoTypes

cloudasset.assets.exportDnsManagedZones

cloudasset.assets.exportDnsPolicies

cloudasset.assets.exportDomainsRegistrations

cloudasset.assets.exportEventarcTriggers

cloudasset.assets.exportFileBackups

cloudasset.assets.exportFileInstances

cloudasset.assets.exportFirebaseAppInfos

cloudasset.assets.exportFirebaseProjects

cloudasset.assets.exportFirestoreDatabases

cloudasset.assets.exportGKEHubFeatures

cloudasset.assets.exportGKEHubMemberships

cloudasset.assets.exportGameservicesGameServerClusters

cloudasset.assets.exportGameservicesGameServerConfigs

cloudasset.assets.exportGameservicesGameServerDeployments

cloudasset.assets.exportGameservicesRealms

cloudasset.assets.exportGkeBackupBackupPlans

cloudasset.assets.exportGkeBackupBackups

cloudasset.assets.exportGkeBackupRestorePlans

cloudasset.assets.exportGkeBackupRestores

cloudasset.assets.exportGkeBackupVolumeBackups

cloudasset.assets.exportGkeBackupVolumeRestores

cloudasset.assets.exportHealthcareConsentStores

cloudasset.assets.exportHealthcareDatasets

cloudasset.assets.exportHealthcareDicomStores

cloudasset.assets.exportHealthcareFhirStores

cloudasset.assets.exportHealthcareHl7V2Stores

cloudasset.assets.exportIamPolicy

cloudasset.assets.exportIamRoles

cloudasset.assets.exportIamServiceAccountKeys

cloudasset.assets.exportIamServiceAccounts

cloudasset.assets.exportIapTunnel

cloudasset.assets.exportIapTunnelInstances

cloudasset.assets.exportIapTunnelZones

cloudasset.assets.exportIapWeb

cloudasset.assets.exportIapWebServiceVersion

cloudasset.assets.exportIapWebServices

cloudasset.assets.exportIapWebType

cloudasset.assets.exportIdsEndpoints

cloudasset.assets.exportIntegrationsAuthConfigs

cloudasset.assets.exportIntegrationsCertificates

cloudasset.assets.exportIntegrationsExecutions

cloudasset.assets.exportIntegrationsIntegrationVersions

cloudasset.assets.exportIntegrationsIntegrations

cloudasset.assets.exportIntegrationsSfdcChannels

cloudasset.assets.exportIntegrationsSfdcInstances

cloudasset.assets.exportIntegrationsSuspensions

cloudasset.assets.exportLoggingLogMetrics

cloudasset.assets.exportLoggingLogSinks

cloudasset.assets.exportManagedidentitiesDomain

cloudasset.assets.exportMetastoreBackups

cloudasset.assets.exportMetastoreMetadataImports

cloudasset.assets.exportMetastoreServices

cloudasset.assets.exportMonitoringAlertPolicies

cloudasset.assets.exportNetworkConnectivityHubs

cloudasset.assets.exportNetworkConnectivitySpokes

cloudasset.assets.exportNetworkManagementConnectivityTests

cloudasset.assets.exportNetworkServicesEndpointPolicies

cloudasset.assets.exportNetworkServicesGateways

cloudasset.assets.exportNetworkServicesGrpcRoutes

cloudasset.assets.exportNetworkServicesHttpRoutes

cloudasset.assets.exportNetworkServicesMeshes

cloudasset.assets.exportNetworkServicesServiceBindings

cloudasset.assets.exportNetworkServicesTcpRoutes

cloudasset.assets.exportNetworkServicesTlsRoutes

cloudasset.assets.exportOSConfigOSPolicyAssignmentReports

cloudasset.assets.exportOSConfigOSPolicyAssignments

cloudasset.assets.exportOSConfigVulnerabilityReports

cloudasset.assets.exportOSInventories

cloudasset.assets.exportOrgPolicy

cloudasset.assets.exportPatchDeployments

cloudasset.assets.exportPubsubSnapshots

cloudasset.assets.exportPubsubSubscriptions

cloudasset.assets.exportPubsubTopics

cloudasset.assets.exportRedisInstances

cloudasset.assets.exportResource

cloudasset.assets.exportSecretManagerSecretVersions

cloudasset.assets.exportSecretManagerSecrets

cloudasset.assets.exportServiceDirectoryNamespaces

cloudasset.assets.exportServicePerimeter

cloudasset.assets.exportServiceconsumermanagementConsumerProperty

cloudasset.assets.exportServiceconsumermanagementConsumerQuotaLimits

cloudasset.assets.exportServiceconsumermanagementConsumers

cloudasset.assets.exportServiceconsumermanagementProducerOverrides

cloudasset.assets.exportServiceconsumermanagementTenancyUnits

cloudasset.assets.exportServiceconsumermanagementVisibility

cloudasset.assets.exportServicemanagementServices

cloudasset.assets.exportServiceusageAdminOverrides

cloudasset.assets.exportServiceusageConsumerOverrides

cloudasset.assets.exportServiceusageServices

cloudasset.assets.exportSpannerBackups

cloudasset.assets.exportSpannerDatabases

cloudasset.assets.exportSpannerInstances

cloudasset.assets.exportSpeakerIdPhrases

cloudasset.assets.exportSpeakerIdSettings

cloudasset.assets.exportSpeakerIdSpeakers

cloudasset.assets.exportSpeechCustomClasses

cloudasset.assets.exportSpeechPhraseSets

cloudasset.assets.exportSqladminBackupRuns

cloudasset.assets.exportSqladminInstances

cloudasset.assets.exportStorageBuckets

cloudasset.assets.exportTpuNodes

cloudasset.assets.exportVpcaccessConnector

cloudasset.assets.listAccessLevel

cloudasset.assets.listAccessPolicy

cloudasset.assets.listAiplatformBatchPredictionJobs

cloudasset.assets.listAiplatformCustomJobs

cloudasset.assets.listAiplatformDataLabelingJobs

cloudasset.assets.listAiplatformDatasets

cloudasset.assets.listAiplatformEndpoints

cloudasset.assets.listAiplatformHyperparameterTuningJobs

cloudasset.assets.listAiplatformMetadataStores

cloudasset.assets.listAiplatformModelDeploymentMonitoringJobs

cloudasset.assets.listAiplatformModels

cloudasset.assets.listAiplatformPipelineJobs

cloudasset.assets.listAiplatformSpecialistPools

cloudasset.assets.listAiplatformTrainingPipelines

cloudasset.assets.listAllAccessPolicy

cloudasset.assets.listAnthosConnectedCluster

cloudasset.assets.listAnthosedgeCluster

cloudasset.assets.listApigatewayApi

cloudasset.assets.listApigatewayApiConfig

cloudasset.assets.listApigatewayGateway

cloudasset.assets.listApikeysKeys

cloudasset.assets.listAppengineApplications

cloudasset.assets.listAppengineServices

cloudasset.assets.listAppengineVersions

cloudasset.assets.listArtifactregistryDockerImages

cloudasset.assets.listArtifactregistryRepositories

cloudasset.assets.listAssuredWorkloadsWorkloads

cloudasset.assets.listBeyondCorpApiGateways

cloudasset.assets.listBeyondCorpAppConnections

cloudasset.assets.listBeyondCorpAppConnectors

cloudasset.assets.listBeyondCorpAppGateways

cloudasset.assets.listBeyondCorpClientConnectorServices

cloudasset.assets.listBeyondCorpClientGateways

cloudasset.assets.listBigqueryDatasets

cloudasset.assets.listBigqueryModels

cloudasset.assets.listBigqueryTables

cloudasset.assets.listBigtableAppProfile

cloudasset.assets.listBigtableBackup

cloudasset.assets.listBigtableCluster

cloudasset.assets.listBigtableInstance

cloudasset.assets.listBigtableTable

cloudasset.assets.listCloudAssetFeeds

cloudasset.assets.listCloudDeployDeliveryPipelines

cloudasset.assets.listCloudDeployReleases

cloudasset.assets.listCloudDeployRollouts

cloudasset.assets.listCloudDeployTargets

cloudasset.assets.listCloudDocumentAIEvaluation

cloudasset.assets.listCloudDocumentAIHumanReviewConfig

cloudasset.assets.listCloudDocumentAILabelerPool

cloudasset.assets.listCloudDocumentAIProcessor

cloudasset.assets.listCloudDocumentAIProcessorVersion

cloudasset.assets.listCloudbillingBillingAccounts

cloudasset.assets.listCloudbillingProjectBillingInfos

cloudasset.assets.listCloudfunctionsFunctions

cloudasset.assets.listCloudfunctionsGen2Functions

cloudasset.assets.listCloudkmsCryptoKeyVersions

cloudasset.assets.listCloudkmsCryptoKeys

cloudasset.assets.listCloudkmsEkmConnections

cloudasset.assets.listCloudkmsImportJobs

cloudasset.assets.listCloudkmsKeyRings

cloudasset.assets.listCloudmemcacheInstances

cloudasset.assets.listCloudresourcemanagerFolders

cloudasset.assets.listCloudresourcemanagerOrganizations

cloudasset.assets.listCloudresourcemanagerProjects

cloudasset.assets.listCloudresourcemanagerTagBindings

cloudasset.assets.listCloudresourcemanagerTagKeys

cloudasset.assets.listCloudresourcemanagerTagValues

cloudasset.assets.listComposerEnvironments

cloudasset.assets.listComputeAddress

cloudasset.assets.listComputeAutoscalers

cloudasset.assets.listComputeBackendBuckets

cloudasset.assets.listComputeBackendServices

cloudasset.assets.listComputeCommitments

cloudasset.assets.listComputeDisks

cloudasset.assets.listComputeExternalVpnGateways

cloudasset.assets.listComputeFirewallPolicies

cloudasset.assets.listComputeFirewalls

cloudasset.assets.listComputeForwardingRules

cloudasset.assets.listComputeGlobalAddress

cloudasset.assets.listComputeGlobalForwardingRules

cloudasset.assets.listComputeHealthChecks

cloudasset.assets.listComputeHttpHealthChecks

cloudasset.assets.listComputeHttpsHealthChecks

cloudasset.assets.listComputeImages

cloudasset.assets.listComputeInstanceGroupManagers

cloudasset.assets.listComputeInstanceGroups

cloudasset.assets.listComputeInstanceTemplates

cloudasset.assets.listComputeInstances

cloudasset.assets.listComputeInterconnect

cloudasset.assets.listComputeInterconnectAttachment

cloudasset.assets.listComputeLicenses

cloudasset.assets.listComputeNetworkEndpointGroups

cloudasset.assets.listComputeNetworks

cloudasset.assets.listComputeNodeGroups

cloudasset.assets.listComputeNodeTemplates

cloudasset.assets.listComputePacketMirrorings

cloudasset.assets.listComputeProjects

cloudasset.assets.listComputeRegionAutoscaler

cloudasset.assets.listComputeRegionBackendServices

cloudasset.assets.listComputeRegionDisk

cloudasset.assets.listComputeRegionInstanceGroup

cloudasset.assets.listComputeRegionInstanceGroupManager

cloudasset.assets.listComputeReservations

cloudasset.assets.listComputeResourcePolicies

cloudasset.assets.listComputeRouters

cloudasset.assets.listComputeRoutes

cloudasset.assets.listComputeSecurityPolicy

cloudasset.assets.listComputeServiceAttachments

cloudasset.assets.listComputeSnapshots

cloudasset.assets.listComputeSslCertificates

cloudasset.assets.listComputeSslPolicies

cloudasset.assets.listComputeSubnetworks

cloudasset.assets.listComputeTargetHttpProxies

cloudasset.assets.listComputeTargetHttpsProxies

cloudasset.assets.listComputeTargetInstances

cloudasset.assets.listComputeTargetPools

cloudasset.assets.listComputeTargetSslProxies

cloudasset.assets.listComputeTargetTcpProxies

cloudasset.assets.listComputeTargetVpnGateways

cloudasset.assets.listComputeUrlMaps

cloudasset.assets.listComputeVpnGateways

cloudasset.assets.listComputeVpnTunnels

cloudasset.assets.listConnectorsConnections

cloudasset.assets.listConnectorsConnectorVersions

cloudasset.assets.listConnectorsConnectors

cloudasset.assets.listConnectorsProviders

cloudasset.assets.listConnectorsRuntimeConfigs

cloudasset.assets.listContainerAppsDeployment

cloudasset.assets.listContainerAppsReplicaSets

cloudasset.assets.listContainerBatchJobs

cloudasset.assets.listContainerClusterrole

cloudasset.assets.listContainerClusterrolebinding

cloudasset.assets.listContainerClusters

cloudasset.assets.listContainerExtensionsIngresses

cloudasset.assets.listContainerJobs

cloudasset.assets.listContainerNamespace

cloudasset.assets.listContainerNetworkingIngresses

cloudasset.assets.listContainerNetworkingNetworkPolicies

cloudasset.assets.listContainerNode

cloudasset.assets.listContainerNodepool

cloudasset.assets.listContainerPod

cloudasset.assets.listContainerReplicaSets

cloudasset.assets.listContainerRole

cloudasset.assets.listContainerRolebinding

cloudasset.assets.listContainerServices

cloudasset.assets.listContainerregistryImage

cloudasset.assets.listDataMigrationConnectionProfiles

cloudasset.assets.listDataMigrationMigrationJobs

cloudasset.assets.listDataflowJobs

cloudasset.assets.listDatafusionInstance

cloudasset.assets.listDataplexAssets

cloudasset.assets.listDataplexLakes

cloudasset.assets.listDataplexTasks

cloudasset.assets.listDataplexZones

cloudasset.assets.listDataprocAutoscalingPolicies

cloudasset.assets.listDataprocBatches

cloudasset.assets.listDataprocClusters

cloudasset.assets.listDataprocJobs

cloudasset.assets.listDataprocSessions

cloudasset.assets.listDataprocWorkflowTemplates

cloudasset.assets.listDatastreamConnectionProfile

cloudasset.assets.listDatastreamPrivateConnection

cloudasset.assets.listDatastreamStream

cloudasset.assets.listDialogflowAgents

cloudasset.assets.listDialogflowConversationProfiles

cloudasset.assets.listDialogflowKnowledgeBases

cloudasset.assets.listDialogflowLocationSettings

cloudasset.assets.listDlpDeidentifyTemplates

cloudasset.assets.listDlpDlpJobs

cloudasset.assets.listDlpInspectTemplates

cloudasset.assets.listDlpJobTriggers

cloudasset.assets.listDlpStoredInfoTypes

cloudasset.assets.listDnsManagedZones

cloudasset.assets.listDnsPolicies

cloudasset.assets.listDomainsRegistrations

cloudasset.assets.listEventarcTriggers

cloudasset.assets.listFileBackups

cloudasset.assets.listFileInstances

cloudasset.assets.listFirebaseAppInfos

cloudasset.assets.listFirebaseProjects

cloudasset.assets.listFirestoreDatabases

cloudasset.assets.listGKEHubFeatures

cloudasset.assets.listGKEHubMemberships

cloudasset.assets.listGameservicesGameServerClusters

cloudasset.assets.listGameservicesGameServerConfigs

cloudasset.assets.listGameservicesGameServerDeployments

cloudasset.assets.listGameservicesRealms

cloudasset.assets.listGkeBackupBackupPlans

cloudasset.assets.listGkeBackupBackups

cloudasset.assets.listGkeBackupRestorePlans

cloudasset.assets.listGkeBackupRestores

cloudasset.assets.listGkeBackupVolumeBackups

cloudasset.assets.listGkeBackupVolumeRestores

cloudasset.assets.listHealthcareConsentStores

cloudasset.assets.listHealthcareDatasets

cloudasset.assets.listHealthcareDicomStores

cloudasset.assets.listHealthcareFhirStores

cloudasset.assets.listHealthcareHl7V2Stores

cloudasset.assets.listIamPolicy

cloudasset.assets.listIamRoles

cloudasset.assets.listIamServiceAccountKeys

cloudasset.assets.listIamServiceAccounts

cloudasset.assets.listIapTunnel

cloudasset.assets.listIapTunnelInstances

cloudasset.assets.listIapTunnelZones

cloudasset.assets.listIapWeb

cloudasset.assets.listIapWebServiceVersion

cloudasset.assets.listIapWebServices

cloudasset.assets.listIapWebType

cloudasset.assets.listIdsEndpoints

cloudasset.assets.listIntegrationsAuthConfigs

cloudasset.assets.listIntegrationsCertificates

cloudasset.assets.listIntegrationsExecutions

cloudasset.assets.listIntegrationsIntegrationVersions

cloudasset.assets.listIntegrationsIntegrations

cloudasset.assets.listIntegrationsSfdcChannels

cloudasset.assets.listIntegrationsSfdcInstances

cloudasset.assets.listIntegrationsSuspensions

cloudasset.assets.listLoggingLogMetrics

cloudasset.assets.listLoggingLogSinks

cloudasset.assets.listManagedidentitiesDomain

cloudasset.assets.listMetastoreBackups

cloudasset.assets.listMetastoreMetadataImports

cloudasset.assets.listMetastoreServices

cloudasset.assets.listMonitoringAlertPolicies

cloudasset.assets.listNetworkConnectivityHubs

cloudasset.assets.listNetworkConnectivitySpokes

cloudasset.assets.listNetworkManagementConnectivityTests

cloudasset.assets.listNetworkServicesEndpointPolicies

cloudasset.assets.listNetworkServicesGateways

cloudasset.assets.listNetworkServicesGrpcRoutes

cloudasset.assets.listNetworkServicesHttpRoutes

cloudasset.assets.listNetworkServicesMeshes

cloudasset.assets.listNetworkServicesServiceBindings

cloudasset.assets.listNetworkServicesTcpRoutes

cloudasset.assets.listNetworkServicesTlsRoutes

cloudasset.assets.listOSConfigOSPolicyAssignmentReports

cloudasset.assets.listOSConfigOSPolicyAssignments

cloudasset.assets.listOSConfigVulnerabilityReports

cloudasset.assets.listOSInventories

cloudasset.assets.listOrgPolicy

cloudasset.assets.listPatchDeployments

cloudasset.assets.listPubsubSnapshots

cloudasset.assets.listPubsubSubscriptions

cloudasset.assets.listPubsubTopics

cloudasset.assets.listRedisInstances

cloudasset.assets.listResource

cloudasset.assets.listRunDomainMapping

cloudasset.assets.listRunRevision

cloudasset.assets.listRunService

cloudasset.assets.listSecretManagerSecretVersions

cloudasset.assets.listSecretManagerSecrets

cloudasset.assets.listServiceDirectoryNamespaces

cloudasset.assets.listServicePerimeter

cloudasset.assets.listServiceconsumermanagementConsumerProperty

cloudasset.assets.listServiceconsumermanagementConsumerQuotaLimits

cloudasset.assets.listServiceconsumermanagementConsumers

cloudasset.assets.listServiceconsumermanagementProducerOverrides

cloudasset.assets.listServiceconsumermanagementTenancyUnits

cloudasset.assets.listServiceconsumermanagementVisibility

cloudasset.assets.listServicemanagementServices

cloudasset.assets.listServiceusageAdminOverrides

cloudasset.assets.listServiceusageConsumerOverrides

cloudasset.assets.listServiceusageServices

cloudasset.assets.listSpannerBackups

cloudasset.assets.listSpannerDatabases

cloudasset.assets.listSpannerInstances

cloudasset.assets.listSpeakerIdPhrases

cloudasset.assets.listSpeakerIdSettings

cloudasset.assets.listSpeakerIdSpeakers

cloudasset.assets.listSpeechCustomClasses

cloudasset.assets.listSpeechPhraseSets

cloudasset.assets.listSqladminBackupRuns

cloudasset.assets.listSqladminInstances

cloudasset.assets.listStorageBuckets

cloudasset.assets.listTpuNodes

cloudasset.assets.listVpcaccessConnector

cloudasset.assets.queryAccessPolicy

cloudasset.assets.queryIamPolicy

cloudasset.assets.queryOSInventories

cloudasset.assets.queryResource

cloudasset.assets.searchAllIamPolicies

cloudasset.assets.searchAllResources

cloudasset.feeds.*

  • cloudasset.feeds.create
  • cloudasset.feeds.delete
  • cloudasset.feeds.get
  • cloudasset.feeds.list
  • cloudasset.feeds.update

cloudasset.othercloudconnections.get

cloudasset.othercloudconnections.list

cloudasset.othercloudconnections.verify

cloudsql.instances.connect

cloudsql.users.list

compute.globalOperations.get

compute.instances.get

compute.instances.list

compute.networkEndpointGroups.get

compute.projects.get

container.clusters.get

monitoring.alertPolicies.list

orgpolicy.policy.get

recommender.cloudAssetInsights.get

recommender.cloudAssetInsights.list

recommender.locations.*

  • recommender.locations.get
  • recommender.locations.list

resourcemanager.projects.get

resourcemanager.projects.list

securitycenter.organizationsettings.get

serviceusage.quotas.get

serviceusage.services.get

serviceusage.services.list

stackdriver.projects.get

(roles/securitycenter.securityResponseServiceAgent)

Gives Playbook Runner permissions to execute all Google authored Playbooks. This role will keep evolving as we add more playbooks

compute.globalOperations.get

compute.instances.deleteAccessConfig

compute.instances.get

compute.instances.setMetadata

compute.regionOperations.get

compute.zoneOperations.get

iam.serviceAccounts.actAs

pubsub.topics.publish

securitycenter.findings.list

storage.buckets.get

storage.buckets.update

(roles/securitycenter.serviceAgent)

Security Center service agent can scan GCP resources and import security scans.

accesscontextmanager.gcpUserAccessBindings.get

accesscontextmanager.gcpUserAccessBindings.list

aiplatform.dataItems.list

aiplatform.datasets.list

bigquery.datasets.get

binaryauthorization.policy.get

cloudasset.assets.analyzeIamPolicy

cloudasset.assets.analyzeMove

cloudasset.assets.analyzeOrgPolicy

cloudasset.assets.exportAccessLevel

cloudasset.assets.exportAccessPolicy

cloudasset.assets.exportAiplatformBatchPredictionJobs

cloudasset.assets.exportAiplatformCustomJobs

cloudasset.assets.exportAiplatformDataLabelingJobs

cloudasset.assets.exportAiplatformDatasets

cloudasset.assets.exportAiplatformEndpoints

cloudasset.assets.exportAiplatformHyperparameterTuningJobs

cloudasset.assets.exportAiplatformMetadataStores

cloudasset.assets.exportAiplatformModelDeploymentMonitoringJobs

cloudasset.assets.exportAiplatformModels

cloudasset.assets.exportAiplatformPipelineJobs

cloudasset.assets.exportAiplatformSpecialistPools

cloudasset.assets.exportAiplatformTrainingPipelines

cloudasset.assets.exportAllAccessPolicy

cloudasset.assets.exportAnthosConnectedCluster

cloudasset.assets.exportAnthosedgeCluster

cloudasset.assets.exportApigatewayApi

cloudasset.assets.exportApigatewayApiConfig

cloudasset.assets.exportApigatewayGateway

cloudasset.assets.exportApikeysKeys

cloudasset.assets.exportAppengineApplications

cloudasset.assets.exportAppengineServices

cloudasset.assets.exportAppengineVersions

cloudasset.assets.exportArtifactregistryDockerImages

cloudasset.assets.exportArtifactregistryRepositories

cloudasset.assets.exportAssuredWorkloadsWorkloads

cloudasset.assets.exportBeyondCorpApiGateways

cloudasset.assets.exportBeyondCorpAppConnections

cloudasset.assets.exportBeyondCorpAppConnectors

cloudasset.assets.exportBeyondCorpAppGateways

cloudasset.assets.exportBeyondCorpClientConnectorServices

cloudasset.assets.exportBeyondCorpClientGateways

cloudasset.assets.exportBigqueryDatasets

cloudasset.assets.exportBigqueryModels

cloudasset.assets.exportBigqueryTables

cloudasset.assets.exportBigtableAppProfile

cloudasset.assets.exportBigtableBackup

cloudasset.assets.exportBigtableCluster

cloudasset.assets.exportBigtableInstance

cloudasset.assets.exportBigtableTable

cloudasset.assets.exportCloudAssetFeeds

cloudasset.assets.exportCloudDeployDeliveryPipelines

cloudasset.assets.exportCloudDeployReleases

cloudasset.assets.exportCloudDeployRollouts

cloudasset.assets.exportCloudDeployTargets

cloudasset.assets.exportCloudDocumentAIEvaluation

cloudasset.assets.exportCloudDocumentAIHumanReviewConfig

cloudasset.assets.exportCloudDocumentAILabelerPool

cloudasset.assets.exportCloudDocumentAIProcessor

cloudasset.assets.exportCloudDocumentAIProcessorVersion

cloudasset.assets.exportCloudbillingBillingAccounts

cloudasset.assets.exportCloudbillingProjectBillingInfos

cloudasset.assets.exportCloudfunctionsFunctions

cloudasset.assets.exportCloudfunctionsGen2Functions

cloudasset.assets.exportCloudkmsCryptoKeyVersions

cloudasset.assets.exportCloudkmsCryptoKeys

cloudasset.assets.exportCloudkmsEkmConnections

cloudasset.assets.exportCloudkmsImportJobs

cloudasset.assets.exportCloudkmsKeyRings

cloudasset.assets.exportCloudmemcacheInstances

cloudasset.assets.exportCloudresourcemanagerFolders

cloudasset.assets.exportCloudresourcemanagerOrganizations

cloudasset.assets.exportCloudresourcemanagerProjects

cloudasset.assets.exportCloudresourcemanagerTagBindings

cloudasset.assets.exportCloudresourcemanagerTagKeys

cloudasset.assets.exportCloudresourcemanagerTagValues

cloudasset.assets.exportComposerEnvironments

cloudasset.assets.exportComputeAddress

cloudasset.assets.exportComputeAutoscalers

cloudasset.assets.exportComputeBackendBuckets

cloudasset.assets.exportComputeBackendServices

cloudasset.assets.exportComputeCommitments

cloudasset.assets.exportComputeDisks

cloudasset.assets.exportComputeExternalVpnGateways

cloudasset.assets.exportComputeFirewallPolicies

cloudasset.assets.exportComputeFirewalls

cloudasset.assets.exportComputeForwardingRules

cloudasset.assets.exportComputeGlobalAddress

cloudasset.assets.exportComputeGlobalForwardingRules

cloudasset.assets.exportComputeHealthChecks

cloudasset.assets.exportComputeHttpHealthChecks

cloudasset.assets.exportComputeHttpsHealthChecks

cloudasset.assets.exportComputeImages

cloudasset.assets.exportComputeInstanceGroupManagers

cloudasset.assets.exportComputeInstanceGroups

cloudasset.assets.exportComputeInstanceTemplates

cloudasset.assets.exportComputeInstances

cloudasset.assets.exportComputeInterconnect

cloudasset.assets.exportComputeInterconnectAttachment

cloudasset.assets.exportComputeLicenses

cloudasset.assets.exportComputeNetworkEndpointGroups

cloudasset.assets.exportComputeNetworks

cloudasset.assets.exportComputeNodeGroups

cloudasset.assets.exportComputeNodeTemplates

cloudasset.assets.exportComputePacketMirrorings

cloudasset.assets.exportComputeProjects

cloudasset.assets.exportComputeRegionAutoscaler

cloudasset.assets.exportComputeRegionBackendServices

cloudasset.assets.exportComputeRegionDisk

cloudasset.assets.exportComputeRegionInstanceGroup

cloudasset.assets.exportComputeRegionInstanceGroupManager

cloudasset.assets.exportComputeReservations

cloudasset.assets.exportComputeResourcePolicies

cloudasset.assets.exportComputeRouters

cloudasset.assets.exportComputeRoutes

cloudasset.assets.exportComputeSecurityPolicy

cloudasset.assets.exportComputeServiceAttachments

cloudasset.assets.exportComputeSnapshots

cloudasset.assets.exportComputeSslCertificates

cloudasset.assets.exportComputeSslPolicies

cloudasset.assets.exportComputeSubnetworks

cloudasset.assets.exportComputeTargetHttpProxies

cloudasset.assets.exportComputeTargetHttpsProxies

cloudasset.assets.exportComputeTargetInstances

cloudasset.assets.exportComputeTargetPools

cloudasset.assets.exportComputeTargetSslProxies

cloudasset.assets.exportComputeTargetTcpProxies

cloudasset.assets.exportComputeTargetVpnGateways

cloudasset.assets.exportComputeUrlMaps

cloudasset.assets.exportComputeVpnGateways

cloudasset.assets.exportComputeVpnTunnels

cloudasset.assets.exportConnectorsConnections

cloudasset.assets.exportConnectorsConnectorVersions

cloudasset.assets.exportConnectorsConnectors

cloudasset.assets.exportConnectorsProviders

cloudasset.assets.exportConnectorsRuntimeConfigs

cloudasset.assets.exportContainerAppsDeployment

cloudasset.assets.exportContainerAppsReplicaSets

cloudasset.assets.exportContainerBatchJobs

cloudasset.assets.exportContainerClusterrole

cloudasset.assets.exportContainerClusterrolebinding

cloudasset.assets.exportContainerClusters

cloudasset.assets.exportContainerExtensionsIngresses

cloudasset.assets.exportContainerJobs

cloudasset.assets.exportContainerNamespace

cloudasset.assets.exportContainerNetworkingIngresses

cloudasset.assets.exportContainerNetworkingNetworkPolicies

cloudasset.assets.exportContainerNode

cloudasset.assets.exportContainerNodepool

cloudasset.assets.exportContainerPod

cloudasset.assets.exportContainerReplicaSets

cloudasset.assets.exportContainerRole

cloudasset.assets.exportContainerRolebinding

cloudasset.assets.exportContainerServices

cloudasset.assets.exportContainerregistryImage

cloudasset.assets.exportDataMigrationConnectionProfiles

cloudasset.assets.exportDataMigrationMigrationJobs

cloudasset.assets.exportDataflowJobs

cloudasset.assets.exportDatafusionInstance

cloudasset.assets.exportDataplexAssets

cloudasset.assets.exportDataplexLakes

cloudasset.assets.exportDataplexTasks

cloudasset.assets.exportDataplexZones

cloudasset.assets.exportDataprocAutoscalingPolicies

cloudasset.assets.exportDataprocBatches

cloudasset.assets.exportDataprocClusters

cloudasset.assets.exportDataprocJobs

cloudasset.assets.exportDataprocSessions

cloudasset.assets.exportDataprocWorkflowTemplates

cloudasset.assets.exportDatastreamConnectionProfile

cloudasset.assets.exportDatastreamPrivateConnection

cloudasset.assets.exportDatastreamStream

cloudasset.assets.exportDialogflowAgents

cloudasset.assets.exportDialogflowConversationProfiles

cloudasset.assets.exportDialogflowKnowledgeBases

cloudasset.assets.exportDialogflowLocationSettings

cloudasset.assets.exportDlpDeidentifyTemplates

cloudasset.assets.exportDlpDlpJobs

cloudasset.assets.exportDlpInspectTemplates

cloudasset.assets.exportDlpJobTriggers

cloudasset.assets.exportDlpStoredInfoTypes

cloudasset.assets.exportDnsManagedZones

cloudasset.assets.exportDnsPolicies

cloudasset.assets.exportDomainsRegistrations

cloudasset.assets.exportEventarcTriggers

cloudasset.assets.exportFileBackups

cloudasset.assets.exportFileInstances

cloudasset.assets.exportFirebaseAppInfos

cloudasset.assets.exportFirebaseProjects

cloudasset.assets.exportFirestoreDatabases

cloudasset.assets.exportGKEHubFeatures

cloudasset.assets.exportGKEHubMemberships

cloudasset.assets.exportGameservicesGameServerClusters

cloudasset.assets.exportGameservicesGameServerConfigs

cloudasset.assets.exportGameservicesGameServerDeployments

cloudasset.assets.exportGameservicesRealms

cloudasset.assets.exportGkeBackupBackupPlans

cloudasset.assets.exportGkeBackupBackups

cloudasset.assets.exportGkeBackupRestorePlans

cloudasset.assets.exportGkeBackupRestores

cloudasset.assets.exportGkeBackupVolumeBackups

cloudasset.assets.exportGkeBackupVolumeRestores

cloudasset.assets.exportHealthcareConsentStores

cloudasset.assets.exportHealthcareDatasets

cloudasset.assets.exportHealthcareDicomStores

cloudasset.assets.exportHealthcareFhirStores

cloudasset.assets.exportHealthcareHl7V2Stores

cloudasset.assets.exportIamPolicy

cloudasset.assets.exportIamRoles

cloudasset.assets.exportIamServiceAccountKeys

cloudasset.assets.exportIamServiceAccounts

cloudasset.assets.exportIapTunnel

cloudasset.assets.exportIapTunnelInstances

cloudasset.assets.exportIapTunnelZones

cloudasset.assets.exportIapWeb

cloudasset.assets.exportIapWebServiceVersion

cloudasset.assets.exportIapWebServices

cloudasset.assets.exportIapWebType

cloudasset.assets.exportIdsEndpoints

cloudasset.assets.exportIntegrationsAuthConfigs

cloudasset.assets.exportIntegrationsCertificates

cloudasset.assets.exportIntegrationsExecutions

cloudasset.assets.exportIntegrationsIntegrationVersions

cloudasset.assets.exportIntegrationsIntegrations

cloudasset.assets.exportIntegrationsSfdcChannels

cloudasset.assets.exportIntegrationsSfdcInstances

cloudasset.assets.exportIntegrationsSuspensions

cloudasset.assets.exportLoggingLogMetrics

cloudasset.assets.exportLoggingLogSinks

cloudasset.assets.exportManagedidentitiesDomain

cloudasset.assets.exportMetastoreBackups

cloudasset.assets.exportMetastoreMetadataImports

cloudasset.assets.exportMetastoreServices

cloudasset.assets.exportMonitoringAlertPolicies

cloudasset.assets.exportNetworkConnectivityHubs

cloudasset.assets.exportNetworkConnectivitySpokes

cloudasset.assets.exportNetworkManagementConnectivityTests

cloudasset.assets.exportNetworkServicesEndpointPolicies

cloudasset.assets.exportNetworkServicesGateways

cloudasset.assets.exportNetworkServicesGrpcRoutes

cloudasset.assets.exportNetworkServicesHttpRoutes

cloudasset.assets.exportNetworkServicesMeshes

cloudasset.assets.exportNetworkServicesServiceBindings

cloudasset.assets.exportNetworkServicesTcpRoutes

cloudasset.assets.exportNetworkServicesTlsRoutes

cloudasset.assets.exportOSConfigOSPolicyAssignmentReports

cloudasset.assets.exportOSConfigOSPolicyAssignments

cloudasset.assets.exportOSConfigVulnerabilityReports

cloudasset.assets.exportOSInventories

cloudasset.assets.exportOrgPolicy

cloudasset.assets.exportPatchDeployments

cloudasset.assets.exportPubsubSnapshots

cloudasset.assets.exportPubsubSubscriptions

cloudasset.assets.exportPubsubTopics

cloudasset.assets.exportRedisInstances

cloudasset.assets.exportResource

cloudasset.assets.exportSecretManagerSecretVersions

cloudasset.assets.exportSecretManagerSecrets

cloudasset.assets.exportServiceDirectoryNamespaces

cloudasset.assets.exportServicePerimeter

cloudasset.assets.exportServiceconsumermanagementConsumerProperty

cloudasset.assets.exportServiceconsumermanagementConsumerQuotaLimits

cloudasset.assets.exportServiceconsumermanagementConsumers

cloudasset.assets.exportServiceconsumermanagementProducerOverrides

cloudasset.assets.exportServiceconsumermanagementTenancyUnits

cloudasset.assets.exportServiceconsumermanagementVisibility

cloudasset.assets.exportServicemanagementServices

cloudasset.assets.exportServiceusageAdminOverrides

cloudasset.assets.exportServiceusageConsumerOverrides

cloudasset.assets.exportServiceusageServices

cloudasset.assets.exportSpannerBackups

cloudasset.assets.exportSpannerDatabases

cloudasset.assets.exportSpannerInstances

cloudasset.assets.exportSpeakerIdPhrases

cloudasset.assets.exportSpeakerIdSettings

cloudasset.assets.exportSpeakerIdSpeakers

cloudasset.assets.exportSpeechCustomClasses

cloudasset.assets.exportSpeechPhraseSets

cloudasset.assets.exportSqladminBackupRuns

cloudasset.assets.exportSqladminInstances

cloudasset.assets.exportStorageBuckets

cloudasset.assets.exportTpuNodes

cloudasset.assets.exportVpcaccessConnector

cloudasset.assets.listAccessLevel

cloudasset.assets.listAccessPolicy

cloudasset.assets.listAiplatformBatchPredictionJobs

cloudasset.assets.listAiplatformCustomJobs

cloudasset.assets.listAiplatformDataLabelingJobs

cloudasset.assets.listAiplatformDatasets

cloudasset.assets.listAiplatformEndpoints

cloudasset.assets.listAiplatformHyperparameterTuningJobs

cloudasset.assets.listAiplatformMetadataStores

cloudasset.assets.listAiplatformModelDeploymentMonitoringJobs

cloudasset.assets.listAiplatformModels

cloudasset.assets.listAiplatformPipelineJobs

cloudasset.assets.listAiplatformSpecialistPools

cloudasset.assets.listAiplatformTrainingPipelines

cloudasset.assets.listAllAccessPolicy

cloudasset.assets.listAnthosConnectedCluster

cloudasset.assets.listAnthosedgeCluster

cloudasset.assets.listApigatewayApi

cloudasset.assets.listApigatewayApiConfig

cloudasset.assets.listApigatewayGateway

cloudasset.assets.listApikeysKeys

cloudasset.assets.listAppengineApplications

cloudasset.assets.listAppengineServices

cloudasset.assets.listAppengineVersions

cloudasset.assets.listArtifactregistryDockerImages

cloudasset.assets.listArtifactregistryRepositories

cloudasset.assets.listAssuredWorkloadsWorkloads

cloudasset.assets.listBeyondCorpApiGateways

cloudasset.assets.listBeyondCorpAppConnections

cloudasset.assets.listBeyondCorpAppConnectors

cloudasset.assets.listBeyondCorpAppGateways

cloudasset.assets.listBeyondCorpClientConnectorServices

cloudasset.assets.listBeyondCorpClientGateways

cloudasset.assets.listBigqueryDatasets

cloudasset.assets.listBigqueryModels

cloudasset.assets.listBigqueryTables

cloudasset.assets.listBigtableAppProfile

cloudasset.assets.listBigtableBackup

cloudasset.assets.listBigtableCluster

cloudasset.assets.listBigtableInstance

cloudasset.assets.listBigtableTable

cloudasset.assets.listCloudAssetFeeds

cloudasset.assets.listCloudDeployDeliveryPipelines

cloudasset.assets.listCloudDeployReleases

cloudasset.assets.listCloudDeployRollouts

cloudasset.assets.listCloudDeployTargets

cloudasset.assets.listCloudDocumentAIEvaluation

cloudasset.assets.listCloudDocumentAIHumanReviewConfig

cloudasset.assets.listCloudDocumentAILabelerPool

cloudasset.assets.listCloudDocumentAIProcessor

cloudasset.assets.listCloudDocumentAIProcessorVersion

cloudasset.assets.listCloudbillingBillingAccounts

cloudasset.assets.listCloudbillingProjectBillingInfos

cloudasset.assets.listCloudfunctionsFunctions

cloudasset.assets.listCloudfunctionsGen2Functions

cloudasset.assets.listCloudkmsCryptoKeyVersions

cloudasset.assets.listCloudkmsCryptoKeys

cloudasset.assets.listCloudkmsEkmConnections

cloudasset.assets.listCloudkmsImportJobs

cloudasset.assets.listCloudkmsKeyRings

cloudasset.assets.listCloudmemcacheInstances

cloudasset.assets.listCloudresourcemanagerFolders

cloudasset.assets.listCloudresourcemanagerOrganizations

cloudasset.assets.listCloudresourcemanagerProjects

cloudasset.assets.listCloudresourcemanagerTagBindings

cloudasset.assets.listCloudresourcemanagerTagKeys

cloudasset.assets.listCloudresourcemanagerTagValues

cloudasset.assets.listComposerEnvironments

cloudasset.assets.listComputeAddress

cloudasset.assets.listComputeAutoscalers

cloudasset.assets.listComputeBackendBuckets

cloudasset.assets.listComputeBackendServices

cloudasset.assets.listComputeCommitments

cloudasset.assets.listComputeDisks

cloudasset.assets.listComputeExternalVpnGateways

cloudasset.assets.listComputeFirewallPolicies

cloudasset.assets.listComputeFirewalls

cloudasset.assets.listComputeForwardingRules

cloudasset.assets.listComputeGlobalAddress

cloudasset.assets.listComputeGlobalForwardingRules

cloudasset.assets.listComputeHealthChecks

cloudasset.assets.listComputeHttpHealthChecks

cloudasset.assets.listComputeHttpsHealthChecks

cloudasset.assets.listComputeImages

cloudasset.assets.listComputeInstanceGroupManagers

cloudasset.assets.listComputeInstanceGroups

cloudasset.assets.listComputeInstanceTemplates

cloudasset.assets.listComputeInstances

cloudasset.assets.listComputeInterconnect

cloudasset.assets.listComputeInterconnectAttachment

cloudasset.assets.listComputeLicenses

cloudasset.assets.listComputeNetworkEndpointGroups

cloudasset.assets.listComputeNetworks

cloudasset.assets.listComputeNodeGroups

cloudasset.assets.listComputeNodeTemplates

cloudasset.assets.listComputePacketMirrorings

cloudasset.assets.listComputeProjects

cloudasset.assets.listComputeRegionAutoscaler

cloudasset.assets.listComputeRegionBackendServices

cloudasset.assets.listComputeRegionDisk

cloudasset.assets.listComputeRegionInstanceGroup

cloudasset.assets.listComputeRegionInstanceGroupManager

cloudasset.assets.listComputeReservations

cloudasset.assets.listComputeResourcePolicies

cloudasset.assets.listComputeRouters

cloudasset.assets.listComputeRoutes

cloudasset.assets.listComputeSecurityPolicy

cloudasset.assets.listComputeServiceAttachments

cloudasset.assets.listComputeSnapshots

cloudasset.assets.listComputeSslCertificates

cloudasset.assets.listComputeSslPolicies

cloudasset.assets.listComputeSubnetworks

cloudasset.assets.listComputeTargetHttpProxies

cloudasset.assets.listComputeTargetHttpsProxies

cloudasset.assets.listComputeTargetInstances

cloudasset.assets.listComputeTargetPools

cloudasset.assets.listComputeTargetSslProxies

cloudasset.assets.listComputeTargetTcpProxies

cloudasset.assets.listComputeTargetVpnGateways

cloudasset.assets.listComputeUrlMaps

cloudasset.assets.listComputeVpnGateways

cloudasset.assets.listComputeVpnTunnels

cloudasset.assets.listConnectorsConnections

cloudasset.assets.listConnectorsConnectorVersions

cloudasset.assets.listConnectorsConnectors

cloudasset.assets.listConnectorsProviders

cloudasset.assets.listConnectorsRuntimeConfigs

cloudasset.assets.listContainerAppsDeployment

cloudasset.assets.listContainerAppsReplicaSets

cloudasset.assets.listContainerBatchJobs

cloudasset.assets.listContainerClusterrole

cloudasset.assets.listContainerClusterrolebinding

cloudasset.assets.listContainerClusters

cloudasset.assets.listContainerExtensionsIngresses

cloudasset.assets.listContainerJobs

cloudasset.assets.listContainerNamespace

cloudasset.assets.listContainerNetworkingIngresses

cloudasset.assets.listContainerNetworkingNetworkPolicies

cloudasset.assets.listContainerNode

cloudasset.assets.listContainerNodepool

cloudasset.assets.listContainerPod

cloudasset.assets.listContainerReplicaSets

cloudasset.assets.listContainerRole

cloudasset.assets.listContainerRolebinding

cloudasset.assets.listContainerServices

cloudasset.assets.listContainerregistryImage

cloudasset.assets.listDataMigrationConnectionProfiles

cloudasset.assets.listDataMigrationMigrationJobs

cloudasset.assets.listDataflowJobs

cloudasset.assets.listDatafusionInstance

cloudasset.assets.listDataplexAssets

cloudasset.assets.listDataplexLakes

cloudasset.assets.listDataplexTasks

cloudasset.assets.listDataplexZones

cloudasset.assets.listDataprocAutoscalingPolicies

cloudasset.assets.listDataprocBatches

cloudasset.assets.listDataprocClusters

cloudasset.assets.listDataprocJobs

cloudasset.assets.listDataprocSessions

cloudasset.assets.listDataprocWorkflowTemplates

cloudasset.assets.listDatastreamConnectionProfile

cloudasset.assets.listDatastreamPrivateConnection

cloudasset.assets.listDatastreamStream

cloudasset.assets.listDialogflowAgents

cloudasset.assets.listDialogflowConversationProfiles

cloudasset.assets.listDialogflowKnowledgeBases

cloudasset.assets.listDialogflowLocationSettings

cloudasset.assets.listDlpDeidentifyTemplates

cloudasset.assets.listDlpDlpJobs

cloudasset.assets.listDlpInspectTemplates

cloudasset.assets.listDlpJobTriggers

cloudasset.assets.listDlpStoredInfoTypes

cloudasset.assets.listDnsManagedZones

cloudasset.assets.listDnsPolicies

cloudasset.assets.listDomainsRegistrations

cloudasset.assets.listEventarcTriggers

cloudasset.assets.listFileBackups

cloudasset.assets.listFileInstances

cloudasset.assets.listFirebaseAppInfos

cloudasset.assets.listFirebaseProjects

cloudasset.assets.listFirestoreDatabases

cloudasset.assets.listGKEHubFeatures

cloudasset.assets.listGKEHubMemberships

cloudasset.assets.listGameservicesGameServerClusters

cloudasset.assets.listGameservicesGameServerConfigs

cloudasset.assets.listGameservicesGameServerDeployments

cloudasset.assets.listGameservicesRealms

cloudasset.assets.listGkeBackupBackupPlans

cloudasset.assets.listGkeBackupBackups

cloudasset.assets.listGkeBackupRestorePlans

cloudasset.assets.listGkeBackupRestores

cloudasset.assets.listGkeBackupVolumeBackups

cloudasset.assets.listGkeBackupVolumeRestores

cloudasset.assets.listHealthcareConsentStores

cloudasset.assets.listHealthcareDatasets

cloudasset.assets.listHealthcareDicomStores

cloudasset.assets.listHealthcareFhirStores

cloudasset.assets.listHealthcareHl7V2Stores

cloudasset.assets.listIamPolicy

cloudasset.assets.listIamRoles

cloudasset.assets.listIamServiceAccountKeys

cloudasset.assets.listIamServiceAccounts

cloudasset.assets.listIapTunnel

cloudasset.assets.listIapTunnelInstances

cloudasset.assets.listIapTunnelZones

cloudasset.assets.listIapWeb

cloudasset.assets.listIapWebServiceVersion

cloudasset.assets.listIapWebServices

cloudasset.assets.listIapWebType

cloudasset.assets.listIdsEndpoints

cloudasset.assets.listIntegrationsAuthConfigs

cloudasset.assets.listIntegrationsCertificates

cloudasset.assets.listIntegrationsExecutions

cloudasset.assets.listIntegrationsIntegrationVersions

cloudasset.assets.listIntegrationsIntegrations

cloudasset.assets.listIntegrationsSfdcChannels

cloudasset.assets.listIntegrationsSfdcInstances

cloudasset.assets.listIntegrationsSuspensions

cloudasset.assets.listLoggingLogMetrics

cloudasset.assets.listLoggingLogSinks

cloudasset.assets.listManagedidentitiesDomain

cloudasset.assets.listMetastoreBackups

cloudasset.assets.listMetastoreMetadataImports

cloudasset.assets.listMetastoreServices

cloudasset.assets.listMonitoringAlertPolicies

cloudasset.assets.listNetworkConnectivityHubs

cloudasset.assets.listNetworkConnectivitySpokes

cloudasset.assets.listNetworkManagementConnectivityTests

cloudasset.assets.listNetworkServicesEndpointPolicies

cloudasset.assets.listNetworkServicesGateways

cloudasset.assets.listNetworkServicesGrpcRoutes

cloudasset.assets.listNetworkServicesHttpRoutes

cloudasset.assets.listNetworkServicesMeshes

cloudasset.assets.listNetworkServicesServiceBindings

cloudasset.assets.listNetworkServicesTcpRoutes

cloudasset.assets.listNetworkServicesTlsRoutes

cloudasset.assets.listOSConfigOSPolicyAssignmentReports

cloudasset.assets.listOSConfigOSPolicyAssignments

cloudasset.assets.listOSConfigVulnerabilityReports

cloudasset.assets.listOSInventories

cloudasset.assets.listOrgPolicy

cloudasset.assets.listPatchDeployments

cloudasset.assets.listPubsubSnapshots

cloudasset.assets.listPubsubSubscriptions

cloudasset.assets.listPubsubTopics

cloudasset.assets.listRedisInstances

cloudasset.assets.listResource

cloudasset.assets.listRunDomainMapping

cloudasset.assets.listRunRevision

cloudasset.assets.listRunService

cloudasset.assets.listSecretManagerSecretVersions

cloudasset.assets.listSecretManagerSecrets

cloudasset.assets.listServiceDirectoryNamespaces

cloudasset.assets.listServicePerimeter

cloudasset.assets.listServiceconsumermanagementConsumerProperty

cloudasset.assets.listServiceconsumermanagementConsumerQuotaLimits

cloudasset.assets.listServiceconsumermanagementConsumers

cloudasset.assets.listServiceconsumermanagementProducerOverrides

cloudasset.assets.listServiceconsumermanagementTenancyUnits

cloudasset.assets.listServiceconsumermanagementVisibility

cloudasset.assets.listServicemanagementServices

cloudasset.assets.listServiceusageAdminOverrides

cloudasset.assets.listServiceusageConsumerOverrides

cloudasset.assets.listServiceusageServices

cloudasset.assets.listSpannerBackups

cloudasset.assets.listSpannerDatabases

cloudasset.assets.listSpannerInstances

cloudasset.assets.listSpeakerIdPhrases

cloudasset.assets.listSpeakerIdSettings

cloudasset.assets.listSpeakerIdSpeakers

cloudasset.assets.listSpeechCustomClasses

cloudasset.assets.listSpeechPhraseSets

cloudasset.assets.listSqladminBackupRuns

cloudasset.assets.listSqladminInstances

cloudasset.assets.listStorageBuckets

cloudasset.assets.listTpuNodes

cloudasset.assets.listVpcaccessConnector

cloudasset.assets.queryAccessPolicy

cloudasset.assets.queryIamPolicy

cloudasset.assets.queryOSInventories

cloudasset.assets.queryResource

cloudasset.assets.searchAllIamPolicies

cloudasset.assets.searchAllResources

cloudasset.feeds.*

  • cloudasset.feeds.create
  • cloudasset.feeds.delete
  • cloudasset.feeds.get
  • cloudasset.feeds.list
  • cloudasset.feeds.update

cloudasset.othercloudconnections.get

cloudasset.othercloudconnections.list

cloudasset.othercloudconnections.verify

cloudsql.instances.connect

cloudsql.users.list

compute.disks.useReadOnly

compute.globalOperations.get

compute.instances.get

compute.instances.list

compute.networkEndpointGroups.get

compute.projects.get

compute.regionOperations.get

compute.zoneOperations.get

container.clusters.get

iam.denypolicies.get

iam.denypolicies.list

iam.googleapis.com/workloadIdentityPoolProviders.list

iam.googleapis.com/workloadIdentityPools.list

logging.logEntries.list

monitoring.alertPolicies.list

monitoring.timeSeries.list

orgpolicy.policies.list

orgpolicy.policy.get

recommender.cloudAssetInsights.get

recommender.cloudAssetInsights.list

recommender.locations.*

  • recommender.locations.get
  • recommender.locations.list

resourcemanager.folders.get

resourcemanager.folders.list

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.getIamPolicy

resourcemanager.projects.list

resourcemanager.tagValues.get

securitycenter.assets.list

securitycenter.assetsecuritymarks.update

securitycenter.findings.list

securitycenter.notificationconfig.create

securitycenter.notificationconfig.delete

securitycenter.notificationconfig.update

securitycenter.organizationsettings.get

securitycenter.resourcevalueconfigs.get

securitycenter.resourcevalueconfigs.list

securitycenter.simulations.get

securitycenter.sources.list

securitycenter.valuedresources.list

securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.*

  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.get
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.list

securitycentermanagement.securityHealthAnalyticsCustomModules.create

securitycentermanagement.securityHealthAnalyticsCustomModules.delete

securitycentermanagement.securityHealthAnalyticsCustomModules.get

securitycentermanagement.securityHealthAnalyticsCustomModules.list

securitycentermanagement.securityHealthAnalyticsCustomModules.simulate

securitycentermanagement.securityHealthAnalyticsCustomModules.update

serviceusage.quotas.get

serviceusage.services.disable

serviceusage.services.enable

serviceusage.services.get

serviceusage.services.list

stackdriver.projects.get

storage.buckets.get

storage.buckets.getIamPolicy

storage.buckets.list

(roles/securitycenter.settingsAdmin)

Admin(super user) access to security center settings

Lowest-level resources where you can grant this role:

  • Project

resourcemanager.folders.get

resourcemanager.folders.list

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.list

securitycenter.bigQueryExports.*

  • securitycenter.bigQueryExports.create
  • securitycenter.bigQueryExports.delete
  • securitycenter.bigQueryExports.get
  • securitycenter.bigQueryExports.list
  • securitycenter.bigQueryExports.update

securitycenter.billingtier.update

securitycenter.containerthreatdetectionsettings.*

  • securitycenter.containerthreatdetectionsettings.calculate
  • securitycenter.containerthreatdetectionsettings.get
  • securitycenter.containerthreatdetectionsettings.update

securitycenter.effectivesecurityhealthanalyticscustommodules.*

  • securitycenter.effectivesecurityhealthanalyticscustommodules.get
  • securitycenter.effectivesecurityhealthanalyticscustommodules.list

securitycenter.eventthreatdetectionsettings.*

  • securitycenter.eventthreatdetectionsettings.calculate
  • securitycenter.eventthreatdetectionsettings.get
  • securitycenter.eventthreatdetectionsettings.update

securitycenter.integratedvulnerabilityscannersettings.*

  • securitycenter.integratedvulnerabilityscannersettings.calculate
  • securitycenter.integratedvulnerabilityscannersettings.get
  • securitycenter.integratedvulnerabilityscannersettings.update

securitycenter.muteconfigs.*

  • securitycenter.muteconfigs.create
  • securitycenter.muteconfigs.delete
  • securitycenter.muteconfigs.get
  • securitycenter.muteconfigs.list
  • securitycenter.muteconfigs.update

securitycenter.notificationconfig.*

  • securitycenter.notificationconfig.create
  • securitycenter.notificationconfig.delete
  • securitycenter.notificationconfig.get
  • securitycenter.notificationconfig.list
  • securitycenter.notificationconfig.update

securitycenter.organizationsettings.*

  • securitycenter.organizationsettings.get
  • securitycenter.organizationsettings.update

securitycenter.rapidvulnerabilitydetectionsettings.*

  • securitycenter.rapidvulnerabilitydetectionsettings.calculate
  • securitycenter.rapidvulnerabilitydetectionsettings.get
  • securitycenter.rapidvulnerabilitydetectionsettings.update

securitycenter.securitycentersettings.*

  • securitycenter.securitycentersettings.get
  • securitycenter.securitycentersettings.update

securitycenter.securityhealthanalyticscustommodules.create

securitycenter.securityhealthanalyticscustommodules.delete

securitycenter.securityhealthanalyticscustommodules.get

securitycenter.securityhealthanalyticscustommodules.list

securitycenter.securityhealthanalyticscustommodules.update

securitycenter.securityhealthanalyticssettings.*

  • securitycenter.securityhealthanalyticssettings.calculate
  • securitycenter.securityhealthanalyticssettings.get
  • securitycenter.securityhealthanalyticssettings.update

securitycenter.subscription.get

securitycenter.userinterfacemetadata.get

securitycenter.virtualmachinethreatdetectionsettings.*

  • securitycenter.virtualmachinethreatdetectionsettings.calculate
  • securitycenter.virtualmachinethreatdetectionsettings.get
  • securitycenter.virtualmachinethreatdetectionsettings.update

securitycenter.websecurityscannersettings.*

  • securitycenter.websecurityscannersettings.calculate
  • securitycenter.websecurityscannersettings.get
  • securitycenter.websecurityscannersettings.update

securitycentermanagement.*

  • securitycentermanagement.billingMetadata.get
  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.get
  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.list
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.get
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.list
  • securitycentermanagement.eventThreatDetectionCustomModules.create
  • securitycentermanagement.eventThreatDetectionCustomModules.delete
  • securitycentermanagement.eventThreatDetectionCustomModules.get
  • securitycentermanagement.eventThreatDetectionCustomModules.list
  • securitycentermanagement.eventThreatDetectionCustomModules.update
  • securitycentermanagement.eventThreatDetectionCustomModules.validate
  • securitycentermanagement.locations.get
  • securitycentermanagement.locations.list
  • securitycentermanagement.securityCenterServices.get
  • securitycentermanagement.securityCenterServices.list
  • securitycentermanagement.securityCenterServices.update
  • securitycentermanagement.securityCommandCenter.activate
  • securitycentermanagement.securityCommandCenter.checkActivationOperation
  • securitycentermanagement.securityCommandCenter.checkEligibility
  • securitycentermanagement.securityCommandCenter.checkOnboardingStatus
  • securitycentermanagement.securityCommandCenter.generateServiceAccounts
  • securitycentermanagement.securityCommandCenter.get
  • securitycentermanagement.securityCommandCenter.update
  • securitycentermanagement.securityHealthAnalyticsCustomModules.create
  • securitycentermanagement.securityHealthAnalyticsCustomModules.delete
  • securitycentermanagement.securityHealthAnalyticsCustomModules.get
  • securitycentermanagement.securityHealthAnalyticsCustomModules.list
  • securitycentermanagement.securityHealthAnalyticsCustomModules.simulate
  • securitycentermanagement.securityHealthAnalyticsCustomModules.test
  • securitycentermanagement.securityHealthAnalyticsCustomModules.update

(roles/securitycenter.settingsEditor)

Read-Write access to security center settings

Lowest-level resources where you can grant this role:

  • Project

resourcemanager.folders.get

resourcemanager.folders.list

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.list

securitycenter.bigQueryExports.*

  • securitycenter.bigQueryExports.create
  • securitycenter.bigQueryExports.delete
  • securitycenter.bigQueryExports.get
  • securitycenter.bigQueryExports.list
  • securitycenter.bigQueryExports.update

securitycenter.billingtier.update

securitycenter.containerthreatdetectionsettings.*

  • securitycenter.containerthreatdetectionsettings.calculate
  • securitycenter.containerthreatdetectionsettings.get
  • securitycenter.containerthreatdetectionsettings.update

securitycenter.effectivesecurityhealthanalyticscustommodules.*

  • securitycenter.effectivesecurityhealthanalyticscustommodules.get
  • securitycenter.effectivesecurityhealthanalyticscustommodules.list

securitycenter.eventthreatdetectionsettings.*

  • securitycenter.eventthreatdetectionsettings.calculate
  • securitycenter.eventthreatdetectionsettings.get
  • securitycenter.eventthreatdetectionsettings.update

securitycenter.integratedvulnerabilityscannersettings.*

  • securitycenter.integratedvulnerabilityscannersettings.calculate
  • securitycenter.integratedvulnerabilityscannersettings.get
  • securitycenter.integratedvulnerabilityscannersettings.update

securitycenter.muteconfigs.*

  • securitycenter.muteconfigs.create
  • securitycenter.muteconfigs.delete
  • securitycenter.muteconfigs.get
  • securitycenter.muteconfigs.list
  • securitycenter.muteconfigs.update

securitycenter.notificationconfig.*

  • securitycenter.notificationconfig.create
  • securitycenter.notificationconfig.delete
  • securitycenter.notificationconfig.get
  • securitycenter.notificationconfig.list
  • securitycenter.notificationconfig.update

securitycenter.organizationsettings.*

  • securitycenter.organizationsettings.get
  • securitycenter.organizationsettings.update

securitycenter.rapidvulnerabilitydetectionsettings.*

  • securitycenter.rapidvulnerabilitydetectionsettings.calculate
  • securitycenter.rapidvulnerabilitydetectionsettings.get
  • securitycenter.rapidvulnerabilitydetectionsettings.update

securitycenter.securitycentersettings.*

  • securitycenter.securitycentersettings.get
  • securitycenter.securitycentersettings.update

securitycenter.securityhealthanalyticscustommodules.create

securitycenter.securityhealthanalyticscustommodules.delete

securitycenter.securityhealthanalyticscustommodules.get

securitycenter.securityhealthanalyticscustommodules.list

securitycenter.securityhealthanalyticscustommodules.update

securitycenter.securityhealthanalyticssettings.*

  • securitycenter.securityhealthanalyticssettings.calculate
  • securitycenter.securityhealthanalyticssettings.get
  • securitycenter.securityhealthanalyticssettings.update

securitycenter.subscription.get

securitycenter.userinterfacemetadata.get

securitycenter.virtualmachinethreatdetectionsettings.*

  • securitycenter.virtualmachinethreatdetectionsettings.calculate
  • securitycenter.virtualmachinethreatdetectionsettings.get
  • securitycenter.virtualmachinethreatdetectionsettings.update

securitycenter.websecurityscannersettings.*

  • securitycenter.websecurityscannersettings.calculate
  • securitycenter.websecurityscannersettings.get
  • securitycenter.websecurityscannersettings.update

securitycentermanagement.*

  • securitycentermanagement.billingMetadata.get
  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.get
  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.list
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.get
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.list
  • securitycentermanagement.eventThreatDetectionCustomModules.create
  • securitycentermanagement.eventThreatDetectionCustomModules.delete
  • securitycentermanagement.eventThreatDetectionCustomModules.get
  • securitycentermanagement.eventThreatDetectionCustomModules.list
  • securitycentermanagement.eventThreatDetectionCustomModules.update
  • securitycentermanagement.eventThreatDetectionCustomModules.validate
  • securitycentermanagement.locations.get
  • securitycentermanagement.locations.list
  • securitycentermanagement.securityCenterServices.get
  • securitycentermanagement.securityCenterServices.list
  • securitycentermanagement.securityCenterServices.update
  • securitycentermanagement.securityCommandCenter.activate
  • securitycentermanagement.securityCommandCenter.checkActivationOperation
  • securitycentermanagement.securityCommandCenter.checkEligibility
  • securitycentermanagement.securityCommandCenter.checkOnboardingStatus
  • securitycentermanagement.securityCommandCenter.generateServiceAccounts
  • securitycentermanagement.securityCommandCenter.get
  • securitycentermanagement.securityCommandCenter.update
  • securitycentermanagement.securityHealthAnalyticsCustomModules.create
  • securitycentermanagement.securityHealthAnalyticsCustomModules.delete
  • securitycentermanagement.securityHealthAnalyticsCustomModules.get
  • securitycentermanagement.securityHealthAnalyticsCustomModules.list
  • securitycentermanagement.securityHealthAnalyticsCustomModules.simulate
  • securitycentermanagement.securityHealthAnalyticsCustomModules.test
  • securitycentermanagement.securityHealthAnalyticsCustomModules.update

(roles/securitycenter.settingsViewer)

Read access to security center settings

Lowest-level resources where you can grant this role:

  • Project

resourcemanager.folders.get

resourcemanager.folders.list

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.list

securitycenter.bigQueryExports.get

securitycenter.bigQueryExports.list

securitycenter.containerthreatdetectionsettings.calculate

securitycenter.containerthreatdetectionsettings.get

securitycenter.effectivesecurityhealthanalyticscustommodules.*

  • securitycenter.effectivesecurityhealthanalyticscustommodules.get
  • securitycenter.effectivesecurityhealthanalyticscustommodules.list

securitycenter.eventthreatdetectionsettings.calculate

securitycenter.eventthreatdetectionsettings.get

securitycenter.integratedvulnerabilityscannersettings.calculate

securitycenter.integratedvulnerabilityscannersettings.get

securitycenter.muteconfigs.get

securitycenter.muteconfigs.list

securitycenter.notificationconfig.get

securitycenter.notificationconfig.list

securitycenter.organizationsettings.get

securitycenter.rapidvulnerabilitydetectionsettings.calculate

securitycenter.rapidvulnerabilitydetectionsettings.get

securitycenter.securitycentersettings.get

securitycenter.securityhealthanalyticscustommodules.get

securitycenter.securityhealthanalyticscustommodules.list

securitycenter.securityhealthanalyticssettings.calculate

securitycenter.securityhealthanalyticssettings.get

securitycenter.subscription.get

securitycenter.userinterfacemetadata.get

securitycenter.virtualmachinethreatdetectionsettings.calculate

securitycenter.virtualmachinethreatdetectionsettings.get

securitycenter.websecurityscannersettings.calculate

securitycenter.websecurityscannersettings.get

securitycentermanagement.billingMetadata.get

securitycentermanagement.effectiveEventThreatDetectionCustomModules.*

  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.get
  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.list

securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.*

  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.get
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.list

securitycentermanagement.eventThreatDetectionCustomModules.get

securitycentermanagement.eventThreatDetectionCustomModules.list

securitycentermanagement.eventThreatDetectionCustomModules.validate

securitycentermanagement.locations.*

  • securitycentermanagement.locations.get
  • securitycentermanagement.locations.list

securitycentermanagement.securityCenterServices.get

securitycentermanagement.securityCenterServices.list

securitycentermanagement.securityCommandCenter.checkActivationOperation

securitycentermanagement.securityCommandCenter.checkOnboardingStatus

securitycentermanagement.securityCommandCenter.get

securitycentermanagement.securityHealthAnalyticsCustomModules.get

securitycentermanagement.securityHealthAnalyticsCustomModules.list

securitycentermanagement.securityHealthAnalyticsCustomModules.simulate

securitycentermanagement.securityHealthAnalyticsCustomModules.test

(roles/securitycenter.simulationsViewer)

Read access to security center simulations

securitycenter.simulations.get

(roles/securitycenter.sourcesAdmin)

Admin access to sources

Lowest-level resources where you can grant this role:

  • Organization

resourcemanager.organizations.get

securitycenter.sources.*

  • securitycenter.sources.get
  • securitycenter.sources.getIamPolicy
  • securitycenter.sources.list
  • securitycenter.sources.setIamPolicy
  • securitycenter.sources.update

securitycenter.userinterfacemetadata.get

(roles/securitycenter.sourcesEditor)

Read-write access to sources

Lowest-level resources where you can grant this role:

  • Organization

resourcemanager.organizations.get

securitycenter.sources.get

securitycenter.sources.list

securitycenter.sources.update

securitycenter.userinterfacemetadata.get

(roles/securitycenter.sourcesViewer)

Read access to sources

Lowest-level resources where you can grant this role:

  • Project

resourcemanager.organizations.get

securitycenter.sources.get

securitycenter.sources.list

securitycenter.userinterfacemetadata.get

(roles/securitycenter.valuedResourcesViewer)

Read access to security center valued resources

securitycenter.valuedresources.list

Rôles de l'API Security Command Center Management

Les rôles IAM suivants sont disponibles pour l'API Security Command Center Management. Vous pouvez attribuer ces rôles au niveau de l'organisation, d'un dossier ou d'un projet.

Role Permissions

(roles/securitycentermanagement.admin)

Full access to manage Cloud Security Command Center services and custom modules configuration.

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.list

securitycenter.organizationsettings.*

  • securitycenter.organizationsettings.get
  • securitycenter.organizationsettings.update

securitycenter.securitycentersettings.*

  • securitycenter.securitycentersettings.get
  • securitycenter.securitycentersettings.update

securitycentermanagement.*

  • securitycentermanagement.billingMetadata.get
  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.get
  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.list
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.get
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.list
  • securitycentermanagement.eventThreatDetectionCustomModules.create
  • securitycentermanagement.eventThreatDetectionCustomModules.delete
  • securitycentermanagement.eventThreatDetectionCustomModules.get
  • securitycentermanagement.eventThreatDetectionCustomModules.list
  • securitycentermanagement.eventThreatDetectionCustomModules.update
  • securitycentermanagement.eventThreatDetectionCustomModules.validate
  • securitycentermanagement.locations.get
  • securitycentermanagement.locations.list
  • securitycentermanagement.securityCenterServices.get
  • securitycentermanagement.securityCenterServices.list
  • securitycentermanagement.securityCenterServices.update
  • securitycentermanagement.securityCommandCenter.activate
  • securitycentermanagement.securityCommandCenter.checkActivationOperation
  • securitycentermanagement.securityCommandCenter.checkEligibility
  • securitycentermanagement.securityCommandCenter.checkOnboardingStatus
  • securitycentermanagement.securityCommandCenter.generateServiceAccounts
  • securitycentermanagement.securityCommandCenter.get
  • securitycentermanagement.securityCommandCenter.update
  • securitycentermanagement.securityHealthAnalyticsCustomModules.create
  • securitycentermanagement.securityHealthAnalyticsCustomModules.delete
  • securitycentermanagement.securityHealthAnalyticsCustomModules.get
  • securitycentermanagement.securityHealthAnalyticsCustomModules.list
  • securitycentermanagement.securityHealthAnalyticsCustomModules.simulate
  • securitycentermanagement.securityHealthAnalyticsCustomModules.test
  • securitycentermanagement.securityHealthAnalyticsCustomModules.update

(roles/securitycentermanagement.customModulesEditor)

Full access to manage Cloud Security Command Center custom modules.

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.list

securitycentermanagement.effectiveEventThreatDetectionCustomModules.*

  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.get
  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.list

securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.*

  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.get
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.list

securitycentermanagement.eventThreatDetectionCustomModules.*

  • securitycentermanagement.eventThreatDetectionCustomModules.create
  • securitycentermanagement.eventThreatDetectionCustomModules.delete
  • securitycentermanagement.eventThreatDetectionCustomModules.get
  • securitycentermanagement.eventThreatDetectionCustomModules.list
  • securitycentermanagement.eventThreatDetectionCustomModules.update
  • securitycentermanagement.eventThreatDetectionCustomModules.validate

securitycentermanagement.locations.*

  • securitycentermanagement.locations.get
  • securitycentermanagement.locations.list

securitycentermanagement.securityHealthAnalyticsCustomModules.*

  • securitycentermanagement.securityHealthAnalyticsCustomModules.create
  • securitycentermanagement.securityHealthAnalyticsCustomModules.delete
  • securitycentermanagement.securityHealthAnalyticsCustomModules.get
  • securitycentermanagement.securityHealthAnalyticsCustomModules.list
  • securitycentermanagement.securityHealthAnalyticsCustomModules.simulate
  • securitycentermanagement.securityHealthAnalyticsCustomModules.test
  • securitycentermanagement.securityHealthAnalyticsCustomModules.update

(roles/securitycentermanagement.customModulesViewer)

Readonly access to Cloud Security Command Center custom modules.

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.list

securitycentermanagement.effectiveEventThreatDetectionCustomModules.*

  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.get
  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.list

securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.*

  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.get
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.list

securitycentermanagement.eventThreatDetectionCustomModules.get

securitycentermanagement.eventThreatDetectionCustomModules.list

securitycentermanagement.eventThreatDetectionCustomModules.validate

securitycentermanagement.locations.*

  • securitycentermanagement.locations.get
  • securitycentermanagement.locations.list

securitycentermanagement.securityHealthAnalyticsCustomModules.get

securitycentermanagement.securityHealthAnalyticsCustomModules.list

securitycentermanagement.securityHealthAnalyticsCustomModules.simulate

securitycentermanagement.securityHealthAnalyticsCustomModules.test

(roles/securitycentermanagement.etdCustomModulesEditor)

Full access to manage Cloud Security Command Center ETD custom modules.

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.list

securitycentermanagement.effectiveEventThreatDetectionCustomModules.*

  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.get
  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.list

securitycentermanagement.eventThreatDetectionCustomModules.*

  • securitycentermanagement.eventThreatDetectionCustomModules.create
  • securitycentermanagement.eventThreatDetectionCustomModules.delete
  • securitycentermanagement.eventThreatDetectionCustomModules.get
  • securitycentermanagement.eventThreatDetectionCustomModules.list
  • securitycentermanagement.eventThreatDetectionCustomModules.update
  • securitycentermanagement.eventThreatDetectionCustomModules.validate

securitycentermanagement.locations.*

  • securitycentermanagement.locations.get
  • securitycentermanagement.locations.list

(roles/securitycentermanagement.etdCustomModulesViewer)

Readonly access to Cloud Security Command Center ETD custom modules.

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.list

securitycentermanagement.effectiveEventThreatDetectionCustomModules.*

  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.get
  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.list

securitycentermanagement.eventThreatDetectionCustomModules.get

securitycentermanagement.eventThreatDetectionCustomModules.list

securitycentermanagement.eventThreatDetectionCustomModules.validate

securitycentermanagement.locations.*

  • securitycentermanagement.locations.get
  • securitycentermanagement.locations.list

(roles/securitycentermanagement.securityCenterServicesEditor)

Full access to manage Cloud Security Command Center services configuration.

securitycentermanagement.securityCenterServices.*

  • securitycentermanagement.securityCenterServices.get
  • securitycentermanagement.securityCenterServices.list
  • securitycentermanagement.securityCenterServices.update

(roles/securitycentermanagement.securityCenterServicesViewer)

Readonly access to Cloud Security Command Center services configuration.

securitycentermanagement.securityCenterServices.get

securitycentermanagement.securityCenterServices.list

(roles/securitycentermanagement.settingsEditor)

Full access to manage Cloud Security Command Center settings

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.list

securitycenter.organizationsettings.*

  • securitycenter.organizationsettings.get
  • securitycenter.organizationsettings.update

securitycenter.securitycentersettings.*

  • securitycenter.securitycentersettings.get
  • securitycenter.securitycentersettings.update

securitycentermanagement.*

  • securitycentermanagement.billingMetadata.get
  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.get
  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.list
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.get
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.list
  • securitycentermanagement.eventThreatDetectionCustomModules.create
  • securitycentermanagement.eventThreatDetectionCustomModules.delete
  • securitycentermanagement.eventThreatDetectionCustomModules.get
  • securitycentermanagement.eventThreatDetectionCustomModules.list
  • securitycentermanagement.eventThreatDetectionCustomModules.update
  • securitycentermanagement.eventThreatDetectionCustomModules.validate
  • securitycentermanagement.locations.get
  • securitycentermanagement.locations.list
  • securitycentermanagement.securityCenterServices.get
  • securitycentermanagement.securityCenterServices.list
  • securitycentermanagement.securityCenterServices.update
  • securitycentermanagement.securityCommandCenter.activate
  • securitycentermanagement.securityCommandCenter.checkActivationOperation
  • securitycentermanagement.securityCommandCenter.checkEligibility
  • securitycentermanagement.securityCommandCenter.checkOnboardingStatus
  • securitycentermanagement.securityCommandCenter.generateServiceAccounts
  • securitycentermanagement.securityCommandCenter.get
  • securitycentermanagement.securityCommandCenter.update
  • securitycentermanagement.securityHealthAnalyticsCustomModules.create
  • securitycentermanagement.securityHealthAnalyticsCustomModules.delete
  • securitycentermanagement.securityHealthAnalyticsCustomModules.get
  • securitycentermanagement.securityHealthAnalyticsCustomModules.list
  • securitycentermanagement.securityHealthAnalyticsCustomModules.simulate
  • securitycentermanagement.securityHealthAnalyticsCustomModules.test
  • securitycentermanagement.securityHealthAnalyticsCustomModules.update

(roles/securitycentermanagement.settingsViewer)

Readonly access to Cloud Security Command Center settings

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.list

securitycenter.organizationsettings.get

securitycenter.securitycentersettings.get

securitycentermanagement.billingMetadata.get

securitycentermanagement.effectiveEventThreatDetectionCustomModules.*

  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.get
  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.list

securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.*

  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.get
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.list

securitycentermanagement.eventThreatDetectionCustomModules.get

securitycentermanagement.eventThreatDetectionCustomModules.list

securitycentermanagement.eventThreatDetectionCustomModules.validate

securitycentermanagement.locations.*

  • securitycentermanagement.locations.get
  • securitycentermanagement.locations.list

securitycentermanagement.securityCenterServices.get

securitycentermanagement.securityCenterServices.list

securitycentermanagement.securityCommandCenter.checkActivationOperation

securitycentermanagement.securityCommandCenter.checkOnboardingStatus

securitycentermanagement.securityCommandCenter.get

securitycentermanagement.securityHealthAnalyticsCustomModules.get

securitycentermanagement.securityHealthAnalyticsCustomModules.list

securitycentermanagement.securityHealthAnalyticsCustomModules.simulate

securitycentermanagement.securityHealthAnalyticsCustomModules.test

(roles/securitycentermanagement.shaCustomModulesEditor)

Full access to manage Cloud Security Command Center SHA custom modules.

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.list

securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.*

  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.get
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.list

securitycentermanagement.locations.*

  • securitycentermanagement.locations.get
  • securitycentermanagement.locations.list

securitycentermanagement.securityHealthAnalyticsCustomModules.*

  • securitycentermanagement.securityHealthAnalyticsCustomModules.create
  • securitycentermanagement.securityHealthAnalyticsCustomModules.delete
  • securitycentermanagement.securityHealthAnalyticsCustomModules.get
  • securitycentermanagement.securityHealthAnalyticsCustomModules.list
  • securitycentermanagement.securityHealthAnalyticsCustomModules.simulate
  • securitycentermanagement.securityHealthAnalyticsCustomModules.test
  • securitycentermanagement.securityHealthAnalyticsCustomModules.update

(roles/securitycentermanagement.shaCustomModulesViewer)

Readonly access to Cloud Security Command Center SHA custom modules.

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.list

securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.*

  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.get
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.list

securitycentermanagement.locations.*

  • securitycentermanagement.locations.get
  • securitycentermanagement.locations.list

securitycentermanagement.securityHealthAnalyticsCustomModules.get

securitycentermanagement.securityHealthAnalyticsCustomModules.list

securitycentermanagement.securityHealthAnalyticsCustomModules.simulate

securitycentermanagement.securityHealthAnalyticsCustomModules.test

(roles/securitycentermanagement.viewer)

Readonly access to Cloud Security Command Center services and custom modules configuration.

resourcemanager.organizations.get

resourcemanager.projects.get

resourcemanager.projects.list

securitycenter.organizationsettings.get

securitycenter.securitycentersettings.get

securitycentermanagement.billingMetadata.get

securitycentermanagement.effectiveEventThreatDetectionCustomModules.*

  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.get
  • securitycentermanagement.effectiveEventThreatDetectionCustomModules.list

securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.*

  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.get
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.list

securitycentermanagement.eventThreatDetectionCustomModules.get

securitycentermanagement.eventThreatDetectionCustomModules.list

securitycentermanagement.eventThreatDetectionCustomModules.validate

securitycentermanagement.locations.*

  • securitycentermanagement.locations.get
  • securitycentermanagement.locations.list

securitycentermanagement.securityCenterServices.get

securitycentermanagement.securityCenterServices.list

securitycentermanagement.securityCommandCenter.checkActivationOperation

securitycentermanagement.securityCommandCenter.checkOnboardingStatus

securitycentermanagement.securityCommandCenter.get

securitycentermanagement.securityHealthAnalyticsCustomModules.get

securitycentermanagement.securityHealthAnalyticsCustomModules.list

securitycentermanagement.securityHealthAnalyticsCustomModules.simulate

securitycentermanagement.securityHealthAnalyticsCustomModules.test

Rôles de l'API Security Posture

Les rôles IAM suivants sont disponibles pour l'API Security Posture et sa fonctionnalité de validation de l'infrastructure en tant que code (IaC). Sauf indication contraire, vous pouvez attribuer ces rôles au niveau de l'organisation, du dossier ou du projet.

Role Permissions

(roles/securityposture.admin)

Full access to Security Posture service APIs.

Lowest-level resources where you can grant this role:

  • Organization

orgpolicy.*

  • orgpolicy.constraints.list
  • orgpolicy.customConstraints.create
  • orgpolicy.customConstraints.delete
  • orgpolicy.customConstraints.get
  • orgpolicy.customConstraints.list
  • orgpolicy.customConstraints.update
  • orgpolicy.policies.create
  • orgpolicy.policies.delete
  • orgpolicy.policies.list
  • orgpolicy.policies.update
  • orgpolicy.policy.get
  • orgpolicy.policy.set

resourcemanager.organizations.get

securitycenter.securityhealthanalyticssettings.*

  • securitycenter.securityhealthanalyticssettings.calculate
  • securitycenter.securityhealthanalyticssettings.get
  • securitycenter.securityhealthanalyticssettings.update

securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.*

  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.get
  • securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.list

securitycentermanagement.securityHealthAnalyticsCustomModules.create

securitycentermanagement.securityHealthAnalyticsCustomModules.delete

securitycentermanagement.securityHealthAnalyticsCustomModules.get

securitycentermanagement.securityHealthAnalyticsCustomModules.list

securitycentermanagement.securityHealthAnalyticsCustomModules.update

securityposture.*

  • securityposture.locations.get
  • securityposture.locations.list
  • securityposture.operations.delete
  • securityposture.operations.get
  • securityposture.operations.list
  • securityposture.postureDeployments.create
  • securityposture.postureDeployments.delete
  • securityposture.postureDeployments.get
  • securityposture.postureDeployments.list
  • securityposture.postureDeployments.update
  • securityposture.postureTemplates.get
  • securityposture.postureTemplates.list
  • securityposture.postures.create
  • securityposture.postures.delete
  • securityposture.postures.extract
  • securityposture.postures.get
  • securityposture.postures.list
  • securityposture.postures.update
  • securityposture.reports.create
  • securityposture.reports.get
  • securityposture.reports.list

(roles/securityposture.postureDeployer)

Mutate and read permissions to the Posture Deployment resource.

orgpolicy.*

  • orgpolicy.constraints.list
  • orgpolicy.customConstraints.create
  • orgpolicy.customConstraints.delete
  • orgpolicy.customConstraints.get
  • orgpolicy.customConstraints.list
  • orgpolicy.customConstraints.update
  • orgpolicy.policies.create
  • orgpolicy.policies.delete
  • orgpolicy.policies.list
  • orgpolicy.policies.update
  • orgpolicy.policy.get
  • orgpolicy.policy.set

resourcemanager.organizations.get

securitycenter.securityhealthanalyticssettings.*

  • securitycenter.securityhealthanalyticssettings.calculate
  • securitycenter.securityhealthanalyticssettings.get
  • securitycenter.securityhealthanalyticssettings.update

securitycentermanagement.securityHealthAnalyticsCustomModules.create

securitycentermanagement.securityHealthAnalyticsCustomModules.delete

securitycentermanagement.securityHealthAnalyticsCustomModules.update

securityposture.operations.get

securityposture.postureDeployments.*

  • securityposture.postureDeployments.create
  • securityposture.postureDeployments.delete
  • securityposture.postureDeployments.get
  • securityposture.postureDeployments.list
  • securityposture.postureDeployments.update

(roles/securityposture.postureDeploymentsViewer)

Read only access to the Posture Deployment resource.

resourcemanager.organizations.get

securityposture.operations.get

securityposture.postureDeployments.get

securityposture.postureDeployments.list

(roles/securityposture.postureEditor)

Mutate and read permissions to the Posture resource.

securityposture.operations.get

securityposture.postures.*

  • securityposture.postures.create
  • securityposture.postures.delete
  • securityposture.postures.extract
  • securityposture.postures.get
  • securityposture.postures.list
  • securityposture.postures.update

(roles/securityposture.postureViewer)

Read only access to the Posture resource.

resourcemanager.organizations.get

securityposture.operations.get

securityposture.postures.get

securityposture.postures.list

(roles/securityposture.reportCreator)

Create access for Reports, e.g. IaC Validation Report.

securityposture.operations.get

securityposture.reports.*

  • securityposture.reports.create
  • securityposture.reports.get
  • securityposture.reports.list

(roles/securityposture.viewer)

Read only access to all the SecurityPosture Service resources.

resourcemanager.organizations.get

securityposture.operations.get

securityposture.postureDeployments.get

securityposture.postureDeployments.list

securityposture.postureTemplates.*

  • securityposture.postureTemplates.get
  • securityposture.postureTemplates.list

securityposture.postures.get

securityposture.postures.list

Rôles d'agent de service

Un agent de service permet à un service d'accéder à vos ressources.

Après avoir activé Security Command Center, deux agents de service sont créés pour vous :

  • service-org-ORGANIZATION_ID@security-center-api.iam.gserviceaccount.com.

    Cet agent de service nécessite le rôle IAM roles/securitycenter.serviceAgent.

  • service-org-ORGANIZATION_ID@gcp-sa-ktd-hpsa.iam.gserviceaccount.com.

    Cet agent de service nécessite le rôle IAM roles/containerthreatdetection.serviceAgent.

Lors du processus d'activation de Security Command Center, vous êtes invité à accorder un ou plusieurs rôles IAM requis à chaque agent de service. L'attribution des rôles à chaque agent de service est nécessaire au bon fonctionnement de Security Command Center.

Pour afficher les autorisations de chaque rôle, consultez les ressources suivantes :

Pour attribuer les rôles, vous devez disposer du rôle roles/resourcemanager.organizationAdmin.

Si vous ne disposez pas du rôle roles/resourcemanager.organizationAdmin, l'administrateur de votre organisation peut attribuer les rôles aux agents de service pour vous à l'aide de la commande gcloud CLI suivante :

gcloud organizations add-iam-policy-binding ORGANIZATION_ID \
    --member="SERVICE_AGENT_NAME" \
    --role="IAM_ROLE"

Remplacez les éléments suivants :

  • ORGANIZATION_ID : ID de votre organisation.
  • SERVICE_AGENT_NAME : nom de l'agent de service auquel vous attribuez le rôle. Le nom est l'un des noms d'agent de service suivants :
    • service-org-ORGANIZATION_ID@security-center-api.iam.gserviceaccount.com
    • service-org-ORGANIZATION_ID@gcp-sa-ktd-hpsa.iam.gserviceaccount.com
  • IAM_ROLE : rôle requis suivant qui correspond à l'agent de service spécifié :
    • roles/securitycenter.serviceAgent
    • roles/containerthreatdetection.serviceAgent

Pour en savoir plus sur les rôles IAM, consultez la page Comprendre les rôles.

Rôles Web Security Scanner

Les rôles IAM suivants sont disponibles pour Web Security Scanner. Vous pouvez attribuer ces rôles au niveau du projet.

Role Permissions

(roles/cloudsecurityscanner.editor)

Full access to all Web Security Scanner resources

Lowest-level resources where you can grant this role:

  • Project

appengine.applications.get

cloudsecurityscanner.*

  • cloudsecurityscanner.crawledurls.list
  • cloudsecurityscanner.results.get
  • cloudsecurityscanner.results.list
  • cloudsecurityscanner.scanruns.get
  • cloudsecurityscanner.scanruns.getSummary
  • cloudsecurityscanner.scanruns.list
  • cloudsecurityscanner.scanruns.stop
  • cloudsecurityscanner.scans.create
  • cloudsecurityscanner.scans.delete
  • cloudsecurityscanner.scans.get
  • cloudsecurityscanner.scans.list
  • cloudsecurityscanner.scans.run
  • cloudsecurityscanner.scans.update

compute.addresses.list

resourcemanager.projects.get

resourcemanager.projects.list

serviceusage.quotas.get

serviceusage.services.get

serviceusage.services.list

(roles/cloudsecurityscanner.runner)

Read access to Scan and ScanRun, plus the ability to start scans

Lowest-level resources where you can grant this role:

  • Project

cloudsecurityscanner.crawledurls.list

cloudsecurityscanner.scanruns.get

cloudsecurityscanner.scanruns.list

cloudsecurityscanner.scanruns.stop

cloudsecurityscanner.scans.get

cloudsecurityscanner.scans.list

cloudsecurityscanner.scans.run

(roles/cloudsecurityscanner.viewer)

Read access to all Web Security Scanner resources

Lowest-level resources where you can grant this role:

  • Project

cloudsecurityscanner.crawledurls.list

cloudsecurityscanner.results.*

  • cloudsecurityscanner.results.get
  • cloudsecurityscanner.results.list

cloudsecurityscanner.scanruns.get

cloudsecurityscanner.scanruns.getSummary

cloudsecurityscanner.scanruns.list

cloudsecurityscanner.scans.get

cloudsecurityscanner.scans.list

serviceusage.quotas.get

serviceusage.services.get

serviceusage.services.list

(roles/websecurityscanner.serviceAgent)

Gives the Cloud Web Security Scanner service account access to compute engine details and app engine details.

appengine.applications.get

cloudasset.assets.listResource

compute.addresses.list

compute.backendServices.get

compute.forwardingRules.get

compute.globalForwardingRules.get

compute.sslCertificates.list

compute.targetHttpProxies.get

compute.targetHttpsProxies.get

compute.urlMaps.get