Skip to main content

Security Command Center

Security Command Center (SCC) is Google Cloud's organization-wide service for misconfiguration and threat findings. The GCP Enterprise Baseline routes its high-severity findings to one Pub/Sub topic and one alert, mutes the sandbox, and can remediate public buckets automatically.

What it does​

Security Command Center runs at the organization and reports findings for every project: misconfigurations from Security Health Analytics in the Standard tier, and threat detection and further services in the Premium and Enterprise tiers. Each finding has a category, a severity and a state. A notification config streams findings that match a filter to a Pub/Sub topic as they arise, a mute rule hides findings that match a filter, and a continuous export writes findings to Cloud Logging.

How BuiltForProd uses it​

Security Command Center is activated for the organization outside the code. scc_tier in environments/core/security/security.hcl records which tier is active: standard (free) by default, premium when the organization subscribes (from $15,000 per year, or pay-as-you-go). The organization-scoped scc unit (environments/core/security/global) wires what happens to the findings:

GCP/acme-gcp-platform-baseline/modules/scc/main.tf (lines 31-51)
resource "google_scc_v2_organization_notification_config" "high" {
organization = var.organization_id
config_id = "${var.namespace}-high-critical"
location = "global"
description = "ACTIVE, unmuted HIGH and CRITICAL findings to Pub/Sub (${var.alerts_topic_id})"
pubsub_topic = var.alerts_topic_id

streaming_config {
filter = "(severity=\"HIGH\" OR severity=\"CRITICAL\") AND state=\"ACTIVE\" AND NOT mute=\"MUTED\""
}
}

resource "google_scc_v2_organization_mute_config" "sandbox" {
count = var.sandbox_project_id == "" ? 0 : 1
organization = var.organization_id
mute_config_id = "${var.namespace}-mute-sandbox"
location = "global"
description = "plat-sandbox is excluded from compliance evidence (experiments, not audited workloads)"
filter = "resource.project_display_name=\"${var.sandbox_project_id}\""
type = "STATIC"
}
  • Notification. acme-high-critical streams every active, unmuted finding of HIGH or CRITICAL severity to the topic acme-security-alerts in acme-core-security (Pub/Sub), which the contract publishes to each stage as platform--alerts-topic.
  • Sandbox mute. The static mute rule acme-mute-sandbox mutes the findings of acme-plat-sandbox, which is for experiments and is excluded from compliance evidence, so they never reach the topic.
  • Alert. The continuous export to Cloud Logging brings findings into the central log bucket through the organization sink, where the log-based detection scc-high-findings raises an alert to the security mailbox through Cloud Monitoring.

The notifier (optional). With enable_scc_notifier = true (off by default), the unit runs the Cloud Run service acme-scc-notifier in acme-core-security, with internal ingress only, fed by an authenticated push subscription on the alerts topic. It writes one structured log line per finding. With auto_remediate_public_buckets = true (the default once the notifier runs), it removes allUsers and allAuthenticatedUsers from any bucket with a PUBLIC_BUCKET_ACL finding, except in acme-core-public, whose buckets are public by design. Its account holds Storage Admin on every project but acme-core-public, so even a misrouted finding cannot change a public bucket. The image is built from src/scc-notifier by the Baseline's notifier-image.yml workflow; email stays with the scc-high-findings alert.

The auditor groups hold Security Command Center Admin Viewer at the organization, so they see every finding without being able to change the configuration.

Terms you will see​

TermMeaning
FindingOne detected issue on one resource, with a category, a severity and a state.
Security Health AnalyticsThe misconfiguration detectors of the Standard tier.
Notification configA filter and a Pub/Sub topic that matching findings stream to.
Mute ruleA filter whose matching findings are hidden from the default views.
PUBLIC_BUCKET_ACLThe finding category for a bucket readable by anyone.

Where to read more​