Security Command Center
Security Command Center (SCC) is Google Cloud's organization-wide service for misconfiguration and threat findings. The GCP Enterprise Baseline routes its high-severity findings to one Pub/Sub topic and one alert, mutes the sandbox, and can remediate public buckets automatically.
What it does
Security Command Center runs at the organization and reports findings for every project: misconfigurations from Security Health Analytics in the Standard tier, and threat detection and further services in the Premium and Enterprise tiers. Each finding has a category, a severity and a state. A notification config streams findings that match a filter to a Pub/Sub topic as they arise, a mute rule hides findings that match a filter, and a continuous export writes findings to Cloud Logging.
How BuiltForProd uses it
Security Command Center is activated for the organization outside the code. scc_tier in environments/core/security/security.hcl records which tier is active: standard (free) by default, premium when the organization subscribes (from $15,000 per year, or pay-as-you-go). The organization-scoped scc unit (environments/core/security/global) wires what happens to the findings:
resource "google_scc_v2_organization_notification_config" "high" {
organization = var.organization_id
config_id = "${var.namespace}-high-critical"
location = "global"
description = "ACTIVE, unmuted HIGH and CRITICAL findings to Pub/Sub (${var.alerts_topic_id})"
pubsub_topic = var.alerts_topic_id
streaming_config {
filter = "(severity=\"HIGH\" OR severity=\"CRITICAL\") AND state=\"ACTIVE\" AND NOT mute=\"MUTED\""
}
}
resource "google_scc_v2_organization_mute_config" "sandbox" {
count = var.sandbox_project_id == "" ? 0 : 1
organization = var.organization_id
mute_config_id = "${var.namespace}-mute-sandbox"
location = "global"
description = "plat-sandbox is excluded from compliance evidence (experiments, not audited workloads)"
filter = "resource.project_display_name=\"${var.sandbox_project_id}\""
type = "STATIC"
}
- Notification.
acme-high-criticalstreams every active, unmuted finding of HIGH or CRITICAL severity to the topicacme-security-alertsinacme-core-security(Pub/Sub), which the contract publishes to each stage asplatform--alerts-topic. - Sandbox mute. The static mute rule
acme-mute-sandboxmutes the findings ofacme-plat-sandbox, which is for experiments and is excluded from compliance evidence, so they never reach the topic. - Alert. The continuous export to Cloud Logging brings findings into the central log bucket through the organization sink, where the log-based detection
scc-high-findingsraises an alert to the security mailbox through Cloud Monitoring.
The notifier (optional). With enable_scc_notifier = true (off by default), the unit runs the Cloud Run service acme-scc-notifier in acme-core-security, with internal ingress only, fed by an authenticated push subscription on the alerts topic. It writes one structured log line per finding. With auto_remediate_public_buckets = true (the default once the notifier runs), it removes allUsers and allAuthenticatedUsers from any bucket with a PUBLIC_BUCKET_ACL finding, except in acme-core-public, whose buckets are public by design. Its account holds Storage Admin on every project but acme-core-public, so even a misrouted finding cannot change a public bucket. The image is built from src/scc-notifier by the Baseline's notifier-image.yml workflow; email stays with the scc-high-findings alert.
The auditor groups hold Security Command Center Admin Viewer at the organization, so they see every finding without being able to change the configuration.
Terms you will see
| Term | Meaning |
|---|---|
| Finding | One detected issue on one resource, with a category, a severity and a state. |
| Security Health Analytics | The misconfiguration detectors of the Standard tier. |
| Notification config | A filter and a Pub/Sub topic that matching findings stream to. |
| Mute rule | A filter whose matching findings are hidden from the default views. |
PUBLIC_BUCKET_ACL | The finding category for a bucket readable by anyone. |
Where to read more
- GCP Enterprise Baseline overview for the detective controls as a whole.
- Pub/Sub for the alerts topic.
- Secure for the security pillar of the BuiltForProd Standard.