GCP-VPCNetwork-Private-Access-Enabled
Severity: High
Description: This control ensures that Private Google Access is enabled for all subnetwork in VPC Network. Private Google Access enables virtual machine instances on a subnet to reach Google APIs and services using an internal IP address rather than an external IP address. External IP addresses are routable and reachable over the Internet. Internal (private) IP addresses are internal to Google Cloud Platform and are not routable or reachable over the Internet. You can use Private Google Access to allow VMs without Internet access to reach Google APIs, services, and properties that are accessible over HTTP/HTTPS.
Remediation Steps:
Perform following to remove default network from project:
Sign in to GCP Console https://console.cloud.google.com.
Go to VPC network list in GCP Console by visiting networking list.
Click on the subnet name, the Subnet details page is displayed
Click on EDIT button
Set Private Google access to On
Click on Save.
Important:
Reference:
Blue Hexagon Proprietary