GCP
Lastly, we will look at cloud auditing tools that can be leveraged within GCP.
Google Cloud Monitoring
IT auditors can leverage Google Cloud Monitoring to gain real-time visibility into GCP. We can get to Cloud Monitoring by simply searching for it on the Google Cloud console, as shown in Figure 7.23:

Figure 7.23 – Google Cloud Monitoring Overview
A useful feature for an IT auditor is Dashboards. This provides us with dashboards for Disks, Firewalls, Infrastructure Summary, and VM Instances:

Figure 7.24 – Dashboards Overview
One valuable dashboard to review is Firewalls. Let us go to the Firewalls dashboard, as seen in Figure 7.25:

Figure 7.25 – The Firewalls dashboard
If we dig deeper, we note that there is an ingress/inbound rule that allows traffic from the internet (0.0.0.0/0). This particular rule should pique an IT auditor’s interest as port 22 (SSH...