Security Command Center 可帮助您在 Google Cloud 和其他云服务提供商之间预防、检测和应对安全风险。启用 Security Command Center 后,您可以使用 Google Cloud 控制台查看影响 Compute Engine 资源的最高优先级安全风险。
本文档介绍了如何激活 Security Command Center 以及查看它为您的 Compute Engine 资源提供的信息中心。
激活 Security Command Center
如需使用 Security Command Center 分析 Compute Engine 资源,您必须激活 Security Command Center。本部分介绍了 Security Command Center 提供的服务层级,以及如何在项目中激活标准层级或专业层级。
[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-09-03。"],[],[],null,["# Monitor security risks with Security Command Center\n\n[Security Command Center](/security-command-center/docs/security-command-center-overview)\nhelps you prevent, detect, and respond to security risks across Google Cloud and other cloud\nproviders. When you enable Security Command Center, you can use the Google Cloud console to view the\nhighest-priority security risks that affect your\nCompute Engine resources.\n\n\nThis document explains how to activate Security Command Center and view the dashboard that it\nprovides for your Compute Engine resources.\n\nActivate Security Command Center\n--------------------------------\n\n\nTo analyze your Compute Engine resources with Security Command Center, you must\n[activate Security Command Center](/security-command-center/docs/activate-scc-overview).\nThis section explains the service tiers that Security Command Center offers and explains how to\nactivate the Standard or Premium tier in your project.\n\n### Service tiers\n\n\nWhen you activate Security Command Center, you choose which\n[service tier](/security-command-center/docs/service-tiers) to activate:\n\n- **Standard**. Enables basic scanning for risks and misconfigurations. Applies to your Google Cloud resources.\n- **Premium**. Provides enhanced scanning for risks, vulnerabilities, and misconfigurations, as well as security posture management, attack paths, threat detection, and compliance monitoring. Applies to your Google Cloud resources.\n- **Enterprise**. Offers a complete cloud-native application protection platform (CNAPP) solution, including automated case management and remediation playbooks. Applies to your Google Cloud resources, as well as resources hosted by other cloud providers.\n\n\nYou can use the Standard tier at no additional charge. To learn about pricing for the Premium\nand Enterprise tiers, see [Security Command Center\npricing](/security-command-center/pricing).\n| **Note** : This page explains how to activate the Standard or Premium service tier for your project. Some Security Command Center features require you to [activate the Enterprise\n| tier](/security-command-center/docs/activate-enterprise-tier) or [activate the Standard\n| or Premium tier](/security-command-center/docs/activate-scc-for-an-organization) for your entire organization.\n\n### Activate Security Command Center in your project\n\n\nTo activate the Security Command Center Standard or Premium tier in your project, do the following:\n\n1. In the Google Cloud console, go to **Compute Engine Overview**.\n\n [Go to Compute Engine Overview](https://console.cloud.google.com/projectselector2/compute/overview?supportedpurview=project)\n2.\n Look for a pane titled **Sample security findings**.\n\n\n This pane shows examples of the types of security findings that you might see after you\n enable Security Command Center. These examples don't represent actual security issues in your\n project.\n\n\n If you see a pane titled **Top security findings**, then\n Security Command Center is already activated. You can skip the remaining steps.\n3. In the **Sample security findings** pane, click **Turn on security scanning for\n free**. The activation pane opens.\n4. Optional: To choose a different service tier, find the service tier that you want to enable, and then click **Select** for that tier.\n5. Click **Enable**.\n\n\nAfter you activate Security Command Center, it starts to analyze, or scan, your resources for\nCompute Engine and other Google Cloud services. This initial scan is\n[usually\ncomplete within minutes or hours](/security-command-center/docs/concepts-scan-latency-overview#scan_latency).\n\nReview high-priority security risks\n-----------------------------------\n\n\nAfter Security Command Center\n[completes\nan initial scan](/security-command-center/docs/concepts-scan-latency-overview#scan_latency) of your Compute Engine resources, you can review high-priority\n*findings* for your resources in the Google Cloud console. Each finding represents a\nsecurity risk.\n\n\nTo review high-priority findings for your Compute Engine resources, do the following:\n\n1.\n In the Google Cloud console, go to **Compute Engine Overview**.\n\n [Go to Compute Engine Overview](https://console.cloud.google.com/projectselector2/compute/overview?supportedpurview=project)\n2.\n Find the **Top security findings** pane. This pane lists the most important types of\n findings that affect your Compute Engine resources.\n\n - To view the high-priority findings in each category, click the name of the category.\n - To view all of your findings, click arrow_forward **View all findings**.\n\nGet an overview of other risks\n------------------------------\n\n\nIn addition to an [overview of high-priority risks](#high-priority-risks), you can\nuse the Google Cloud console to view other types of security risks that affect your\nCompute Engine resources.\n\n\nTo get an overview of these additional risks, in the Google Cloud console, go to\n**Security Risk Overview**.\n\n[Go to Security Risk Overview](https://console.cloud.google.com/projectselector2/compute/security?supportedpurview=project)\n\n\nThis page shows the following information:\n\nTop security findings\n\n:\n This table lists the most important types of findings that affect your Compute Engine resources.\n\nAll vulnerability findings over time\n\n:\n This chart shows the total number of Security Command Center findings over time for your Compute Engine instances. Findings are categorized by severity.\n\n\n To change the date range, click the list, and then select a new value.\n\nTop CVE findings on your virtual machines\n\n:\n This heatmap shows the number of Common Vulnerabilities and Exposures (CVEs) that affect your Compute Engine instances, grouped by the potential impact and exploitability of each CVE.\n\nTop CVE findings\n\n:\n This table lists the most severe CVEs that affect your Compute Engine instances, including the exploitability and impact of each CVE.\n\nBoost your security knowledge\n\n:\n This pane provides links to more information about Security Command Center and strategies for mitigating vulnerabilities.\n\n\nTo get more details, click the links in each pane.\n\nWhat's next\n-----------\n\n- [Security Command Center\n overview](/security-command-center/docs/security-command-center-overview)\n- [Security Command Center service tiers](/security-command-center/docs/service-tiers)\n- [Security Command Center pricing](/security-command-center/pricing)"]]