Security Command Center controls for generative AI use cases

This document includes the best practices and guidelines for Security Command Center when running generative AI workloads on Google Cloud. Use Security Command Center with Vertex AI to help protect your cloud organization, your AI workloads, and the AI data that you store on Google Cloud.

Security Command Center provides the following:

  • Centralized security management
  • Threat detection and incident response
  • Automated security assessments
  • Compliance and regulatory reporting
  • Security recommendations and best practices

Required Security Command Center controls

The following controls are strongly recommended when using Security Command Center.

Enable Security Command Center at the organization level

Google control ID SCC-CO-6.1
Category Required
Description
Enable Security Command Center at the organization level to avoid additional configuration. If you don't want to use Security Command Center, you must enable another posture management solution.
Applicable products
  • Security Command Center
Related NIST-800-53 controls
  • SI-4
  • SI-5
Related CRI profile controls
  • PR.DS-5.1
  • PR.DS-8.1
  • ID.RA-1.1
  • DE.CM-1.1
  • DE.CM-1.2
  • DE.CM-1.3
  • DE.CM-1.4
  • DE.CM-5.1
  • DE.CM-6.1
  • DE.CM-6.2
  • DE.CM-6.3
  • DE.CM-7.1
  • DE.CM-7.2
  • DE.CM-7.3
  • DE.CM-7.4
  • DE.DP-2.1
  • DE.DP-3.1
  • DE.DP-4.1
  • DE.DP-4.2
  • DE.DP-5.1
  • DE.AE-2.1
  • DE.AE-3.1
  • DE.AE-3.2
  • DE.AE-4.1
  • ID.RA-1.1
  • ID.RA-2.1
  • ID.RA-3.1
  • ID.RA-3.2
  • ID.RA-3.3
Related information

Depending on your use cases around generative AI, we recommend additional controls. These controls include data retention controls and other policy-driven controls that are based on your enterprise policies.

Configure alerts from Security Command Center

Google control ID SCC-CO-7.1
Category Recommended
Description
Alerts from the Security Command Center provide visibility into your organization and notify you about issues with your Google Cloud services so you can take appropriate action. You can set up alerts in Cloud Logging to get notifications on errors that are related to the Security Command Center service agent (service-org-ORGANIZATION_NUMBER@security-center-api.iam.gserviceaccount.com).
Applicable products
  • Security Command Center
  • Logging
Related NIST-800-53 controls
  • AU-2
  • AU-3
  • AU-8
  • AU-9
Related CRI profile controls
  • DM.ED-7.1
  • DM.ED-7.2
  • DM.ED-7.3
  • DM.ED-7.4
  • PR.IP-1.4
Related information

What's next