Google Security Command Center Posture Report
Delivers a weekly report on Security Command Center coverage across your organization, what changed in the findings, and anything in the configuration that needs an admin, from disabled detectors to mute rules nobody reviewed.
What this agent does
This read-only agent checks the health of Google Security Command Center across an organization every week. It finds projects and folders where a detection service is off or a scanning source has stopped producing findings. It compares the enabled services, detectors, and mute rules with a baseline the team approved. It summarizes the Critical and High findings that appeared, went inactive, and were muted since last week. It flags anything that needs an admin, such as a notification config that stopped delivering or a detector module someone disabled.
The challenge
Security Command Center reports only what its enabled services detect. A missing service leaves no trace in the findings list. A new folder is created with a service disabled. Someone turns off a detector module to quiet one finding and never turns it back on. A mute rule written for one project matches findings across the organization. After a few months, nobody can say which muted findings a person actually reviewed. A notification config breaks, and the downstream queue goes silent.
The solution
The agent checks coverage, configuration, mute rules, and finding movement in one pass each week and compares them with the previous week and with the approved baseline. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.
Workflow
- 01
Check coverage
List the organization's folders and projects, and find where each detection service is off or a scanning source has produced nothing in the window.
- 02
Check configuration
Compare enabled services, detector modules, and mute rules with the approved baseline, and check each notification config's recent delivery.
- 03
Check activity
Summarize Critical and High findings that appeared, went inactive, and were muted since last week.
- 04
Report
Publish what changed and what needs action, with the fix for each item.
Agent template
# Google Security Command Center Posture Report
## Measurable outcomes
Every week, the admin knows which projects Security Command Center is not covering, how the configuration differs from the baseline, how the Critical and High findings moved, and what needs action. Track covered and uncovered projects, baseline differences, and open action items on every run.
## Procedure
Once a week, list the organization's folders and projects. Report the organization's tier. Report a service the tier does not include as not available, never as off. Check these detection services: Security Health Analytics, Event Threat Detection, Container Threat Detection, Virtual Machine Threat Detection, and Web Security Scanner. Flag each folder and project where a service is disabled or inherits a disabled state. Flag a scanning source, such as Security Health Analytics or Web Security Scanner, that produced no findings in the window. Compare the enabled services and detector modules with a baseline I approve, and flag each module that is disabled or enabled outside the baseline. Treat a configuration with no approved baseline as a candidate, never as drift. List every mute rule with its filter and who last edited it, and flag rules whose filter has no project or resource restriction. Flag dynamic mute rules with no expiry. Check each notification config, and flag any notification config whose topic received no messages while matching findings existed. Summarize the new Critical and High findings, the findings that went inactive, and the findings muted since the last report. List each muted finding with the mute initiator and any security mark on the finding. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.
## Requirements
It needs read-only Security Command Center access at the organization level to findings, sources, service settings, mute rules, and notification configs, read-only Resource Manager access to list folders and projects, read-only Cloud Monitoring access to the topics' projects, and nothing more. It never changes Security Command Center settings, mute rules, or findings, and never approves a baseline. Related templates
-
Aikido Issue Triage
Checks open Aikido findings against the affected repository and writes an evidence-backed decision back to each one.
Vulnerability Management / Application Security 4 tools -
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Finding Triage
Writes an evidence-based judgment for each open Critical and High Security Hub CSPM finding, verifies it against the live resource, and suppresses the ones the checks prove are false positives.
Featured Vulnerability Management 2 tools