With Google Cloud, security and compliance are not just features, they are built into your infrastructure
Seamless GCP Integration
Kawach offers a seamless connection to your Google Cloud environment,
enabling automated tracking of your cloud resources and configurations.
The integration is designed to support compliance frameworks such as SOC
2, ISO 27001, HIPAA, and more. By centralizing cloud security and
compliance operations, Kawach reduces risk while improving visibility
across your GCP infrastructure.
Key Benefits
Automated Compliance Monitoring
Continuously monitor GCP resources and collect audit evidence
with minimal manual effort..
Centralized Access and Identity Management
Sync IAM data for scheduled access reviews to ensure only
authorized personnel access critical systems.
Proactive Security Insights
Detect vulnerabilities and misconfigurations in real time across
Compute Engine, Container Registry, and other services.
Comprehensive Asset Inventory
Maintain an up-to-date inventory of VMs, storage buckets,
networks, and service accounts; mark out-of-scope resources to
streamline audits.
Scalable and Flexible
Automatically discover new resources and scale compliance efforts
as your cloud environment grows.
Continuous Risk Oversight
Track changes, misconfigurations, and policy deviations
automatically to ensure ongoing control effectiveness.
Integration Setup
- Connect GCP to Kawach Use the setup script for fast, secure integration, or follow manual steps for granular control.
- Configure Domain-Wide Delegation Grant the Kawach service account access to domain-wide data via the Google Admin Console.
- Assign Roles and Permissions Provide required GCP roles, such as resourcemanager.organizationAdmin, to enable full integration and automated evidence collection.
Supported GCP Resources
Kawach automatically fetches and monitors key GCP resources:
- IAM Users and Roles Track access assignments and role changes.
- Compute Instances Monitor VM configurations, states, and security settings.
- Storage Buckets Audit data access permissions and configurations.
- Network Configurations Review firewalls, subnets, and security settings.
Unsupported resources can be manually added for full audit coverage.
Ongoing Management
- Periodic Reconnection Maintain integration as permissions, APIs, or organizational structures change.
- Scope Management Define and update monitored resources to ensure accurate compliance tracking.
- Continuous Monitoring Track new resources, access changes, and vulnerabilities automatically.
Conclusion
Kawach’s integration with Google Cloud Platform (GCP) empowers organizations to maintain continuous compliance, strengthen security controls, and reduce manual effort.
By connecting your GCP environment, Kawach provides automated monitoring, access reviews, and evidence collection, helping teams meet regulatory requirements efficiently and confidently.