[meta][CDR] Update Google SCC integration to Leverage Native CDR Workflows #13898
Labels
Category: CDR
enhancement
New feature or request
Integration:google_scc
Google Security Command Center
Team:Security-Service Integrations
Security Service Integrations team [elastic/security-service-integrations]
As part of effort to leverage Cloud Detection and Response (CDR) workflows such as Elastic CSPM and CNVM for 3rd party integrations, the cloud security findings data from Google Security Command Center needs to be enriched just like previous enhancements for AWS Security Hub.
For this work, the
google_scc.finding
data stream must be enriched to support Elastic CSPM workflow.Tasks:
Success Criteria
Integration to be updated GSCC- https://www.elastic.co/docs/current/integrations/google_scc
The findings from GSCC which are compliance related findings i.e., CSPM/KSPM should be part of the 3rd party data view and mapped to the ECS schema supported by Cloud Security features.
To develop ES and Kibana assets (transforms, ingest pipelines, data views, etc.) required to make the data from GSCC integrations available in the Cloud Security features.
The text was updated successfully, but these errors were encountered: