Skip to content

[meta][CDR] Update Google SCC integration to Leverage Native CDR Workflows #13898

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
5 tasks
kcreddy opened this issue May 13, 2025 · 1 comment
Open
5 tasks
Assignees
Labels
Category: CDR enhancement New feature or request Integration:google_scc Google Security Command Center Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

Comments

@kcreddy
Copy link
Contributor

kcreddy commented May 13, 2025

As part of effort to leverage Cloud Detection and Response (CDR) workflows such as Elastic CSPM and CNVM for 3rd party integrations, the cloud security findings data from Google Security Command Center needs to be enriched just like previous enhancements for AWS Security Hub.

For this work, the google_scc.finding data stream must be enriched to support Elastic CSPM workflow.

Tasks:

Success Criteria
Integration to be updated GSCC- https://www.elastic.co/docs/current/integrations/google_scc
The findings from GSCC which are compliance related findings i.e., CSPM/KSPM should be part of the 3rd party data view and mapped to the ECS schema supported by Cloud Security features.
To develop ES and Kibana assets (transforms, ingest pipelines, data views, etc.) required to make the data from GSCC integrations available in the Cloud Security features.

@kcreddy kcreddy self-assigned this May 13, 2025
@kcreddy kcreddy added enhancement New feature or request Category: CDR Integration:google_scc Google Security Command Center Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] labels May 13, 2025
@elasticmachine
Copy link

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Category: CDR enhancement New feature or request Integration:google_scc Google Security Command Center Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]
Projects
None yet
Development

No branches or pull requests

2 participants