31 of 32 in All Controls
gcp

Enable Policy Analyzer and IAM Recommender

IDGCP-IAM-004
Severity
medium
Automation
Auto
Category
iam
Enforcementmandatory
Complexity / Impact
low(low impact)
Cloud Scopegcp:organization
Environments
productionnon-production
Target Resources
IAMPolicyServiceAccountRecommenderOrganizationProject
Services
iamrecommendercloudassetlogging
Tags
gcpiamrecommenderleast-privilegepolicy-analyzersecurity-posture
Frameworks
CIS GCPNIST 800-53ISO 27001PCI DSSSOC 2
Governance
cloud-security-team (monthly)
Created
2026-08-28
Last Updated
2026-08-28

Specification & Description

Activate Google Cloud Policy Analyzer and IAM Recommender at the organization level to continuously analyze effective access, discover overprivileged accounts, identify unused permissions, and safely enforce least-privilege IAM bindings across all projects.

Technical Specifications

Google Cloud Policy Intelligence provides two foundational IAM governance capabilities that should be activated organization-wide:

  1. Policy Analyzer: Evaluates effective access across your entire resource hierarchy. It answers complex questions like "Which external users can read this BigQuery dataset?", "Who can impersonate this deployment service account?", and "What effective permissions does a specific engineer have across all folders?" It traces group memberships, inherited bindings, and service account impersonation chains.

  2. IAM Recommender: Continuously analyzes rolling 90-day Cloud Audit Logs per principal (users, groups, and service accounts). When an identity holds broad permissions that are never exercised (e.g., assigned roles/editor but only calling Cloud Storage APIs), the recommender suggests safe, tailored role reductions.

  3. Unused Service Account Discovery: Identifies active service accounts with zero API activity over 90 days, flagging them for safe disabling and decommissioning.

  4. Policy Simulator: Validates proposed permission removals against historical activity before applying them in production, guaranteeing that legitimate workload traffic is not disrupted.

Security Rationale

Role accumulation is a primary cause of privilege creep in growing organizations. Developers and operational service accounts are frequently granted broad administrative roles during initial provisioning and never scoped down. Overprivileged identities dramatically expand the blast radius if credentials are leaked: an attacker who compromises a single service account can exploit unused admin permissions to move laterally and access sensitive data. Together, Policy Analyzer and IAM Recommender provide data-driven evidence of effective access paths and actual permission usage, eliminating the guesswork and fear of breaking production workloads when right-sizing IAM policies.

Policy Exceptions (1)

Break-glass emergency identities and disaster recovery service accounts that are intentionally idle during standard operations are exempt from automated 90-day inactivity deletion, provided they are documented in the emergency access register and tested semi-annually.

Operational & Implementation Notes

IAM Recommender requires a minimum of 90 days of continuous Cloud Audit Logging to establish high-confidence recommendations. In newly created landing zone projects, the recommender will gather telemetry before producing role reduction suggestions. Always pair recommender reviews with Policy Simulator to prevent accidental removal of seasonal or monthly cron job permissions.

We value your privacy

We use analytics cookies to understand how visitors interact with our site and to improve the user experience. You can choose to accept or decline these cookies.