Skip to main content
{ Reporting and Compliance / Vulnerability Management }

Google Security Command Center Posture Report

Delivers a weekly report on Security Command Center coverage across your organization, what changed in the findings, and anything in the configuration that needs an admin, from disabled detectors to mute rules nobody reviewed.

What this agent does

This read-only agent checks the health of Google Security Command Center across an organization every week. It finds projects and folders where a detection service is off or a scanning source has stopped producing findings. It compares the enabled services, detectors, and mute rules with a baseline the team approved. It summarizes the Critical and High findings that appeared, went inactive, and were muted since last week. It flags anything that needs an admin, such as a notification config that stopped delivering or a detector module someone disabled.

The challenge

Security Command Center reports only what its enabled services detect. A missing service leaves no trace in the findings list. A new folder is created with a service disabled. Someone turns off a detector module to quiet one finding and never turns it back on. A mute rule written for one project matches findings across the organization. After a few months, nobody can say which muted findings a person actually reviewed. A notification config breaks, and the downstream queue goes silent.

The solution

The agent checks coverage, configuration, mute rules, and finding movement in one pass each week and compares them with the previous week and with the approved baseline. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.

Workflow

  1. 01

    Check coverage

    List the organization's folders and projects, and find where each detection service is off or a scanning source has produced nothing in the window.

  2. 02

    Check configuration

    Compare enabled services, detector modules, and mute rules with the approved baseline, and check each notification config's recent delivery.

  3. 03

    Check activity

    Summarize Critical and High findings that appeared, went inactive, and were muted since last week.

  4. 04

    Report

    Publish what changed and what needs action, with the fix for each item.

Agent template

# Google Security Command Center Posture Report

## Measurable outcomes

Every week, the admin knows which projects Security Command Center is not covering, how the configuration differs from the baseline, how the Critical and High findings moved, and what needs action. Track covered and uncovered projects, baseline differences, and open action items on every run.

## Procedure

Once a week, list the organization's folders and projects. Report the organization's tier. Report a service the tier does not include as not available, never as off. Check these detection services: Security Health Analytics, Event Threat Detection, Container Threat Detection, Virtual Machine Threat Detection, and Web Security Scanner. Flag each folder and project where a service is disabled or inherits a disabled state. Flag a scanning source, such as Security Health Analytics or Web Security Scanner, that produced no findings in the window. Compare the enabled services and detector modules with a baseline I approve, and flag each module that is disabled or enabled outside the baseline. Treat a configuration with no approved baseline as a candidate, never as drift. List every mute rule with its filter and who last edited it, and flag rules whose filter has no project or resource restriction. Flag dynamic mute rules with no expiry. Check each notification config, and flag any notification config whose topic received no messages while matching findings existed. Summarize the new Critical and High findings, the findings that went inactive, and the findings muted since the last report. List each muted finding with the mute initiator and any security mark on the finding. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.

## Requirements

It needs read-only Security Command Center access at the organization level to findings, sources, service settings, mute rules, and notification configs, read-only Resource Manager access to list folders and projects, read-only Cloud Monitoring access to the topics' projects, and nothing more. It never changes Security Command Center settings, mute rules, or findings, and never approves a baseline.