Google Security Command Center Integration

Google Security Command Center (SCC) is a native security management and data risk platform offered by Google for the Google Cloud services. The SCC can be used as a vulnerability monitoring tool to monitor vulnerabilities or can also be used as an Incident management service to log incident tickets whenever any incident occurs on the cloud infrastructure.

Prerequisites for Integration

  • Log in to Sprinto as administrator.

  • Ensure you have “Admin” access to the SCC account you wish to integrate.

How to integrate Sprinto with Google Security Command Center

Note: Ensure you have an integrated Google Workspace account on Sprinto. You can refer to integrate Google to learn more.

  1. Go to the Google Cloud login portal, and login with your credentials.

  2. On Google Cloud Console page, and click API & Services.

  3. Select Enable API & Services, and search for Google Command Center API. Select the API from the search result.

  4. On Google Command Center API page, click Enable.

Note: This enables the API on Security Command Center account. You can refer to below procedures to configure SCC as Incident management system or vulnerability monitoring system on Sprinto per your requirement.

Incident management

Do the below procedure to configure Google Security Command Center as incident management system:

  1. On Sprinto app, go to Security Hub > Incidents and click Add incident mgmt system.

  2. On Add an Incident Management System page, click Manage using Sprinto.

  3. On Manage incident on Sprinto page, click Add next to GSC.

  4. Take the following steps to add the Google Security Command Center on Vulnerability section:

    1. Go to Security Hub > Vulnerabilities and click on Add monitoring source.

    2. On Add vulnerability monitoring source page, click on Choose next to Google Security Command Center.

Vulnerabilities

Do the below procedure to configure Google Security Command Center as Vulnerabilty monitoring source:

  1. On Sprinto app, go to Security Hub > Vulnerabilities and click Add monitoring source.

  2. On Add vulnerability monitoring source page, click Choose next to SCC.

  3. On Configuration page, select the projects you want to setup vulnerability monitoring, then click Add Google Security Center.

    Note: If required, you can connect multiple accounts to fetch projects from various sources.

Final Step

This completes the integration procedure. To check if there are any tasks left or if any checks failed, go to Security Hub > Incident, or Security Hub > Vulnerability and look for Google Security Center.

Last updated