# Google Security Command Center Integration

Google Security Command Center (**SCC**) is a native security management and data risk platform offered by Google for the Google Cloud services. The SCC can be used as a vulnerability monitoring tool to monitor vulnerabilities or can also be used as an Incident management service to log incident tickets whenever any incident occurs on the cloud infrastructure.

### Prerequisites for Integration <a href="#prerequisites-for-integration" id="prerequisites-for-integration"></a>

* Log in to Sprinto as administrator.
* Ensure you have “Admin” access to the SCC account you wish to integrate.

### How to integrate Sprinto with Google Security Command Center <a href="#how-to-integrate-sprinto-with-google-security-command-center" id="how-to-integrate-sprinto-with-google-security-command-center"></a>

**Note**: Ensure you have an integrated Google Workspace account on Sprinto. You can refer to [integrate Google](https://sprinto.freshdesk.com/support/solutions/articles/72000600926-how-to-integrate-sprinto-with-google-workspace) to learn more.

1. Go to the [Google Cloud login portal](https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fconsole.cloud.google.com%2F\&followup=https%3A%2F%2Fconsole.cloud.google.com%2F\&ifkv=AXo7B7VH91PgVQ4jbBNWJWktVxk9boELn5o7id36NEZ4Sqe_2oniGbu2nRVujGIbcloSOj4wZ5WhEA\&osid=1\&passive=1209600\&service=cloudconsole\&flowName=GlifWebSignIn\&flowEntry=ServiceLogin\&dsh=S2097510477%3A1693460833283669), and login with your credentials.
2. On **Google Cloud Console** page, and click **API & Services**.

   <figure><img src="https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/72071862414/original/wdj3pzOI_g1H7c6hJKXGWKbf117M2lqIEg.png?1699521882" alt="" width="563"><figcaption></figcaption></figure>
3. Select **Enable API & Services,** and search for **Google Command Center API.** Select the API from the search result. &#x20;

   <figure><img src="https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/72071862493/original/z2FFv2eRQV57Y54iVXHLhLo62mVKFJgV9w.png?1699521936" alt="" width="563"><figcaption></figcaption></figure>
4. On **Google Command Center API** page, click **Enable**.

   <figure><img src="https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/72071862600/original/xGztZ9IvlQTmcp73Oo32L8HJloN2iWlpng.png?1699522012" alt="" width="563"><figcaption></figcaption></figure>

**Note**: This enables the API on Security Command Center account. You can refer to below procedures to  configure SCC as Incident management system or vulnerability monitoring system on Sprinto per your requirement.

### Incident management <a href="#incident-management" id="incident-management"></a>

Do the below procedure to configure Google Security Command Center as incident management system:

1. On Sprinto app, go to **Data Library** > **Incidents** and click **Add incident mgmt system**.
2. On **Add an Incident Management System** page, click **Manage using Sprinto**.
3. On **Manage incident on Sprinto** page, click **Add** next to GSC.
4. Take the following steps to add the Google Security Command Center on Vulnerability section:
   1. Go to **Security Hub** > **Vulnerabilities** and click on **Add monitoring source**.
   2. On **Add vulnerability monitoring source** page, click on **Choose** next to Google Security Command Center.

### Vulnerabilities <a href="#vulnerabilities" id="vulnerabilities"></a>

Do the below procedure to configure Google Security Command Center as Vulnerabilty monitoring source:

1. On Sprinto app, go to **Data Library** > **Vulnerabilities** and click **Add monitoring source**.
2. On **Add vulnerability monitoring source** page, click **Choose** next to SCC.
3. On **Configuration** page, select the projects you want to setup vulnerability monitoring, then click **Add Google Security Center**.

   **Note**: If required, you can connect multiple accounts to fetch projects from various sources.<br>

### Final Step <a href="#final-step" id="final-step"></a>

This completes the integration procedure. To check if there are any tasks left or if any checks failed, go to **Security Hub** > **Incident,** or **Security Hub** > **Vulnerability** and look for Google Security Center.
