: Integrate Prisma Cloud with Google Cloud Security Command Center (SCC)
Focus
Focus

Integrate Prisma Cloud with Google Cloud Security Command Center (SCC)

Table of Contents

Integrate Prisma Cloud with Google Cloud Security Command Center (SCC)

Learn how to integrate Prisma™ Cloud with Google Cloud Security Command Center (SCC).
Integrate Prisma™ Cloud with Google Cloud Security Command Center (SCC) for centralized visibility in to security and compliance risks associated with your cloud assets on the Google Cloud Platform (GCP).
You can set up this integration for a GCP Organization that you are monitoring with Prisma Cloud. The alerts generated by Prisma Cloud for GCP accounts based on your alert rule are posted to Google Cloud SCC. To show Prisma Cloud alerts in Google Could SCC for cloud accounts of other cloud types (such as AWS and Azure), contact Prisma Cloud support on the Palo Alto Networks LIVE Community.
  1. Verify the permissions for the service account you use to onboard the GCP Organization on Prisma Cloud.
    The Viewer, Organization Viewer, and Security Center Findings Editor roles are required.
  2. Enable the APIs required to view assets and findings on the Cloud SCC console.
    1. Go to the GCP Console API Library and select your GCP project.
      Make sure to enable these APIs in the project that owns the Service Account, which you will use to onboard the GCP Organization on Prisma Cloud.
    2. Select
      Enable APIs and Services
      .
    3. Enable the
      Cloud Security Command Center API
      .
    4. Enable the
      Identity and Access Management (IAM) API
      .
      The service account must also include the iam.serviceAccounts.signJwt permission for the integration.
  3. Sign up for the Prisma Cloud SCC solution on the Google console.
    A security center administrator can set up this integration on the Google console.
    1. Go to the Google Console and search for
      Prisma Cloud CSCC
      .
    2. Visit Palo Alto Networks site to Signup
      .
    3. Select the organization that you onboarded in to Prisma Cloud.
    4. Select the
      Service account
      you used to onboard the GCP Organization.
    5. Copy the
      Source ID
      . You need the
      Source ID
      when you set up this integration in Prisma Cloud.
    6. Click
      Done
      .
  4. Set up Google Cloud SCC as one of the integration channels in Prisma Cloud.
    1. Log in to Prisma Cloud.
    2. Select
      Settings
      Integrations
      .
    3. Add Integration
      Google CSCC
      . A modal wizard opens where you can add the CSCC integration.
    4. Enter
      Integration Name
      and
      Description
      .
    5. Enter the
      Source ID
      that you copied from Google.
    6. Select the
      GCP Organization
      .
    7. Next
      and then
      Test
      . Review the Summary and
      Save
      .
      For a successful integration, you must configure adequate permissions for the service account (as listed above). After you set up the integration successfully, you can use the Get Status link in
      Settings
      Integrations
      to periodically check the integration status.
  5. Create an Alert Rule for Run-Time Checks or modify an existing rule to send alerts to Google Cloud SCC. See Send Prisma Cloud Alert Notifications to Third-Party Tools.
  6. View alerts in Cloud SCC.
    1. Go to the Google Console and select
      Security
      Security Command Center
      .
    2. Click
      Findings
      to view the alerts.
    3. Select the rule to see the details about the alerts.

Recommended For You