Is there a way to have certain roles on the SIEM portion of SecOps to be able to view certain logs, and others not?
Yes according to this: https://cloud.google.com/chronicle/docs/soar/cloud-architecture/access-control
Google Security Operations utilizes a customizable RBAC mechanism to support any required flexibility or strictness on access control and provides a default Master Admin account which belongs to the customer.
Yes according to this: https://cloud.google.com/chronicle/docs/soar/cloud-architecture/access-control
Google Security Operations utilizes a customizable RBAC mechanism to support any required flexibility or strictness on access control and provides a default Master Admin account which belongs to the customer.
Hi NC
For RBAC and data RBAC this requires BYOID and workforce identity federation with a pool.
Reply
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.