Skip to main content
Solved

Log monitoring RBAC

  • July 25, 2024
  • 2 replies
  • 6 views

Forum|alt.badge.img+5

Is there a way to have certain roles on the SIEM portion of SecOps to be able to view certain logs, and others not?

Best answer by nc2

Yes according to this: https://cloud.google.com/chronicle/docs/soar/cloud-architecture/access-control

Google Security Operations utilizes a customizable RBAC mechanism to support any required flexibility or strictness on access control and provides a default Master Admin account which belongs to the customer.

2 replies

Forum|alt.badge.img+5
  • Author
  • Bronze 5
  • Answer
  • July 25, 2024

Yes according to this: https://cloud.google.com/chronicle/docs/soar/cloud-architecture/access-control

Google Security Operations utilizes a customizable RBAC mechanism to support any required flexibility or strictness on access control and provides a default Master Admin account which belongs to the customer.


dnehoda
Staff
Forum|alt.badge.img+16
  • Staff
  • August 1, 2024

Yes according to this: https://cloud.google.com/chronicle/docs/soar/cloud-architecture/access-control

Google Security Operations utilizes a customizable RBAC mechanism to support any required flexibility or strictness on access control and provides a default Master Admin account which belongs to the customer.


Hi NC 

For RBAC and data RBAC this requires BYOID and workforce identity federation with a pool.