Skip to main content

Hi,

When projects in GCP are in shut-down state, will Security Command Center remove all project-related vulnerabilities (vulnerabilities for all resources within the project)?

As far as I see, non of them is removed, vulnerabilities still remain.

Should we wait for 30-day period for the projects to be deleted, after which vulnerabilities will be automatically removed? Or will we have to mark them one-by-one with security marks?

Thanks in advance for an answer.

Best Regards,

SBG

Hey @SevenBridges thanks for the question. Apologies for taking so long to get back to you here, we just wanted to make sure we get you the correct answer!
 
As it stands, SHA misconfigurations should be automatically removed, but only if the project is deleted versus still provisioned and shut down. Threats will remain active until manually addressed by the client since deleting a project does not necessarily fully address the issue of a threat actor that may have been active; the actor may have moved on to other projects and you can't tell until you manually investigate. 
 
Does this help? Let me know!
 
-Nick