sha3:89042110149eae1a1786ff03725ed99ffbaf6fbf9ded8606cb95f328a5a15df1IntactSecurity Command Center / Cloud Asset Inventory / Organization Policy
Google Cloud governance, organization through project.
PolicyCortex runs inside your Google Cloud organization and reads Security Command Center, Cloud Asset Inventory, Organization Policy, IAM, and audit logs, recording what the estate was, what changed it, and what machines were allowed to do, mapped to CMMC, NIST 800-171, SOC 2, PCI DSS, and ISO 27001. GCP support covers governance, remediation, and control-linked evidence, not an ATO workflow.
b1d7e176874a8711d1c5177cd3140d73e09e3e953780b0a2d63a03f846c92f43prev:794d0c9907e1What a Google Cloud estate must prove
Security Command Center reports findings for now; Cloud Asset Inventory reports state for now; Cloud Audit Logs record that something changed. The assessor asks about then: what was this bucket's access setting, this service account's roles, this organization policy constraint, as of the date they name, who or what changed it and under what authority, and what any automated fix was permitted to do before it ran.
Scope in Google Cloud is the resource hierarchy: which folders and projects sit inside the boundary, and whether what is outside it was unobserved or simply not connected.
- gcp.scope
- Organization through folder to project. The hierarchy is honored and the declared boundary is a field on every record.
- gcp.sources
- Security Command Center findings, Cloud Asset Inventory feeds, Organization Policy constraints, IAM, Cloud Audit Logs (Admin and Data Access). Read scope for the evaluation.
- gcp.regimes
- Assured Workloads regimes (IL4, IL5, FedRAMP High, ITAR) are recognized as boundary constraints and respected.
- gcp.limit
- GCP support covers governance, remediation, and control-linked evidence. It is not an ATO packaging workflow; AWS and Azure boundaries are supported for that.
7e3bddb99bc240c29c61945e806a95beb3dd0a9dd40333a33b1e520aecb659a9prev:b1d7e176874aThe evidence produced from your organization
Security Command Center is consumed, not replaced. The record adds what it does not ship: state as of any date, the authority behind each change, and the envelope around each action. Where each proof files:
- Asset Inventory · SCC
- Proof of state: asset feeds and findings captured as point-in-time records with the raw API response attached, content hashed, regenerable to any date.
- Cloud Audit Logs · IAM
- Proof of change: who or what altered a resource, under what authority, with before and after hashes and a rollback identifier. An audit log entry says it happened; the record says under whose authority.
- Remediation
- Proof of agency: approval-gated remediation through Cloud Functions or gcloud in Cloud Build, inside an envelope and in the trust mode you set. GATED is the default. Every action logs to Cloud Audit Logs with its rollback identifier.
- Organization Policy
- Constraints are honored; remediation works within them. A constraint change is a row in proof of change, not a surprise.
- Frameworks
- CMMC Level 2, NIST 800-171, SOC 2, PCI DSS, ISO 27001: one control mapping per record, written down, not implied.
018c69031bfded1ba65ee412452784d31fe03d5ae8faf511325df4e381f290f7prev:7e3bddb99bc2How the record is verified across the hierarchy
Across the organization the recomputation covers every connected folder and project as one chain, and Assured Workloads constraints are recorded as scope, so the boundary they impose is part of what recomputes.
Every record PolicyCortex writes for this obligation is content hashed with SHA3-256 and carries the digest of the record before it, so each line commits to the entire history above it. The log is append only: a correction is a new record, never an edit. Verification is a recomputation, not an assertion. Run the chain from the first record forward and it returns one of two answers: intact, or the sequence number of the first record that breaks.
A second party can do that recomputation without our help. The records, the digests, and the chain rule are everything required: no PolicyCortex account, no API of ours in the loop. When a collector was down or a scope was unobserved, the chain carries a declared gap with the interval and the reason, never silently fewer rows. Absence is declared, not inferred.
1ea0adc3885edb32d5f30368a7c89af4deb7a09d625668a2db3c87fb9f57e2b5prev:018c69031bfdHow you evaluate it in a Google Cloud organization
The fourteen days begin with a service account holding read scope at the organization; Security Command Center findings, Cloud Asset Inventory feeds, Organization Policy, IAM, and Cloud Audit Logs are read, nothing is written.
Connect read only for fourteen days, in SHADOW mode, inside your own tenant. Nothing executes. Policy evaluation, evidence collection, and action gating run where your data already is; there is no telemetry pipeline to PolicyCortex servers and no egress of evidence. At the end of the fourteen days you hold the records and can recompute the chain yourself.
- eval.mode
- SHADOW. Watch only; nothing executes.
- eval.duration
- Fourteen days.
- eval.location
- Your tenant. Azure, AWS, and GCP are observed clouds, including AWS GovCloud, Azure Government, and GCC High.
- eval.egress
- None. No telemetry pipeline to PolicyCortex servers; no evidence leaves the tenant.
- eval.after
- You keep the records. Licensing is annual and the tenant owns the evidence; a delivery engagement is optional.
7a7e71ddab919df7463e001b0421417db2a417e02601c17edf16098ec783c048prev:1ea0adc3885eDelivery, if you want the record stood up for you
Licensing does not depend on it, but a fixed-scope delivery engagement is available: thirty days, one agreed primary cloud environment, an evidence package built and defended through assessor review. The independent assessor makes the certification decision. No certification is guaranteed.
The standard engagement scope is a CMMC Level 2 package in one primary environment. A Google Cloud environment is scoped with you before work begins.
- engagement.scope
- Thirty days. One agreed primary cloud environment.
- engagement.outcome
- An evidence package built and defended through assessor review.
- engagement.limit
- The independent assessor decides. No certification is guaranteed.
89042110149eae1a1786ff03725ed99ffbaf6fbf9ded8606cb95f328a5a15df1prev:7a7e71ddab91Questions assessors and buyers ask
Are Assured Workloads supported?
Yes. Assured Workloads compliance regimes (IL4, IL5, FedRAMP High, ITAR) are recognized; PolicyCortex respects the boundary constraints they impose and records them as scope.
Does this replace Security Command Center?
No. SCC findings are consumed and recorded; PolicyCortex adds cross-framework mapping, gated remediation, and a hash-chained record of state as of any date. Existing SCC investment is preserved.
Multiple organizations?
Yes. Multiple Google Cloud organizations can be onboarded under one PolicyCortex tenant, with isolation enforced at the IAM layer and recorded as separate scopes.
How does remediation execute?
Through Cloud Functions invoking the GCP API, or gcloud commands in Cloud Build, inside an autonomy envelope and in the trust mode you set. GATED is the default: a named human approves each action and becomes part of its record. Every action logs to Cloud Audit Logs with a rollback identifier.
Does GCP get an ATO package?
No. GCP support covers governance, remediation, and control-linked evidence. ATO packaging (SSP, SAR, POA&M, OSCAL, eMASS) is supported for AWS and Azure boundaries.
What happens when a collector is down?
The chain carries a declared gap: the stream, the interval, the reason, and when it was declared. Evidence never silently has fewer rows.
Connect an organization read only. Recompute what you see.