Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

Vulnerability Scan Authorization for Google Compute

What is the official and required process to perform our own independent vulnerability scans against virtual machines in the Google Compute Engine? These will be Penetration tests (our own) that will scan the public IP for open ports and report results back to us.

Microsoft Azure requires authorization and so does Amazon. Does Google?

like image 630
OBSInfrastructureSvcs Avatar asked May 02 '26 05:05

OBSInfrastructureSvcs


1 Answers

No, Google does not need to be notified before you run a security scan on your Google Compute Engine projects. You will have to abide by Google Cloud Platform Acceptable Use Policy and the Terms of Service.

Please also be aware of Google's Vulnerability Rewards Program Rules.

like image 91
Misha Brukman Avatar answered May 04 '26 20:05

Misha Brukman



Donate For Us

If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!