Risk Level: High (not acceptable risk)
Rule ID: VertexAI-002
Ensure that the root access to your Google Cloud Vertex AI notebook instances is disabled in order to reduce the risk of accidental or malicious system damage by limiting administrative privileges within the instances.
Disabling root access to your Google Cloud Vertex AI notebook instances minimizes the risk of unauthorized modifications, enhances security by preventing potential misuse or exploitation of superuser privileges, and helps maintain a more controlled and secure AI environment.
Audit
To determine if your Vertex AI notebook instances are configured to prevent root access, perform the following operations:
Remediation / Resolution
To ensure that root access is disabled for your Google Cloud Vertex AI notebook instances, perform the following operations:
References
- Google Cloud Platform (GCP) Documentation
- Introduction to Vertex AI Workbench
- Manage features through metadata
- Access control
- GCP Command Line Interface (CLI) Documentation
- gcloud projects list
- gcloud workbench instances list
- gcloud workbench instances describe
- gcloud workbench instances stop
- gcloud workbench instances update
- gcloud workbench instances start
Publication date Jul 8, 2024