Authentication

Project with API keys

Platform(s)
Compliance Frameworks

Brazilian General Data Protection (LGPD), CCM-CSA, CCPA, CPRA, Data Security Posture Management (DSPM) Best Practices, GCP CIS, GDPR, HITRUST, iso_27001_2022, iso_27002_2022, Mitre ATT&CK, mpa, New Zealand Information Security Manual, NIST 800-171, NIST 800-53, PDPA, UK Cyber Essentials

Description

API keys are used for authentication, they are simple encrypted strings that identify an application without any principal. Project '{CloudAccount}' is using API keys - {CloudAccount.GcpApiKey}. API keys are insecure because they can be viewed publicly, such as from within a browser, or they can be accessed on a device where the key resides. It is recommended to not use API keys in order to avoid these security risks