Security Health Analytics automatically scans Google Cloud resources for misconfigurations and security vulnerabilities. For new activations, Google now points to Compliance Manager as the successor.
What is Security Health Analytics?
Security Health Analytics is a service within Security Command Center that continuously scans Google Cloud resources for security issues. It identifies common misconfigurations such as publicly accessible storage buckets, overly permissive firewall rules, missing encryption, or insecure IAM permissions.
The detectors are based on Google best practices and are mapped to industry standards such as CIS Benchmarks, PCI DSS, ISO 27001, and NIST 800-53. Each finding includes a problem description, affected resources, and specific remediation steps, prioritized by severity.
Important note: For organizations newly activating Security Command Center (Standard, Premium, or Enterprise tier), Security Health Analytics is no longer available. Google instead recommends Compliance Manager with the Security Essentials framework, along with Vulnerability Assessment for Google Cloud, to detect misconfigurations and vulnerabilities. Existing Security Health Analytics activations continue to work.
Core Features
- Automatic, continuous scans for misconfigurations
- Detectors for Compute Engine, Cloud Storage, BigQuery, Cloud SQL, GKE, IAM, and network configurations
- Mapping of findings to compliance frameworks for reporting
- Prioritization of findings by severity with remediation recommendations
- Custom detectors in higher tiers for organization-specific policies
Typical Use Cases
Continuous security posture management
Automatically scanning new deployments and immediately reporting misconfigurations to the security team.
Compliance verification for existing activations
Organizations with running Security Health Analytics activations use the compliance mapping to document security status for audits.
Pre-production security gate
Integration into CI/CD pipelines so new resources are automatically checked before production deployment.
Multi-project security baseline
Centralized, cross-project security verification for organizations with many Google Cloud projects.
Benefits
- Integrated into Security Command Center, no separate deployment needed
- Automatic detection of new resources within a short time
- Mapping to common compliance frameworks simplifies audits
Integration with innFactory
As a certified Google Cloud partner, innFactory supports you with Security Health Analytics and with migrating to Compliance Manager: configuration, custom detectors, remediation workflows, and compliance implementation.
Contact us for a consultation on Security Health Analytics, Compliance Manager, and Google Cloud security.
Available Tiers & Options
Standard
- Included free with SCC Standard
- Basic misconfiguration detection
- Automatic scans
- Superseded by Compliance Manager for new activations
Premium
- Extensive detector catalog
- Compliance mapping (CIS Benchmark, PCI DSS, ISO 27001, NIST 800-53)
- Custom detectors
- Superseded by Compliance Manager for new activations
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What is Security Health Analytics?
Security Health Analytics is a service within Security Command Center that automatically scans Google Cloud resources for misconfigurations and security vulnerabilities, such as public buckets, open firewall rules, or missing encryption.
Is Security Health Analytics still current?
For existing activations, Security Health Analytics continues to work. For newly activated organizations on the Standard, Premium, and Enterprise tiers, Google now recommends Compliance Manager with the Security Essentials framework and Vulnerability Assessment for Google Cloud as the successor.
What is the difference between Security Health Analytics and Compliance Manager?
Compliance Manager combines misconfiguration and vulnerability detection in a framework-based approach mapped to standards like CIS Benchmark, ISO 27001, NIST 800-53, and PCI DSS. It replaces Security Health Analytics for new Security Command Center activations.
Which resources are scanned?
Security Health Analytics checks Compute Engine, Cloud Storage, BigQuery, Cloud SQL, GKE, IAM, and network configurations, among others. New resources are automatically included in scans.
Can I create custom detectors?
With Security Command Center Premium or Enterprise, you can define custom detectors that check organization-specific policies.
How are findings prioritized?
Findings are categorized by severity (Critical, High, Medium, Low) and include a problem description, affected resources, and specific remediation steps.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.
