name:pgAudit Flags Not Enabled for PostgreSQL Instances in Cloud SQL
author:princechaddha
severity:medium
description:|
Ensure that the "cloudsql.enable_pgaudit" and "pgaudit.log" database flags are enabled for your Google Cloud PostgreSQL server instances to enable database auditing. These configurations are crucial for compliance with government, financial, and ISO certifications.
impact:|
Without pgAudit and log configurations, critical database activities may go unmonitored, potentially leading to non-compliance with regulatory standards and increasing the risk of security incidents.
remediation:|
Configure your PostgreSQL instances with the "cloudsql.enable_pgaudit" flag set to "on" and the "pgaudit.log" flag set to "all". These settings enable enhanced auditing capabilities.