Control: Ensure that Cloud Storage buckets used for exporting logs are configured using bucket lock
Description
It is recommended that Cloud Storage buckets used for exporting logs are using bucket lock.
Usage
Run the control in your terminal:
powerpipe control run gcp_compliance.control.storage_bucket_log_retention_policy_lock_enabled
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run gcp_compliance.control.storage_bucket_log_retention_policy_lock_enabled --share
SQL
This control uses a named query:
storage_bucket_log_retention_policy_lock_enabled