GCP Baseline
Two-week hardening sprint: org model, org policies, logging/KMS, IAM cleanup plan, and a 12‑week roadmap—with quick‑wins implemented.
What’s included
- Org & folder layout, environment separation
- Org Policies baseline (restricted APIs, CMEK required where fit)
- Centralised logging & sinks to SIEM or BQ
- KMS/CMEK plan & initial keys
- IAM inventory & cleanup plan
- 12‑week hardening roadmap
Outcomes
- Predictable project layout with safer defaults
- Consistent logging & retention
- Fewer wildcard roles and risky service accounts
- Clarity on what to tackle next
How it works
- Discovery & inventory
- Design & policy set
- Implement quick‑wins
- Handover & roadmap