MEDIUM
Source
CloudSploit
ID
disable-service-account-key-creation

Disable Service Account Key Creation

Determine if “Disable Service Account Key Creation” policy is enforced at the GCP organization level.

User-managed keys can impose a security risk if they are not handled correctly. To minimize the risk, enable user-managed keys in only specific locations.

Ensure that “Disable Service Account Key Creation” constraint is enforced at the organization level.