MEDIUM
Source
CloudSploit
ID
disable-service-account-key-upload

Disable Service Account Key Upload

Determine if “Disable Service Account Key Upload” policy is enforced at the GCP organization level.

User-managed keys can impose a security risk if they are not handled correctly. To minimize the risk, enable user-managed keys in only specific locations.

Ensure that “Disable Service Account Key Upload” constraint is enforced at the organization level.