# AQUILA CSPM - GCP Integration

##### <span style="color: rgb(53, 152, 219);">**Authentication**</span>

<span style="color: rgb(0, 0, 0);">To use this CSPM Google Cloud Platform (GCP) integration, you need to set up a ***Service Account*** with a ***Role*** and a ***Service Account Key*** to access data on your GCP project.</span>

##### <span style="color: rgb(53, 152, 219);">**1. Service Account**</span>

<span style="color: rgb(0, 0, 0);">First, you need to [create a Service Account](https://cloud.google.com/iam/docs/creating-managing-service-accounts). A Service Account (SA) is a particular type of Google account intended to represent a non-human user who needs to access the GCP resources.</span>

<span style="color: rgb(0, 0, 0);">The AQUILA Agent uses the SA to access data on Google Cloud Platform using the Google APIs.</span>

##### <span style="color: rgb(53, 152, 219);">**2. Required IAM Service Account Roles:**</span>

<span style="color: rgb(53, 152, 219);">**For CSPM-GCP Integration**</span>

- <span style="color: rgb(0, 0, 0);">**Browser**: This role grants read access to the project hierarchy.</span>
- <span style="color: rgb(0, 0, 0);">**Cloud Asset Viewer**: Can view asset metadata across GCP services.</span>

<span style="color: rgb(0, 0, 0);">Click here --&gt;</span> [GCP - How to Add a Role](https://docs.cytechint.io/books/system-integrations/page/gcp-how-to-add-a-role)

##### <span style="color: rgb(53, 152, 219);">**3. Enable API Services**</span>

- <span style="color: rgb(0, 0, 0);">**Cloud Asset API**: Provides metadata inventory and history of GCP resources and IAM policies for security analysis, audit, and compliance.</span>

<span style="color: rgb(0, 0, 0);">Click here --&gt; </span>[GCP - How to enable Cloud Asset API](https://docs.cytechint.io/books/system-integrations/page/gcp-how-to-enable-cloud-asset-api)

##### <span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW124724174 BCX0">4. Service Account Key </span></span><span class="EOP SCXW124724174 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}"> </span>**</span>

<span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW124724174 BCX0">Next, with the Service Account (SA) with access to Google Cloud Platform (GCP) resources setup, you need some credentials to associate with it: a Service Account Key. </span></span><span class="EOP SCXW124724174 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}"> </span></span>

<span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW124724174 BCX0">From the list of SA (Service Accounts): </span></span><span class="EOP SCXW124724174 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}"> </span></span>

<div class="ListContainerWrapper SCXW124724174 BCX0" id="bkmrk-go-to%C2%A0iam-%26-admin-%3E-">1. <span style="color: rgb(0, 0, 0);">Go to **IAM &amp; Admin &gt; Service Accounts** in the GCP Console.</span>
2. <span style="color: rgb(0, 0, 0);">Click the service account you created.</span>
3. <span style="color: rgb(0, 0, 0);">Under the **"Keys"** section, click **"Add Key" &gt; "Create new key"**.</span>
4. <span style="color: rgb(0, 0, 0);">Choose **JSON** as the key type.</span>
5. <span style="color: rgb(0, 0, 0);">**Download and securely store** the generated private key (it cannot be retrieved again from GCP if lost).</span>

</div>
<p class="callout danger">**<span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW124724174 BCX0">Please provide the following information to </span><span class="NormalTextRun SpellingErrorV2Themed SCXW124724174 BCX0">CyTech Support</span><span class="NormalTextRun SCXW124724174 BCX0">:</span></span><span class="EOP SCXW124724174 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}"> </span>**</p>

<div class="ListContainerWrapper SCXW124724174 BCX0" id="bkmrk-project-id%C2%A0---the-pr">- <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US">**<span class="NormalTextRun SCXW124724174 BCX0">Project </span>**<span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW124724174 BCX0">**ID** -</span> </span><span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW124724174 BCX0">The Project ID is the Google Cloud project ID where your resources exist. </span></span></span>
- <span style="color: rgb(0, 0, 0);"><span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW124724174 BCX0">**Credentials File** - </span></span><span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW124724174 BCX0">Save the JSON file with the private key in a secure location of the file system, and make sure that the Log Collector Agent has at least read-only privileges to this file.</span></span></span>

</div>#### <span style="color: rgb(53, 152, 219);">**How to integrate to AQUILA CSPM Module**</span>

##### <span style="color: rgb(53, 152, 219);">**Pre-requisites**</span>

1. <span style="color: rgb(0, 0, 0);">**Access to CyTech - AQUILA**</span>
    - <span style="color: rgb(0, 0, 0);">Only users assigned the **"Owner"** or **"Admin"** role can access the Log Collector installation resources within the platform.</span>

<p class="callout success">**To navigate to CSPM Module please follow the instructions below:**</p>

<div class="x_elementToProof" id="bkmrk-step1%3A-log-in-to-cyt">**<span style="color: rgb(0, 0, 0);">Step 1: Log in to CyTech - AQUILA. Click here --&gt;</span> [AQUILACYBER.ai](https://aquilacyber.ai/overview-v3/dashboard/maindashboard)**</div><div class="x_elementToProof" id="bkmrk-step2%3A-click-on-cybe"><span style="color: rgb(0, 0, 0);">**Step 2: Click on Cyber Monitoring.**</span></div>[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/hItzqzN09q61CMZZ-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/hItzqzN09q61CMZZ-image.png)

<span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" style="color: rgb(0, 0, 0);" xml:lang="EN-US"><span class="NormalTextRun SCXW124724174 BCX0">**Step 3: Choose Cloud Security Posture Management (CSPM).**</span></span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/EbsP1Kz74gmIWnyZ-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/EbsP1Kz74gmIWnyZ-image.png)

<span style="color: rgb(0, 0, 0);">**Step 4: Click the "Let's Go" or "Onboard CSPM" icon to launch installation window.**</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/h53Z6TJIUeSrsoc5-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/h53Z6TJIUeSrsoc5-image.png)

<span style="color: rgb(0, 0, 0);">**Step 5: Click "Let's go" to start the integration process.**</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/7DPNcbHQ3TI5nSmY-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/7DPNcbHQ3TI5nSmY-image.png)

<span style="color: rgb(0, 0, 0);">**Step 6: Choose your log collector. If you haven't installed a log collector yet choose "New Log Collector" click here --&gt;**</span> [Log Collector Installation](https://docs.cytechint.io/books/log-collector-installations). <span style="color: rgb(0, 0, 0);">**If you have already have an existing log collector choose "Current Log Collector" and click "Next".**</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/YmaKgMpQPUBQOutG-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/YmaKgMpQPUBQOutG-image.png)

<span style="color: rgb(0, 0, 0);">**Step 7: Click "Next" if the requirements are met.**</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/9XREDs3GMrovq966-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/9XREDs3GMrovq966-image.png)

<span style="color: rgb(0, 0, 0);">**Step 8: Choose your current log collector. This will collect the logs coming from your log sources.**</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/6JtsLkQBByfBwsLN-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/6JtsLkQBByfBwsLN-image.png)

<span style="color: rgb(0, 0, 0);">**Step 9: Choose Google Cloud Platform and click "Next" to proceed.**</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/IFKXnmI3U8F8BD8P-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/IFKXnmI3U8F8BD8P-image.png)

<span style="color: rgb(0, 0, 0);">**Step 10: Input all the required credentials from the previous GCP configurations and click "Next" to initiate the integration process. Wait for couple of minutes until a success window shows up.**</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/MmlY4HH1QBJ1g991-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/MmlY4HH1QBJ1g991-image.png)

<p class="callout info"><span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW124724174 BCX0">**<span style="color: rgb(224, 62, 45);">Please refer to this manual for the full guidelines of our CSPM Module. *click here--&gt;*</span> [CyTech - AQUILA CSPM Manual ](https://docs.cytechint.io/books/log-collector-installations/page/cytech-aquila-cloud-security-posture-management-cspm-module)**</span></span></p>

<span class="EOP SCXW124724174 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}">*If you need further assistance, kindly contact our support at **[support@cytechint.com](mailto:info@cytechint.com)** for prompt assistance and guidance.*</span>

<div class="ListContainerWrapper SCXW124724174 BCX0" id="bkmrk-go-to-iam-%26-admin-%3E-"></div>