Skip to content
Back to skills

Cis Gcp Foundations 7.1

ASecurity

Ensure That BigQuery Datasets Are Not Anonymously or Publicly Accessible

  • 2,182 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 3, 2026
securitygobashgcp

Works with

  • cli

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add CyberStrikeus/CyberStrike --skill cis-gcp-foundations-7.1 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cis Gcp Foundations 7.1?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cis Gcp Foundations 7.1
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/cyberstrikeus-cis-gcp-foundations-7-1/badge)](https://www.skillsdirectory.com/skills/cyberstrikeus-cis-gcp-foundations-7-1)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cis-gcp-foundations-7.1
description: "Ensure That BigQuery Datasets Are Not Anonymously or Publicly Accessible"
category: cis-gcp-foundations
version: "4.0.0"
author: cyberstrike-official
tags: [cis, gcp, bigquery, encryption, cmek]
cis_id: "7.1"
cis_benchmark: "CIS Google Cloud Platform Foundation Benchmark v4.0.0"
tech_stack: [gcp]
cwe_ids: []
chains_with: []
prerequisites: []
severity_boost: {}
---

# 7.1 Ensure That BigQuery Datasets Are Not Anonymously or Publicly Accessible (Automated)

## Profile Applicability

- Level 1

## Description

It is recommended that the IAM policy on BigQuery datasets does not allow anonymous and/or public access.

## Rationale

Granting permissions to `allUsers` or `allAuthenticatedUsers` allows anyone to access the dataset. Such access might not be desirable if sensitive data is being stored in the dataset. Therefore, ensure that anonymous and/or public access to a dataset is not allowed.

## Impact

The dataset is not publicly accessible. Explicit modification of IAM privileges would be necessary to make them publicly accessible.

## Audit

### From Google Cloud Console

1. Go to `BigQuery` by visiting: https://console.cloud.google.com/bigquery.
2. Select a dataset from `Resources`.
3. Click `SHARING` near the right side of the window and select `Permissions`.
4. Validate that none of the attached roles contain `allUsers` or `allAuthenticatedUsers`.

### From Google Cloud CLI

List the name of all datasets.

```bash
bq ls
```

Retrieve each dataset details using the following command:

```bash
bq show PROJECT_ID:DATASET_NAME
```

Ensure that `allUsers` and `allAuthenticatedUsers` have not been granted access to the dataset.

## Remediation

### From Google Cloud Console

1. Go to `BigQuery` by visiting: https://console.cloud.google.com/bigquery.
2. Select the dataset from 'Resources'.
3. Click `SHARING` near the right side of the window and select `Permissions`.
4. Review each attached role.
5. Click the delete icon for each member `allUsers` or `allAuthenticatedUsers`. On the popup click `Remove`.

### From Google Cloud CLI

List the name of all datasets.

```bash
bq ls
```

Retrieve the data set details:

```bash
bq show --format=prettyjson PROJECT_ID:DATASET_NAME > PATH_TO_FILE
```

In the access section of the JSON file, update the dataset information to remove all roles containing `allUsers` or `allAuthenticatedUsers`.

Update the dataset:

```bash
bq update --source PATH_TO_FILE PROJECT_ID:DATASET_NAME
```

## Prevention

You can prevent Bigquery dataset from becoming publicly accessible by setting up the `Domain restricted sharing` organization policy at: https://console.cloud.google.com/iam-admin/orgpolicies/iam-allowedPolicyMemberDomains.

## Default Value

By default, BigQuery datasets are not publicly accessible.

## References

1. https://cloud.google.com/bigquery/docs/dataset-access-controls

## CIS Controls

| Controls Version | Control                                               | IG 1 | IG 2 | IG 3 |
| ---------------- | ----------------------------------------------------- | ---- | ---- | ---- |
| v8               | 3.3 Configure Data Access Control Lists               | X    | X    | X    |
| v7               | 14.6 Protect Information through Access Control Lists | X    | X    | X    |

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…