OAUTH-009: Service Account Key Enumeration

Platform
Google Workspace
Category
OAuth & API Security
Severity
High
Zero Trust pillar
Applications & Workloads (weight 1)
Golden fixtures
1
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Service account keys should be inventoried and rotated regularly. Leaked or stale keys provide persistent unauthorized access

Recommended value

All service account keys inventoried, rotated within 90 days, and unused keys removed

Remediation

Google Cloud Console > IAM & Admin > Service accounts > Review and rotate keys > Remove unused service account keys

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for OAUTH-009
ScenarioExpected verdict
always-warnWARN

Framework mappings

NIST SP 800-53
IA-5(1), AC-2(3)
CIS Benchmark
3.9
MITRE ATT&CK
T1078.004, T1552.004