github.com/khulnasoft-lab/defsec@v1.0.5-0.20230827010352-5e9f46893d95/avd_docs/google/platform/AVD-GCP-0007/docs.md (about)

     1  
     2  Service accounts should have a minimal set of permissions assigned in order to do their job. They should never have excessive access as if compromised, an attacker can escalate privileges and take over the entire account.
     3  
     4  ### Impact
     5  Cloud account takeover if a resource using a service account is compromised
     6  
     7  <!-- DO NOT CHANGE -->
     8  {{ remediationActions }}
     9  
    10  ### Links
    11  - https://cloud.google.com/iam/docs/understanding-roles
    12