Skip to main content

More Info:

The default timeout for Cloud Functions should be configured

Risk Level

Low

Address

Operational Maturity, Reliability, Security

Compliance Standards

  • APRA CPS 234 (Australia)
  • BSI C5 (Germany)
  • Brazil LGPD
  • CCPA / CPRA (California)
  • CIS Critical Security Controls v8
  • CMMC 2.0
  • CSA Cloud Controls Matrix v4
  • Cloudanix Best Practice
  • DPDPA
  • Digital Operational Resilience Act (EU)
  • Essential 8
  • ISO/IEC 27017
  • ISO/IEC 27018
  • ISO/IEC 27701
  • KSA PDPL
  • MAS Technology Risk Management (Singapore)
  • MITRE ATT&CK (Cloud)
  • NIS2 Directive
  • NIST SP 800-171
  • NYDFS 23 NYCRR 500
  • SWIFT Customer Security Controls Framework
  • Sarbanes-Oxley IT General Controls
  • UK NCSC Cyber Assessment Framework

Triage and Remediation

Remediation

Using Console

Sure, I can help you with that. Here are the step-by-step instructions to remediate the misconfiguration “Cloud Functions Should Have Default Timeout Configured” for GCP using GCP console:
  1. Open the GCP Console and navigate to the Cloud Functions page.
  2. Find the function that you want to remediate and click on its name.
  3. In the left-hand menu, click on the “Edit” button.
  4. Scroll down to the “Runtime, build, and connections settings” section.
  5. Under the “General” tab, locate the “Timeout” field.
  6. Set a default timeout value for your function. The recommended timeout value is 60 seconds.
  7. Click on the “Save” button to save your changes.
That’s it! You have now successfully remediated the misconfiguration “Cloud Functions Should Have Default Timeout Configured” for GCP using GCP console.

To remediate the misconfiguration “Cloud Functions Should Have Default Timeout Configured” for GCP using GCP CLI, follow these steps:
  1. Open the GCP Cloud Shell or any terminal with GCP CLI installed.
  2. Run the following command to set the default timeout for Cloud Functions:
    Replace FUNCTION_NAME with the name of the Cloud Function that you want to remediate and TIMEOUT with the desired timeout value in seconds. For example, to set the default timeout to 60 seconds for a Cloud Function named my-function, run the following command:
  3. After running the command, the Cloud Function will be redeployed with the default timeout set to the specified value.
  4. Verify that the default timeout has been set by checking the Cloud Function’s configuration using the following command:
    Replace FUNCTION_NAME with the name of the Cloud Function that you remediated. The output of the command will include the timeout field, which should match the value that you set in step 2.
By following these steps, you have successfully remediated the misconfiguration “Cloud Functions Should Have Default Timeout Configured” for GCP using GCP CLI.
To remediate the misconfiguration “Cloud Functions Should Have Default Timeout Configured” for GCP using Python, you can follow these steps:
  1. Open the Cloud Functions page in the GCP console.
  2. Select the function that you want to configure.
  3. In the function details page, click on the “Edit” button.
  4. Scroll down to the “Advanced Options” section.
  5. In the “Timeout” field, set the default timeout for your function. You can set the timeout value in seconds, up to a maximum of 540 seconds (9 minutes).
  6. Click on the “Save” button to save your changes.
  7. To automate this process for multiple functions, you can use the GCP Python SDK. Here’s an example code snippet to set the default timeout for a Cloud Function using the Python SDK:
Note: Before running the above code, make sure that you have installed the google-cloud-functions Python package and authenticated with your GCP account using the gcloud CLI or a service account key file.
Changing timeout on google_cloudfunctions_function is an in-place update and does not force resource replacement.For verification, terraform plan should show an update to the existing google_cloudfunctions_function with timeout changing from null (or the old value) to your specified value (e.g. "60s").

Additional Reading: