Google Cloud Security Command Center (SCC) and Chronicle (Google Security Operations)
by Google Cloud
SCC is Google Cloud’s security posture and threat detection service; Chronicle is the cloud-native SIEM, now named Google Security Operations (Google SecOps).
Naming
Per Google’s docs, “Google Security Operations (formerly Chronicle)” is a cloud-native SIEM; “Google SecOps” is the shorthand and “Google Unified Security” the wider ecosystem. Videos still say “Chronicle”.
Security Command Center (tiers as of 2026-10-05)
- Standard: free activation; basic posture and compliance management for Google Cloud only (limited Security Health Analytics, Web Security Scanner custom scans).
- Premium: adds attack-path simulation, toxic-combination detection, full threat detection (Event, Container, Cloud Run, VM) and compliance monitoring, for Google Cloud only; pay-as-you-go or subscription billing.
- Enterprise: multicloud CNAPP (Google Cloud, AWS, Azure) integrated with Google SecOps. The docs mark this tier as deprecated and shutting down on 2027-05-21, with existing customers migrated to Premium.
- Findings can be exported to BigQuery and Sub to trigger remediation with Cloud Run functions.
Google Security Operations (Chronicle)
- Lifecycle per docs: collect (1,000+ sources via forwarders, API connectors, webhooks), detect (threat intelligence and YARA-L rules), investigate (case management, entity context), respond (playbook automation with AI-agent integration), manage (content hub, dashboards).
- Gemini integration provides in-product help; licensing uses “Google SecOps packages” and Security Tokens (details not on the fetched page).
- Combines SIEM and SOAR.
Wiz
Google completed its $32 billion all-cash acquisition of cloud security company Wiz on 2026-03-11 (Google press corner, Alphabet IR, TechCrunch); Wiz keeps its brand and supports all major clouds. How Wiz and SCC will be positioned relative to each other was not checked. See alphabet.
How they fit (author’s summary, opinion)
SCC: posture, vulnerabilities, cloud-native detections. SecOps: telemetry analytics, hunting and retention across cloud and on-prem. Feed SCC findings into SecOps for correlation.
Billing model
SCC: free Standard, Premium by pay-as-you-go or subscription. SecOps: package/licence based. See https://cloud.google.com/security-command-center/pricing and the SecOps pricing page; no amounts recorded.
Sources
- SCC tiers: https://docs.cloud.google.com/security-command-center/docs/service-tiers (fetched 2026-10-05)
- SecOps overview: https://docs.cloud.google.com/chronicle/docs/overview (fetched 2026-10-05)
- Wiz completion: https://www.googlecloudpresscorner.com/2026-03-11-Google-Completes-Acquisition-of-Wiz and https://techcrunch.com/2026/03/11/google-completes-32b-acquisition-of-wiz (from search results 2026-10-05)
Open items
- Earlier claims (Forseti integration, Cloud Security Scanner naming, Chronicle “petabyte” retention) were removed as unverified.
- SecOps 2026 AI-agent features not detailed.