2 Securing communications and establishing boundary protection
22%
- 2.1Designing and configuring perimeter security
Configuring network perimeter controls (e.g., Cloud Next Generation Firewall [Cloud NGFW] rules and policies, Identity-Aware Proxy [IAP], load balancers, and Certificate Authority Service); Setting up application layer inspection on Cloud NGFW (e.g., layer 7); Differentiating between private and public IP addressing; Configuring web application firewalls (e.g., Google Cloud Armor); Deploying Secure Web Proxy; Configuring Cloud DNS security settings; Continually monitoring and restricting configured APIs
- 2.2Configuring boundary segmentation
Configuring security properties of a VPC network, VPC peering, Shared VPC, and firewall rules; Configuring network isolation and data encapsulation for N-tier applications; Identifying use cases and configuring VPC Service Controls
- 2.3Establishing private connectivity
Designing and configuring private connectivity between VPC networks and Google Cloud projects (Shared VPC, VPC peering, and Private Google Access for on-premises hosts); Designing and configuring private connectivity and encryption between data centers and VPC network (e.g., HA VPN, Cloud Interconnect); Establishing private connectivity between VPC and Google APIs (Private Google Access, Private Google Access for on-premises hosts, restricted Google access, Private Service Connect); Using Cloud NAT to enable outbound traffic
3 Ensuring data protection
23%
- 3.1Protecting sensitive data and preventing data loss
Configuring Sensitive Data Protection (SDP) (e.g., discovering and redacting personally identifiable information (PII), configuring pseudonymization and format preserving encryption); Restricting access to Google Cloud data services (e.g., BigQuery, Cloud Storage, and Cloud SQL datastores); Securing secrets with Secret Manager; Protecting and managing compute instance metadata
- 3.2Managing encryption at rest, in transit, and in use
Identifying use cases for Google default encryption, customer-managed encryption keys (CMEK), and Cloud External Key Manager (EKM); Determining when to use software and hardware keys; Creating and managing encryption keys for CMEK and EKM (e.g., key rotation and revocation, key import); Applying encryption methods to various use cases; Configuring object lifecycle policies for Cloud Storage; Enabling Confidential Computing
- 3.3Securing AI workloads
Implementing security and privacy controls for AI/ML systems to protect against unintentional exploitation of data or models; Determining security requirements for IaaS-hosted and PaaS-hosted training models; Implementing security controls for Vertex AI
4 Managing operations
19%
- 4.1Automating infrastructure and application security
Automating security scanning for Common Vulnerabilities and Exposures (CVEs) through a continuous integration and delivery (CI/CD) pipeline; Configuring Binary Authorization to secure GKE clusters or Cloud Run; Automating virtual machine and container image creation (e.g., hardening, maintenance, VM patch management); Managing policy and drift detection at scale (e.g., cloud security posture management, custom organization policies and custom modules for Security Health Analytics)
- 4.2Configuring logging, monitoring, and detection
Configuring and analyzing network logs (Cloud Next Generation Firewall [Cloud NGFW], VPC flow logs, Packet Mirroring, Cloud Intrusion Detection System [Cloud IDS], Log Analytics); Designing an effective logging strategy; Logging, monitoring, responding to, and remediating security incidents; Designing secure access to logs; Exporting logs to external security systems; Configuring and analyzing Google Cloud Audit Logs and data access logs; Configuring log exports (log sinks and aggregated sinks); Configuring and monitoring Security Command Center
5 Supporting compliance requirements
11%
- 5.1Adhering to regulatory and industry standards requirements for the cloud
Determining technical needs relative to compute, data, network, and storage; Evaluating the shared responsibility model; Configuring security controls within cloud environments to support compliance requirements (e.g., Assured Workloads, organizational policies, Access Transparency, Access Approval, regionalization of data and services); Determining the Google Cloud environment in scope for regulatory compliance; Mapping compliance requirements to Google Cloud services and security controls (e.g., network and access segmentation, audit log coverage)