Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
A layered stack showing the Google Cloud shared responsibility model: bottom layers (physical data centers, hardware, hypervisor, network) are Google's security of the cloud, top layers (application configuration, IAM, data classification and access) are the customer's security in the cloud, with OS patching and runtime as a shared boundary that varies by IaaS, PaaS, or SaaS. Compliance certifications such as ISO 27001, SOC 1/2, and PCI-DSS verify both sides of this boundary.
A layered stack showing the Google Cloud shared responsibility model: Google is responsible for security of the cloud (physical data centers, hardware, hypervisor, and network), while the customer is responsible for security in the cloud (data, identity and access, applications, and configuration). Dashed boundary lines show how the split shifts across IaaS, PaaS, and SaaS service models, with compliance certifications attesting Google's layers and customer-configured controls covering the rest.
Google Cloud's shared responsibility model states that Google is responsible for the security of the cloud infrastructure, while the customer is responsible for security in the cloud, including their data, configurations, and access.
Key tools include configuring resources for data encryption, managing access with Identity and Access Management (IAM), and logging all activity with Cloud Audit Logs.
Google provides documentation and resources, such as the Compliance Reports Manager, to help customers validate that their use of Google Cloud meets the controls demanded by external standards.
Organizations using Google Cloud must follow specific rules, called regulatory and industry standards, which are often required by law or by their industry. Examples include rules for handling financial data (like PCI DSS), protecting health information (like HIPAA), or safeguarding personal data (like GDPR). Google Cloud provides a shared responsibility model for compliance: Google is responsible for the security of the cloud (the infrastructure), while the customer is responsible for security in the cloud (their data, configurations, and access). To support this, Google Cloud offers a wide range of compliance certifications for its services, which customers can rely on to build their own compliant environments.
A key part of adhering to standards is using the right GCP tools to implement the required security controls. This involves configuring resources properly, such as encrypting data at rest and in transit, managing access with Identity and Access Management (IAM), and logging all activity with Cloud Audit Logs. Customers must also understand which GCP services are in scope for a specific compliance standard, as not all services may be certified for every regulation. Google provides documentation and resources, like the Compliance Reports Manager, to help customers validate that their use of GCP meets the controls demanded by these external standards.