| name | google-cloud-waf-security |
| description | Generates security-focused guidance for Google Cloud workloads based on the Google Cloud Well-Architected Framework (WAF). Use to evaluate a workload, identify security requirements, and provide actionable recommendations for IAM, network security, data protection, and operational security. |
| source | google/skills (Apache 2.0) |
Google Cloud Well-Architected Framework skill for the Security pillar
Overview
The security pillar of the Google Cloud Well-Architected Framework provides
design principles and best practices for building a robust security posture by
integrating security into every layer of the architecture for cloud workloads.
It focuses on maintaining confidentiality and integrity of data and systems
while ensuring compliance and privacy. It provides a structured approach to risk
management, threat defense, and identity control, enabling you to operate cloud
workloads securely and at scale.
Core principles
The recommendations in the security pillar of the Well-Architected Framework are
aligned with the following core principles:
-
Implement security by design: Integrate cloud security and network
security considerations starting from the initial design phase of your
applications and infrastructure. Google Cloud provides architecture
blueprints and recommendations to help you apply this principle. Grounding
document:
https://docs.cloud.google.com/architecture/framework/security/implement-security-by-design
-
Implement zero trust: Use a never trust, always verify approach, where
access to resources is granted based on continuous verification of trust.
Google Cloud supports this principle through products like Chrome Enterprise
Premium and Identity-Aware Proxy (IAP). Grounding document: