| name | google-cloud-waf-security |
| metadata | {"category":"WellArchitectedFramework"} |
| description | Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF). Use this skill to evaluate workloads, identify security requirements, and provide actionable recommendations for IAM, network security, data protection, and operational security. |
Google Cloud Well-Architected Framework skill for the Security pillar
Overview
The security pillar of the Google Cloud Well-Architected Framework provides
design principles and best practices for building a robust security posture by
integrating security into every layer of the architecture for cloud workloads.
It focuses on maintaining confidentiality and integrity of data and systems
while ensuring compliance and privacy. It provides a structured approach to risk
management, threat defense, and identity control, enabling you to operate cloud
workloads securely and at scale.
Workflow
When this skill is activated, follow these steps to evaluate and improve the
security posture of the specified Google Cloud workload:
- Understand the context: Ask targeted questions from the Workload
assessment questions list to gather information about the user's current
architecture, security requirements, and constraints.
- Analyze and identify gaps: Evaluate the workload against the Core
principles and the Validation checklist to identify security
vulnerabilities, missing controls, or deviations from best practices.
- Formulate recommendations: Provide actionable, prioritized guidance
based on the Google Cloud Well-Architected Framework. Recommend specific
products from Relevant Google Cloud products to address the identified
gaps.
- Explain the recommendations: Align all recommendations with the
appropriate Core principles and state the benefits that each
recommendation provides.
- Iterate and refine: Help the user adapt the recommendations to their
specific requirements and constraints.
Core principles
The recommendations in the security pillar of the Well-Architected Framework are
aligned with the following core principles:
Relevant Google Cloud products
The following are examples of Google Cloud products and features that are
relevant to security:
-
Identity and access management
- Cloud Identity: Manage user lifecycles, authentication, and identity
federation.
- Identity and Access Management (IAM): Fine-grained access control for
Google Cloud resources.
- Identity-Aware Proxy (IAP): Secure access to applications without a VPN.
- Chrome Enterprise Premium: Endpoint security and context-aware access.
- IAM Recommender: Provide policy intelligence.
-
Network security
- Google Cloud Armor: DDoS protection and Web Application Firewall (WAF).
- VPC Service Controls: Define security perimeters to prevent data
exfiltration.
- Cloud Next-Generation Firewall (NGFW): Advanced threat protection for
network traffic.
- Shared VPC: Centralized network management across projects.
- Cloud Interconnect and IPsec VPN: Secure, private connectivity.
-Private Service Connect: Provide private access to managed services
-
Data security
- Cloud Key Management Service (KMS): Manage encryption keys.
- Sensitive Data Protection (formerly Cloud DLP): Discover and redact
sensitive data.
- Confidential Computing: Encrypt data in use (memory).
-
Security operations (SecOps)
- Google SecOps (Chronicle): Threat detection and security analytics.
- Security Command Center (SCC): Centralized vulnerability and threat
management.
- Cloud Logging and Cloud Monitoring: Visibility into system activity.
- BigQuery: Storing exported logs for analysis.
-
Automation and supply chain
- Cloud Build: Secure CI/CD pipelines.
- Artifact Analysis: Vulnerability scanning for container images.
- Binary Authorization: Deploy-time policy enforcement.
- Assured open source software: Use secured OSS packages.
Workload assessment questions
Ask appropriate questions to understand the security-related requirements and
constraints of the workload and the user's organization. Choose questions from
the following list:
-
Security by design:
- How do you incorporate security considerations into your project's initial
planning and design phases?
- How do you define and document security requirements for new applications
and services?
- How do you ensure that security is integrated into your development
lifecycle?
- What tools and techniques do you use to perform threat modeling during the
design phase?
- How do you manage and prioritize security vulnerabilities discovered during
the design and development process?
- How do you handle security updates and patches for your applications and
infrastructure?
- How do you document and communicate security design decisions to your team
and stakeholders?
- How do you ensure that security configurations are consistently applied
across your environments?
- How do you validate the effectiveness of your security controls and
measures?
- How do you handle security exceptions and deviations from your security
design?
-
Zero trust:
- How do you verify and authenticate users and devices accessing your Google
Cloud resources?
- How do you implement the principle of least privilege for access control?
- How do you monitor and control network traffic within your Google Cloud
environment?
- How do you secure data in transit and at rest in your Google Cloud
environment?
- How do you implement continuous monitoring and logging of user and device
activity?
- How do you handle and respond to security incidents and breaches in a Zero
Trust environment?
- How do you manage and update security policies and controls in a Zero Trust
environment?
- How do you ensure that third-party applications and services comply with
your Zero Trust principles?
- How do you handle remote access and BYOD devices in a Zero Trust
environment?
- How do you educate and train your employees on Zero Trust principles and
practices?
-
Shift-left security:
- How do you integrate security testing into your development pipeline early
in the process?
- What types of security testing do you perform during the development phase?
- How do you provide developers with feedback on security vulnerabilities and
best practices?
- How do you empower developers to take ownership of security in their code?
- How do you ensure that security requirements are clearly defined and
communicated to developers?
- How do you measure the effectiveness of your Shift Left security
initiatives?
- How do you handle security dependencies and third-party libraries in your
code?
Validation checklist
Use the following checklist to evaluate the architecture's alignment with
security recommendations: