オプション
家 Skill 安全 google-cloud-waf-security

google-cloud-waf-security

google/skills google/skills

Google Cloudのワークロードを「Well-Architected Framework」のセキュリティの柱に基づいて評価し、セキュリティ要件を特定するとともに、IAM、ネットワークセキュリティ、データ保護、および運用セキュリティに関する実践的な推奨事項を提供します。

...すべて拡張します
11
更新された時間 2026年9月4日

Google Cloud Well-Architected Framework の「セキュリティ」分野に関するスキル

概要

Google Cloud Well-Architected Framework の「セキュリティ」ピラーは、 クラウドワークロードのアーキテクチャのあらゆる層にセキュリティを統合することで、 強固なセキュリティ体制を構築するための設計原則とベストプラクティスを提供します。 データの機密性と完全性、およびシステムの機密性と完全性を維持しつつ、 コンプライアンスとプライバシーを確保することに重点を置いています。また、リスク 管理、脅威防御、およびID管理に対する体系的なアプローチを提供し、クラウド ワークロードを安全かつ大規模に運用できるようにします。

基本原則

Well-Architected Framework のセキュリティピラーにおける推奨事項は、 以下の基本原則に沿ったものです。

  • セキュリティ・バイ・デザインの実践:アプリケーションおよび インフラストラクチャの初期設計段階から、クラウドセキュリティとネットワーク セキュリティの考慮事項を組み込みます。Google Cloud では、この原則を 適用するためのアーキテクチャ・ブループリントや推奨事項を提供しています。 基本ドキュメント: https://docs.cloud.google.com/architecture/framework/security/implement-security-by-design.md.txt

  • ゼロトラストの実装:「決して信頼せず、常に検証する」というアプローチを採用し、 信頼性の継続的な検証に基づいてリソースへのアクセスを許可します。 Google Cloud は、Chrome Enterprise Premium や Identity-Aware Proxy (IAP) などの製品を通じて、この原則をサポートしています。参考資料: https://docs.cloud.google.com/architecture/framework/security/implement-zero-trust.md.txt

  • シフトレフトセキュリティの実装:ソフトウェア開発ライフサイクルの 早い段階でセキュリティ対策を実施します。システムの変更が行われる前に セキュリティ上の欠陥を回避します。システムの変更がコミットされた後は、 セキュリティ上のバグを早期に、迅速かつ確実に検出して修正します。Google Cloud は、 Cloud Build、Binary Authorization、Artifact Registry などの製品を通じて、この原則をサポートしています。 参考資料: https://docs.cloud.google.com/architecture/framework/security/implement-shift-left-security.md.txt

  • 先制的なサイバー防御の実施:脅威インテリジェンスなどの 堅牢な基礎的対策を導入することで、セキュリティに対する 積極的なアプローチを採用します。このアプローチにより、より効果的な 脅威の検出と対応のための基盤を構築できます。Google Cloudの多層的なセキュリティ 対策のアプローチは、この原則に沿ったものです。 Google Cloud は、Security Command Center、Google Threat Intelligence、 Google SecOps などの製品を通じて、この原則をサポートしています。 参考資料: https://docs.cloud.google.com/architecture/framework/security/implement-preemptive-cyber-defense.md.txt

  • AI を安全かつ責任を持って活用する:責任ある安全な方法で AI システムを 開発・導入します。この原則に関する推奨事項は、 Well-Architected Framework の AI および ML の観点、 ならびに Google の Secure AI Framework (SAIF) に示されたガイダンスと 整合しています。根拠となる文書: https://docs.cloud.google.com/architecture/framework/security/use-ai-securely-and-responsibly.md.txt

  • セキュリティのためのAIの活用:AI機能を活用し、 「Gemini in Security」およびプラットフォーム全体の セキュリティ機能を通じて、既存のセキュリティシステムやプロセスを改善します。AIをツールとして活用し、 是正作業の自動化を促進し、セキュリティ衛生管理を確保することで、他のシステムの セキュリティを強化します。Google Cloudは、Google Threat IntelligenceやGoogle SecOpsといった製品を通じて、この原則をサポートしています。基本資料: https://docs.cloud.google.com/architecture/framework/security/use-ai-for-security.md.txt

  • 規制、コンプライアンス、プライバシーの要件への対応: 業界固有の規制、コンプライアンス基準、およびプライバシー 要件を順守します。Google Cloudは、「Assured Workloads」、「Organization Policy Service」、および当社のコンプライアンス リソースセンターといった製品を通じて、これらの義務の履行を支援します。 参照ドキュメント: https://docs.cloud.google.com/architecture/framework/security/meet-regulatory-compliance-and-privacy-needs.md.txt

関連する Google Cloud 製品

以下は、セキュリティに関連する Google Cloud の製品および機能の です:

  • IDおよびアクセス管理

    • IDおよびアクセス管理(IAM):Google Cloud リソースに対する きめ細かなアクセス制御。
    • Identity-Aware Proxy (IAP):VPN を使用せずにアプリケーションへ安全にアクセスできます。
    • Chrome Enterprise Premium:エンドポイントセキュリティおよびコンテキストに応じたアクセス制御。
  • ネットワークセキュリティ

    • Google Cloud Armor:DDoS 保護および Web アプリケーションファイアウォール(WAF)。
    • VPC Service Controls:セキュリティ境界を定義し、データの 流出を防止します。
    • Cloud Next-Generation Firewall (NGFW): ネットワークトラフィックに対する高度な脅威対策。 Shared VPC: プロジェクトを横断した一元化されたネットワーク管理。
    • Shared VPC:プロジェクトを横断した一元的なネットワーク管理。
    • Cloud Interconnect および IPsec VPN:安全でプライベートな接続。
  • データのセキュリティ

    • Cloud Key Management Service (KMS): 暗号化キーを管理します。
    • 機密データの保護(旧 Cloud DLP):機密データを検出して マスキングします。
    • 機密コンピューティング:使用中のデータ(メモリ内)を暗号化します。
  • セキュリティ運用 (SecOps)

    • Google SecOps(Chronicle):脅威の検出とセキュリティ分析。
    • Security Command Center (SCC):脆弱性と脅威の一元的な 管理。
    • Cloud Logging および Cloud Monitoring:システムアクティビティの可視化。
  • 自動化とサプライチェーン

    • Cloud Build:セキュアな CI/CD パイプライン。
    • アーティファクト分析:コンテナイメージの脆弱性スキャン。
    • バイナリ認証:デプロイ時のポリシー適用。
    • 保証付きオープンソースソフトウェア:セキュリティ対策済みのOSSパッケージの使用。

ワークロード評価に関する質問

ワークロードおよびユーザーの組織におけるセキュリティ関連の要件や 制約を把握するために、適切な質問を行います。以下のリストから 質問を選択してください:

  • 設計段階からのセキュリティ

    • プロジェクトの初期の 計画および設計段階において、セキュリティ上の考慮事項をどのように組み込んでいますか?
    • 新しいアプリケーションやサービスのセキュリティ要件を、どのように定義し、 文書化していますか?
    • 開発ライフサイクルにセキュリティが確実に組み込まれるよう、 どのように確保していますか?
    • 設計フェーズにおいて、脅威モデリングを行うために、 どのようなツールや手法を使用していますか?
    • 設計および開発プロセス中に発見されたセキュリティの脆弱性を、 どのように管理し、優先順位を付けていますか?
    • アプリケーションやインフラストラクチャのセキュリティ更新やパッチを どのように扱っていますか?
    • セキュリティ設計上の決定事項を、チームや ステークホルダーに対してどのように文書化し、伝達していますか?
    • セキュリティ設定がすべての環境において一貫して適用されるよう、 どのように確保していますか?
    • セキュリティ対策や措置の有効性をどのように検証していますか?
    • セキュリティ設計からの例外や逸脱には、どのように 対応していますか?
  • ゼロトラスト

    • Google Cloudリソースにアクセスするユーザーやデバイスを、 どのように検証・認証していますか?
    • アクセス制御において、最小権限の原則をどのように実装していますか?
    • Google Cloud 環境内のネットワークトラフィックをどのように監視・制御していますか?
    • Google Cloud 環境において、転送中および保存中のデータをどのように保護していますか?
    • ユーザーおよびデバイスの アクティビティに対する継続的な監視とログ記録をどのように実装していますか?
    • ゼロトラスト環境において、セキュリティインシデントや侵害に どのように対処し、対応していますか?
    • ゼロトラスト 環境において、セキュリティポリシーや制御策をどのように管理・更新していますか?
    • サードパーティのアプリケーションやサービスが、 自社のゼロトラスト原則に準拠していることをどのように確保していますか?
    • ゼロトラスト 環境において、リモートアクセスやBYODデバイスをどのように扱っていますか?
    • 従業員に対して、ゼロトラストの原則や 実践方法について、どのように教育・研修を行いますか?
  • シフトレフト型セキュリティ

    • 開発プロセスの早い段階で、セキュリティテストを 開発パイプラインにどのように組み込んでいますか?
    • 開発フェーズでは、どのような種類のセキュリティテストを実施していますか?
    • 開発者に対して、セキュリティの脆弱性や ベストプラクティスに関するフィードバックをどのように提供していますか?
    • 開発者が自身のコードのセキュリティに対して主体性を持って取り組めるよう、どのように支援していますか?
    • セキュリティ要件が明確に定義され、 開発者に確実に伝達されるようにするにはどうすればよいでしょうか?
    • 「シフトレフト」セキュリティ イニシアチブの有効性をどのように測定していますか?
    • コード内のセキュリティ依存関係やサードパーティ製ライブラリを どのように扱っていますか?
    • 開発環境におけるセキュリティ設定をどのように管理・更新していますか? 開発環境におけるセキュリティ設定をどのように管理・更新していますか?
    • 開発において、セキュリティ上の例外やセキュリティ ポリシーからの逸脱にどのように対処していますか?
    • 開発者の間で、セキュリティ意識と責任感の文化を どのように醸成していますか?
  • 先制的なサイバー防御

    • 潜在的なセキュリティ脅威がシステムに影響を及ぼす前に、 どのように先手を打って特定し、軽減していますか?
    • 継続的なセキュリティ監視と 分析には、どのようなツールや手法を使用していますか?
    • セキュリティアラートやインシデントに対して、どのように対応し、是正していますか?
    • インシデント対応計画をどのようにシミュレーションし、テストしていますか?
    • 最新のセキュリティ脅威や 脆弱性に関する情報をどのように把握していますか?
    • アプリケーションや サービスに対するDDoS攻撃には、どのように対処し、軽減していますか?
    • 機密データを内部者による脅威からどのように保護していますか?
    • 高度で持続的な脅威(APT)に対して、セキュリティ対策が確実に 有効であるようにするにはどうしていますか?
    • サプライチェーンにおけるセキュリティの脆弱性にはどのように対処していますか?
    • 進化する脅威や技術に対して、セキュリティ体制をどのように適応させていますか?
  • AIワークロードのセキュリティ

    • AIモデルとデータのセキュリティをどのように確保していますか?
    • AIモデルにおける潜在的なバイアスや倫理的な懸念に、どのように対処していますか?
    • AIモデルを敵対的攻撃やデータ ポイズニングからどのように保護していますか?
    • AIモデルで使用されるデータのプライバシーをどのように確保していますか?
    • AIモデルによる決定をどのように説明・解釈していますか?
    • AIモデルやデータへのアクセスをどのように管理・制御していますか?
    • AIおよびMLに関連する規制や基準への 準拠をどのように確保していますか?
    • AIモデルの動作における異常をどのように監視・検知しますか?
    • AIモデルに関連するセキュリティインシデントに、どのように対処し、対応していますか?
    • AIおよびMLの安全かつ責任ある 利用について、従業員への教育・研修をどのように行っていますか?
  • セキュリティのためのAI

    • AIとMLを活用して、セキュリティ体制をどのように強化していますか?
    • セキュリティ目的でどのような種類のAIモデルを使用していますか?
    • セキュリティ用途向けのAIモデルのトレーニングと検証をどのように行っていますか?
    • AIベースのセキュリティシステムの 精度と信頼性をどのように確保していますか?
    • AIベースの セキュリティシステムにおける誤検知や検知漏れには、どのように対処していますか?
    • AIベースのセキュリティシステムを、既存のセキュリティ インフラにどのように統合していますか?
    • セキュリティ用途向けのAIモデルをどのように管理・更新していますか?
    • セキュリティ用途のAIモデルが下した判断を、どのように説明・解釈していますか? セキュリティ用途のAIモデルが下した判断を、どのように説明・解釈していますか?
    • セキュリティ目的でのAIおよびMLの倫理的かつ責任ある利用を どのように確保しますか?
    • セキュリティ体制の向上におけるAIおよびMLの有効性を、どのように測定していますか?
  • 規制遵守とプライバシー

    • どのような規制遵守の枠組みやプライバシー基準を 順守する必要がありますか?
    • Google Cloud 環境におけるコンプライアンスリスクをどのように評価し、 管理していますか?
    • Google Cloud に保存・処理される機密データのプライバシーを どのように確保しますか?
    • プライバシー規制に関連するデータ主体からの要求(DSR)を どのように処理していますか?
    • コンプライアンス活動やその証拠をどのように文書化し、追跡していますか?
    • サードパーティのベンダーやパートナーが、自社の 規制およびプライバシー要件を遵守していることを、どのように確保していますか?
    • コンプライアンス規制に関連するデータ漏洩やセキュリティインシデントには、 どのように対応していますか?
    • 規制コンプライアンスやプライバシー 基準の変更について、どのように最新情報を把握していますか?
    • 規制コンプライアンスおよび プライバシー要件について、従業員への教育・研修をどのように行っていますか?
    • 監査人や規制当局に対して、コンプライアンスの遵守をどのように実証し、証明していますか?

検証チェックリスト

以下のチェックリストを使用して、アーキテクチャが セキュリティ推奨事項に準拠しているかどうかを評価してください:

  • 設計段階からのセキュリティ(Security by design):

    • システムコンポーネントは、そのセキュリティ機能や 強化策に基づいて選定されていますか?
    • ネットワーク、ホスト、およびアプリケーション 各層で多層防御が実装されていますか?
    • 一般的な脆弱性を防ぐために、安全なライブラリやアプリケーション フレームワークが使用されていますか?
    • 業界標準に基づいたリスク評価が実施されていますか?
  • ゼロトラスト

    • ユーザーの身元およびコンテキスト(デバイス、 場所)に基づいてアクセス制御が実施されていますか?
    • 内部トラフィックには、プライベート接続方式(Cloud Interconnect、VPN)が 使用されていますか?
    • すべてのプロジェクトでデフォルトのネットワークは無効化されていますか?
    • 機密データの周囲にVPCサービスコントロールの境界が設定されていますか?
  • シフトレフト・セキュリティ

    • インフラストラクチャは、Infrastructure as Code (例:Terraform)を使用してプロビジョニングされていますか?
    • 自動化されたセキュリティスキャンはCI/CDパイプラインに統合されていますか?
    • 依存関係における脆弱性のスキャンおよびパッチ適用を行う プロセスは存在しますか?
    • 信頼できるイメージのみがデプロイされるよう、バイナリ認証が使用されていますか?
  • 予防的サイバー防御

    • 脅威インテリジェンスはセキュリティ運用に統合されていますか?
    • すべての重要なリソースについて、セキュリティログの記録が有効化され、一元管理されていますか?
    • 一般的なセキュリティ脅威に対して、自動対応が設定されていますか?
    • 防御策は、定期的なテストやレッドチーム活動を通じて検証されていますか?
  • AIセキュリティとガバナンス

    • AIパイプラインは、改ざんやデータポイズニングから保護されていますか?
    • トレーニングデータに対して、 適切な場合には差分プライバシーやデータマスキングが使用されていますか?
    • モデルのガバナンスにおいて、Vertex Explainable AIおよび公平性指標が活用されていますか?
GitHubで見る
---
name: google-cloud-waf-security
description: Evaluates Google Cloud workloads against the Well-Architected Framework security pillar, identifies security requirements, and provides actionable recommendations for IAM, network security, data protection, and operational security.
---

# Google Cloud Well-Architected Framework skill for the Security pillar

## Overview

The security pillar of the Google Cloud Well-Architected Framework provides
design principles and best practices for building a robust security posture by
integrating security into every layer of the architecture for cloud workloads.
It focuses on maintaining confidentiality and integrity of data and systems
while ensuring compliance and privacy. It provides a structured approach to risk
management, threat defense, and identity control, enabling you to operate cloud
workloads securely and at scale.

## Core principles

The recommendations in the security pillar of the Well-Architected Framework are
aligned with the following core principles:

-  **Implement security by design**: Integrate cloud security and network
   security considerations starting from the initial design phase of your
   applications and infrastructure. Google Cloud provides architecture
   blueprints and recommendations to help you apply this principle. Grounding
   document:
   https://docs.cloud.google.com/architecture/framework/security/implement-security-by-design.md.txt

-  **Implement zero trust**: Use a _never trust, always verify_ approach, where
   access to resources is granted based on continuous verification of trust.
   Google Cloud supports this principle through products like Chrome Enterprise
   Premium and Identity-Aware Proxy (IAP). Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/implement-zero-trust.md.txt

-  **Implement shift-left security**: Implement security controls early in the
   software development lifecycle. Avoid security defects before system changes
   are made. Detect and fix security bugs early, fast, and reliably after the
   system changes are committed. Google Cloud supports this principle through
   products like Cloud Build, Binary Authorization, and Artifact Registry.
   Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/implement-shift-left-security.md.txt

-  **Implement preemptive cyber defense**: Adopt a proactive approach to
   security by implementing robust fundamental measures like threat
   intelligence. This approach helps you build a foundation for more effective
   threat detection and response. Google Cloud's approach to layered security
   controls aligns with this principle. Google Cloud supports this principle
   through products like Security Command Center, Google Threat Intelligence,
   and Google SecOps. Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/implement-preemptive-cyber-defense.md.txt

-  **Use AI securely and responsibly**: Develop and deploy AI systems in a
   responsible and secure manner. The recommendations for this principle are
   aligned with guidance in the AI and ML perspective of the Well-Architected
   Framework and in Google's Secure AI Framework (SAIF). Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/use-ai-securely-and-responsibly.md.txt

-  **Use AI for security**: Use AI capabilities to improve your existing
   security systems and processes through Gemini in Security and overall
   platform-security capabilities. Use AI as a tool to increase the automation
   of remedial work and ensure security hygiene to make other systems more
   secure. Google Cloud supports this principle through products like Google
   Threat Intelligence and Google SecOps. Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/use-ai-for-security.md.txt

-  **Meet regulatory, compliance, and privacy needs**: Adhere to
   industry-specific regulations, compliance standards, and privacy
   requirements. Google Cloud helps you meet these obligations through products
   like Assured Workloads, Organization Policy Service, and our compliance
   resource center. Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/meet-regulatory-compliance-and-privacy-needs.md.txt

## Relevant Google Cloud products

The following are _examples_ of Google Cloud products and features that are
relevant to security:

- **Identity and access management**

  - **Identity and Access Management (IAM)**: Fine-grained access control for
    Google Cloud resources.
  - **Identity-Aware Proxy (IAP)**: Secure access to applications without a VPN.
  - **Chrome Enterprise Premium**: Endpoint security and context-aware access.

- **Network security**

  - **Google Cloud Armor**: DDoS protection and Web Application Firewall (WAF).
  - **VPC Service Controls**: Define security perimeters to prevent data
    exfiltration.
  - **Cloud Next-Generation Firewall (NGFW)**: Advanced threat protection for
    network traffic.
  - **Shared VPC**: Centralized network management across projects.
  - **Cloud Interconnect and IPsec VPN**: Secure, private connectivity.

- **Data security**

  - **Cloud Key Management Service (KMS)**: Manage encryption keys.
  - **Sensitive Data Protection (formerly Cloud DLP)**: Discover and redact
    sensitive data.
  - **Confidential Computing**: Encrypt data in use (memory).

- **Security operations (SecOps)**

  - **Google SecOps (Chronicle)**: Threat detection and security analytics.
  - **Security Command Center (SCC)**: Centralized vulnerability and threat
    management.
  - **Cloud Logging and Cloud Monitoring**: Visibility into system activity.

- **Automation and supply chain**

  - **Cloud Build**: Secure CI/CD pipelines.
  - **Artifact Analysis**: Vulnerability scanning for container images.
  - **Binary Authorization**: Deploy-time policy enforcement.
  - **Assured open source software**: Use secured OSS packages.

## Workload assessment questions

Ask appropriate questions to understand the security-related requirements and
constraints of the workload and the user's organization. Choose questions from
the following list:

- **Security by design**:

  - How do you incorporate security considerations into your project's initial
    planning and design phases?
  - How do you define and document security requirements for new applications
    and services?
  - How do you ensure that security is integrated into your development
    lifecycle?
  - What tools and techniques do you use to perform threat modeling during the
    design phase?
  - How do you manage and prioritize security vulnerabilities discovered during
    the design and development process?
  - How do you handle security updates and patches for your applications and
    infrastructure?
  - How do you document and communicate security design decisions to your team
    and stakeholders?
  - How do you ensure that security configurations are consistently applied
    across your environments?
  - How do you validate the effectiveness of your security controls and
    measures?
  - How do you handle security exceptions and deviations from your security
    design?

- **Zero trust**:

  - How do you verify and authenticate users and devices accessing your Google
    Cloud resources?
  - How do you implement the principle of least privilege for access control?
  - How do you monitor and control network traffic within your Google Cloud
    environment?
  - How do you secure data in transit and at rest in your Google Cloud
    environment?
  - How do you implement continuous monitoring and logging of user and device
    activity?
  - How do you handle and respond to security incidents and breaches in a Zero
    Trust environment?
  - How do you manage and update security policies and controls in a Zero Trust
    environment?
  - How do you ensure that third-party applications and services comply with
    your Zero Trust principles?
  - How do you handle remote access and BYOD devices in a Zero Trust
    environment?
  - How do you educate and train your employees on Zero Trust principles and
    practices?

- **Shift-left security**:

  - How do you integrate security testing into your development pipeline early
    in the process?
  - What types of security testing do you perform during the development phase?
  - How do you provide developers with feedback on security vulnerabilities and
    best practices?
  - How do you empower developers to take ownership of security in their code?
  - How do you ensure that security requirements are clearly defined and
    communicated to developers?
  - How do you measure the effectiveness of your Shift Left security
    initiatives?
  - How do you handle security dependencies and third-party libraries in your
    code?
  - How do you manage and update security configurations in your development
    environment?
  - How do you handle security exceptions and deviations from your security
    policies in development?
  - How do you promote a culture of security awareness and responsibility among
    developers?

- **Preemptive cyber defense**:

  - How do you proactively identify and mitigate potential security threats
    before they impact your systems?
  - What tools and techniques do you use for continuous security monitoring and
    analysis?
  - How do you respond to and remediate security alerts and incidents?
  - How do you simulate and test your incident response plans?
  - How do you stay up-to-date with the latest security threats and
    vulnerabilities?
  - How do you handle and mitigate DDoS attacks against your applications and
    services?
  - How do you protect your sensitive data from insider threats?
  - How do you ensure that your security controls are effective against advanced
    persistent threats (APTs)?
  - How do you handle security vulnerabilities in your supply chain?
  - How do you adapt your security posture to evolving threats and technologies?

- **Security of AI workloads**:

  - How do you ensure the security of your AI models and data?
  - How do you address potential biases and ethical concerns in your AI models?
  - How do you protect your AI models from adversarial attacks and data
    poisoning?
  - How do you ensure the privacy of data used in your AI models?
  - How do you explain and interpret the decisions made by your AI models?
  - How do you manage and control access to your AI models and data?
  - How do you ensure compliance with regulations and standards related to
    AI and ML?
  - How do you monitor and detect anomalies in the behavior of your AI models?
  - How do you handle and respond to security incidents involving your AI
    models?
  - How do you educate and train your employees on the secure and responsible
    use of AI and ML?

- **AI for security**:

  - How do you leverage AI and ML to enhance your security posture?
  - What types of AI models do you use for security purposes?
  - How do you train and validate your AI models for security applications?
  - How do you ensure the accuracy and reliability of AI-based security
    systems?
  - How do you handle false positives and false negatives from AI-based
    security systems?
  - How do you integrate AI-based security systems with your existing security
    infrastructure?
  - How do you manage and update your AI models for security applications?
  - How do you explain and interpret the decisions made by your AI models for
    security applications?
  - How do you ensure the ethical and responsible use of AI and ML for security
    purposes?
  - How do you measure the effectiveness of AI and ML in improving your security
    posture?

- **Regulatory compliance and privacy**:

  - What regulatory compliance frameworks and privacy standards do you need to
    adhere to?
  - How do you assess and manage compliance risks in your Google Cloud
    environment?
  - How do you ensure the privacy of sensitive data stored and processed in
    Google Cloud?
  - How do you handle data subject requests (DSRs) related to privacy
    regulations?
  - How do you document and track compliance activities and evidence?
  - How do you ensure that third-party vendors and partners comply with your
    regulatory and privacy requirements?
  - How do you handle data breaches and security incidents related to compliance
    regulations?
  - How do you stay up-to-date with changes in regulatory compliance and privacy
    standards?
  - How do you educate and train your employees on regulatory compliance and
    privacy requirements?
  - How do you demonstrate and prove compliance to auditors and regulators?

## Validation checklist

Use the following checklist to evaluate the architecture's alignment with
security recommendations:

- **Security by design**:

  - Are system components selected based on their security features and
    hardening?
  - Is defense-in-depth implemented at the network, host, and application
    layers?
  - Are safe libraries and application frameworks used to prevent common
    vulnerabilities?
  - Is a risk assessment performed using industry standards?

- **Zero trust**:

  - Is access control enforced based on user identity and context (device,
    location)?
  - Are private connectivity methods (Cloud Interconnect, VPN) used for internal
    traffic?
  - Are default networks disabled in all projects?
  - Are VPC Service Controls perimeters established around sensitive data?

- **Shift-left security**:

  - Is infrastructure provisioned using Infrastructure as Code
    (e.g., Terraform)?
  - Are automated security scans integrated into the CI/CD pipeline?
  - Is there a process for scanning and patching vulnerabilities in
    dependencies?
  - Is Binary Authorization used to ensure only trusted images are deployed?

- **Preemptive cyber defense**:

  - Is threat intelligence integrated into security operations?
  - Is security logging enabled and centralized for all critical resources?
  - Are automated responses configured for common security threats?
  - Are defenses validated through periodic testing or red-teaming?

- **AI security and governance**:

  - Are AI pipelines secured against tampering and data poisoning?
  - Is differential privacy or data masking used for training data where
    appropriate?
  - Are Vertex Explainable AI and fairness indicators used for model governance?

すべてのファイル

0件のファイル

google-cloud-waf-securityをインストール

スキルファイルをダウンロードし、.claude/skills/ ディレクトリに解凍してください。

ZIPをダウンロード

リポジトリをクローンし、スキルファイルをプロジェクトにコピーしてください。

git clone https://github.com/google/skills/tree/main/skills/cloud/google-cloud-waf-security # Copy SKILL.md to your .claude/skills/ directory

コピー コピー
クイックセットアップ: スキルフォルダを .claude/skills/ にコピーしてください。 Claude が自動的にスキルを検出して使用します。
リポジトリ google/skills

関連スキル

gmgn-portfolio
更新された時間 2026年7月1日
zeroize-audit
更新された時間 2026年7月1日
device-integrity
更新された時間 2026年6月29日
flutter-use-http-package
更新された時間 2026年6月30日
OR