google-cloud-waf-security
google/skills
Google Cloudのワークロードを「Well-Architected Framework」のセキュリティの柱に基づいて評価し、セキュリティ要件を特定するとともに、IAM、ネットワークセキュリティ、データ保護、および運用セキュリティに関する実践的な推奨事項を提供します。
...すべて拡張しますGoogle Cloud Well-Architected Framework の「セキュリティ」分野に関するスキル
概要
Google Cloud Well-Architected Framework の「セキュリティ」ピラーは、 クラウドワークロードのアーキテクチャのあらゆる層にセキュリティを統合することで、 強固なセキュリティ体制を構築するための設計原則とベストプラクティスを提供します。 データの機密性と完全性、およびシステムの機密性と完全性を維持しつつ、 コンプライアンスとプライバシーを確保することに重点を置いています。また、リスク 管理、脅威防御、およびID管理に対する体系的なアプローチを提供し、クラウド ワークロードを安全かつ大規模に運用できるようにします。
基本原則
Well-Architected Framework のセキュリティピラーにおける推奨事項は、 以下の基本原則に沿ったものです。
「セキュリティ・バイ・デザイン」の実践:アプリケーションおよび インフラストラクチャの初期設計段階から、クラウドセキュリティとネットワーク セキュリティの考慮事項を組み込みます。Google Cloud では、この原則を 適用するためのアーキテクチャ・ブループリントや推奨事項を提供しています。 基本ドキュメント: https://docs.cloud.google.com/architecture/framework/security/implement-security-by-design.md.txt
ゼロトラストの実装:「決して信頼せず、常に検証する」というアプローチを採用し、 信頼性の継続的な検証に基づいてリソースへのアクセスを許可します。 Google Cloud は、Chrome Enterprise Premium や Identity-Aware Proxy (IAP) などの製品を通じて、この原則をサポートしています。参考資料: https://docs.cloud.google.com/architecture/framework/security/implement-zero-trust.md.txt
シフトレフトセキュリティの実装:ソフトウェア開発ライフサイクルの 早い段階でセキュリティ対策を実施します。システムの変更が行われる前に セキュリティ上の欠陥を回避します。システムの変更がコミットされた後は、 セキュリティ上のバグを早期に、迅速かつ確実に検出して修正します。Google Cloud は、 Cloud Build、Binary Authorization、Artifact Registry などの製品を通じて、この原則をサポートしています。 参考資料: https://docs.cloud.google.com/architecture/framework/security/implement-shift-left-security.md.txt
先制的なサイバー防御の実施:脅威インテリジェンスなどの 堅牢な基礎的対策を導入することで、セキュリティに対する 積極的なアプローチを採用します。このアプローチにより、より効果的な 脅威の検出と対応のための基盤を構築できます。Google Cloudの多層的なセキュリティ 対策のアプローチは、この原則に沿ったものです。 Google Cloud は、Security Command Center、Google Threat Intelligence、 Google SecOps などの製品を通じて、この原則をサポートしています。 参考資料: https://docs.cloud.google.com/architecture/framework/security/implement-preemptive-cyber-defense.md.txt
AI を安全かつ責任を持って活用する:責任ある安全な方法で AI システムを 開発・導入します。この原則に関する推奨事項は、 Well-Architected Framework の AI および ML の観点、 ならびに Google の Secure AI Framework (SAIF) に示されたガイダンスと 整合しています。根拠となる文書: https://docs.cloud.google.com/architecture/framework/security/use-ai-securely-and-responsibly.md.txt
セキュリティのためのAIの活用:AI機能を活用し、 「Gemini in Security」およびプラットフォーム全体の セキュリティ機能を通じて、既存のセキュリティシステムやプロセスを改善します。AIをツールとして活用し、 是正作業の自動化を促進し、セキュリティ衛生管理を確保することで、他のシステムの セキュリティを強化します。Google Cloudは、Google Threat IntelligenceやGoogle SecOpsといった製品を通じて、この原則をサポートしています。基本資料: https://docs.cloud.google.com/architecture/framework/security/use-ai-for-security.md.txt
規制、コンプライアンス、プライバシーの要件への対応: 業界固有の規制、コンプライアンス基準、およびプライバシー 要件を順守します。Google Cloudは、「Assured Workloads」、「Organization Policy Service」、および当社のコンプライアンス リソースセンターといった製品を通じて、これらの義務の履行を支援します。 参照ドキュメント: https://docs.cloud.google.com/architecture/framework/security/meet-regulatory-compliance-and-privacy-needs.md.txt
関連する Google Cloud 製品
以下は、セキュリティに関連する Google Cloud の製品および機能の 例です:
IDおよびアクセス管理
- IDおよびアクセス管理(IAM):Google Cloud リソースに対する きめ細かなアクセス制御。
- Identity-Aware Proxy (IAP):VPN を使用せずにアプリケーションへ安全にアクセスできます。
- Chrome Enterprise Premium:エンドポイントセキュリティおよびコンテキストに応じたアクセス制御。
ネットワークセキュリティ
- Google Cloud Armor:DDoS 保護および Web アプリケーションファイアウォール(WAF)。
- VPC Service Controls:セキュリティ境界を定義し、データの 流出を防止します。
- Cloud Next-Generation Firewall (NGFW): ネットワークトラフィックに対する高度な脅威対策。 Shared VPC: プロジェクトを横断した一元化されたネットワーク管理。
- Shared VPC:プロジェクトを横断した一元的なネットワーク管理。
- Cloud Interconnect および IPsec VPN:安全でプライベートな接続。
データのセキュリティ
- Cloud Key Management Service (KMS): 暗号化キーを管理します。
- 機密データの保護(旧 Cloud DLP):機密データを検出して マスキングします。
- 機密コンピューティング:使用中のデータ(メモリ内)を暗号化します。
セキュリティ運用 (SecOps)
- Google SecOps(Chronicle):脅威の検出とセキュリティ分析。
- Security Command Center (SCC):脆弱性と脅威の一元的な 管理。
- Cloud Logging および Cloud Monitoring:システムアクティビティの可視化。
自動化とサプライチェーン
- Cloud Build:セキュアな CI/CD パイプライン。
- アーティファクト分析:コンテナイメージの脆弱性スキャン。
- バイナリ認証:デプロイ時のポリシー適用。
- 保証付きオープンソースソフトウェア:セキュリティ対策済みのOSSパッケージの使用。
ワークロード評価に関する質問
ワークロードおよびユーザーの組織におけるセキュリティ関連の要件や 制約を把握するために、適切な質問を行います。以下のリストから 質問を選択してください:
設計段階からのセキュリティ:
- プロジェクトの初期の 計画および設計段階において、セキュリティ上の考慮事項をどのように組み込んでいますか?
- 新しいアプリケーションやサービスのセキュリティ要件を、どのように定義し、 文書化していますか?
- 開発ライフサイクルにセキュリティが確実に組み込まれるよう、 どのように確保していますか?
- 設計フェーズにおいて、脅威モデリングを行うために、 どのようなツールや手法を使用していますか?
- 設計および開発プロセス中に発見されたセキュリティの脆弱性を、 どのように管理し、優先順位を付けていますか?
- アプリケーションやインフラストラクチャのセキュリティ更新やパッチを どのように扱っていますか?
- セキュリティ設計上の決定事項を、チームや ステークホルダーに対してどのように文書化し、伝達していますか?
- セキュリティ設定がすべての環境において一貫して適用されるよう、 どのように確保していますか?
- セキュリティ対策や措置の有効性をどのように検証していますか?
- セキュリティ設計からの例外や逸脱には、どのように 対応していますか?
ゼロトラスト:
- Google Cloudリソースにアクセスするユーザーやデバイスを、 どのように検証・認証していますか?
- アクセス制御において、最小権限の原則をどのように実装していますか?
- Google Cloud 環境内のネットワークトラフィックをどのように監視・制御していますか?
- Google Cloud 環境において、転送中および保存中のデータをどのように保護していますか?
- ユーザーおよびデバイスの アクティビティに対する継続的な監視とログ記録をどのように実装していますか?
- ゼロトラスト環境において、セキュリティインシデントや侵害に どのように対処し、対応していますか?
- ゼロトラスト 環境において、セキュリティポリシーや制御策をどのように管理・更新していますか?
- サードパーティのアプリケーションやサービスが、 自社のゼロトラスト原則に準拠していることをどのように確保していますか?
- ゼロトラスト 環境において、リモートアクセスやBYODデバイスをどのように扱っていますか?
- 従業員に対して、ゼロトラストの原則や 実践方法について、どのように教育・研修を行いますか?
シフトレフト型セキュリティ:
- 開発プロセスの早い段階で、セキュリティテストを 開発パイプラインにどのように組み込んでいますか?
- 開発フェーズでは、どのような種類のセキュリティテストを実施していますか?
- 開発者に対して、セキュリティの脆弱性や ベストプラクティスに関するフィードバックをどのように提供していますか?
- 開発者が自身のコードのセキュリティに対して主体性を持って取り組めるよう、どのように支援していますか?
- セキュリティ要件が明確に定義され、 開発者に確実に伝達されるようにするにはどうすればよいでしょうか?
- 「シフトレフト」セキュリティ イニシアチブの有効性をどのように測定していますか?
- コード内のセキュリティ依存関係やサードパーティ製ライブラリを どのように扱っていますか?
- 開発環境におけるセキュリティ設定をどのように管理・更新していますか? 開発環境におけるセキュリティ設定をどのように管理・更新していますか?
- 開発において、セキュリティ上の例外やセキュリティ ポリシーからの逸脱にどのように対処していますか?
- 開発者の間で、セキュリティ意識と責任感の文化を どのように醸成していますか?
先制的なサイバー防御:
- 潜在的なセキュリティ脅威がシステムに影響を及ぼす前に、 どのように先手を打って特定し、軽減していますか?
- 継続的なセキュリティ監視と 分析には、どのようなツールや手法を使用していますか?
- セキュリティアラートやインシデントに対して、どのように対応し、是正していますか?
- インシデント対応計画をどのようにシミュレーションし、テストしていますか?
- 最新のセキュリティ脅威や 脆弱性に関する情報をどのように把握していますか?
- アプリケーションや サービスに対するDDoS攻撃には、どのように対処し、軽減していますか?
- 機密データを内部者による脅威からどのように保護していますか?
- 高度で持続的な脅威(APT)に対して、セキュリティ対策が確実に 有効であるようにするにはどうしていますか?
- サプライチェーンにおけるセキュリティの脆弱性にはどのように対処していますか?
- 進化する脅威や技術に対して、セキュリティ体制をどのように適応させていますか?
AIワークロードのセキュリティ:
- AIモデルとデータのセキュリティをどのように確保していますか?
- AIモデルにおける潜在的なバイアスや倫理的な懸念に、どのように対処していますか?
- AIモデルを敵対的攻撃やデータ ポイズニングからどのように保護していますか?
- AIモデルで使用されるデータのプライバシーをどのように確保していますか?
- AIモデルによる決定をどのように説明・解釈していますか?
- AIモデルやデータへのアクセスをどのように管理・制御していますか?
- AIおよびMLに関連する規制や基準への 準拠をどのように確保していますか?
- AIモデルの動作における異常をどのように監視・検知しますか?
- AIモデルに関連するセキュリティインシデントに、どのように対処し、対応していますか?
- AIおよびMLの安全かつ責任ある 利用について、従業員への教育・研修をどのように行っていますか?
セキュリティのためのAI:
- AIとMLを活用して、セキュリティ体制をどのように強化していますか?
- セキュリティ目的でどのような種類のAIモデルを使用していますか?
- セキュリティ用途向けのAIモデルのトレーニングと検証をどのように行っていますか?
- AIベースのセキュリティシステムの 精度と信頼性をどのように確保していますか?
- AIベースの セキュリティシステムにおける誤検知や検知漏れには、どのように対処していますか?
- AIベースのセキュリティシステムを、既存のセキュリティ インフラにどのように統合していますか?
- セキュリティ用途向けのAIモデルをどのように管理・更新していますか?
- セキュリティ用途のAIモデルが下した判断を、どのように説明・解釈していますか? セキュリティ用途のAIモデルが下した判断を、どのように説明・解釈していますか?
- セキュリティ目的でのAIおよびMLの倫理的かつ責任ある利用を どのように確保しますか?
- セキュリティ体制の向上におけるAIおよびMLの有効性を、どのように測定していますか?
規制遵守とプライバシー:
- どのような規制遵守の枠組みやプライバシー基準を 順守する必要がありますか?
- Google Cloud 環境におけるコンプライアンスリスクをどのように評価し、 管理していますか?
- Google Cloud に保存・処理される機密データのプライバシーを どのように確保しますか?
- プライバシー規制に関連するデータ主体からの要求(DSR)を どのように処理していますか?
- コンプライアンス活動やその証拠をどのように文書化し、追跡していますか?
- サードパーティのベンダーやパートナーが、自社の 規制およびプライバシー要件を遵守していることを、どのように確保していますか?
- コンプライアンス規制に関連するデータ漏洩やセキュリティインシデントには、 どのように対応していますか?
- 規制コンプライアンスやプライバシー 基準の変更について、どのように最新情報を把握していますか?
- 規制コンプライアンスおよび プライバシー要件について、従業員への教育・研修をどのように行っていますか?
- 監査人や規制当局に対して、コンプライアンスの遵守をどのように実証し、証明していますか?
検証チェックリスト
以下のチェックリストを使用して、アーキテクチャが セキュリティ推奨事項に準拠しているかどうかを評価してください:
設計段階からのセキュリティ(Security by design):
- システムコンポーネントは、そのセキュリティ機能や 強化策に基づいて選定されていますか?
- ネットワーク、ホスト、およびアプリケーション 各層で多層防御が実装されていますか?
- 一般的な脆弱性を防ぐために、安全なライブラリやアプリケーション フレームワークが使用されていますか?
- 業界標準に基づいたリスク評価が実施されていますか?
ゼロトラスト:
- ユーザーの身元およびコンテキスト(デバイス、 場所)に基づいてアクセス制御が実施されていますか?
- 内部トラフィックには、プライベート接続方式(Cloud Interconnect、VPN)が 使用されていますか?
- すべてのプロジェクトでデフォルトのネットワークは無効化されていますか?
- 機密データの周囲にVPCサービスコントロールの境界が設定されていますか?
シフトレフト・セキュリティ:
- インフラストラクチャは、Infrastructure as Code (例:Terraform)を使用してプロビジョニングされていますか?
- 自動化されたセキュリティスキャンはCI/CDパイプラインに統合されていますか?
- 依存関係における脆弱性のスキャンおよびパッチ適用を行う プロセスは存在しますか?
- 信頼できるイメージのみがデプロイされるよう、バイナリ認証が使用されていますか?
予防的サイバー防御:
- 脅威インテリジェンスはセキュリティ運用に統合されていますか?
- すべての重要なリソースについて、セキュリティログの記録が有効化され、一元管理されていますか?
- 一般的なセキュリティ脅威に対して、自動対応が設定されていますか?
- 防御策は、定期的なテストやレッドチーム活動を通じて検証されていますか?
AIセキュリティとガバナンス:
- AIパイプラインは、改ざんやデータポイズニングから保護されていますか?
- トレーニングデータに対して、 適切な場合には差分プライバシーやデータマスキングが使用されていますか?
- モデルのガバナンスにおいて、Vertex Explainable AIおよび公平性指標が活用されていますか?
---
name: google-cloud-waf-security
description: Evaluates Google Cloud workloads against the Well-Architected Framework security pillar, identifies security requirements, and provides actionable recommendations for IAM, network security, data protection, and operational security.
---
# Google Cloud Well-Architected Framework skill for the Security pillar
## Overview
The security pillar of the Google Cloud Well-Architected Framework provides
design principles and best practices for building a robust security posture by
integrating security into every layer of the architecture for cloud workloads.
It focuses on maintaining confidentiality and integrity of data and systems
while ensuring compliance and privacy. It provides a structured approach to risk
management, threat defense, and identity control, enabling you to operate cloud
workloads securely and at scale.
## Core principles
The recommendations in the security pillar of the Well-Architected Framework are
aligned with the following core principles:
- **Implement security by design**: Integrate cloud security and network
security considerations starting from the initial design phase of your
applications and infrastructure. Google Cloud provides architecture
blueprints and recommendations to help you apply this principle. Grounding
document:
https://docs.cloud.google.com/architecture/framework/security/implement-security-by-design.md.txt
- **Implement zero trust**: Use a _never trust, always verify_ approach, where
access to resources is granted based on continuous verification of trust.
Google Cloud supports this principle through products like Chrome Enterprise
Premium and Identity-Aware Proxy (IAP). Grounding document:
https://docs.cloud.google.com/architecture/framework/security/implement-zero-trust.md.txt
- **Implement shift-left security**: Implement security controls early in the
software development lifecycle. Avoid security defects before system changes
are made. Detect and fix security bugs early, fast, and reliably after the
system changes are committed. Google Cloud supports this principle through
products like Cloud Build, Binary Authorization, and Artifact Registry.
Grounding document:
https://docs.cloud.google.com/architecture/framework/security/implement-shift-left-security.md.txt
- **Implement preemptive cyber defense**: Adopt a proactive approach to
security by implementing robust fundamental measures like threat
intelligence. This approach helps you build a foundation for more effective
threat detection and response. Google Cloud's approach to layered security
controls aligns with this principle. Google Cloud supports this principle
through products like Security Command Center, Google Threat Intelligence,
and Google SecOps. Grounding document:
https://docs.cloud.google.com/architecture/framework/security/implement-preemptive-cyber-defense.md.txt
- **Use AI securely and responsibly**: Develop and deploy AI systems in a
responsible and secure manner. The recommendations for this principle are
aligned with guidance in the AI and ML perspective of the Well-Architected
Framework and in Google's Secure AI Framework (SAIF). Grounding document:
https://docs.cloud.google.com/architecture/framework/security/use-ai-securely-and-responsibly.md.txt
- **Use AI for security**: Use AI capabilities to improve your existing
security systems and processes through Gemini in Security and overall
platform-security capabilities. Use AI as a tool to increase the automation
of remedial work and ensure security hygiene to make other systems more
secure. Google Cloud supports this principle through products like Google
Threat Intelligence and Google SecOps. Grounding document:
https://docs.cloud.google.com/architecture/framework/security/use-ai-for-security.md.txt
- **Meet regulatory, compliance, and privacy needs**: Adhere to
industry-specific regulations, compliance standards, and privacy
requirements. Google Cloud helps you meet these obligations through products
like Assured Workloads, Organization Policy Service, and our compliance
resource center. Grounding document:
https://docs.cloud.google.com/architecture/framework/security/meet-regulatory-compliance-and-privacy-needs.md.txt
## Relevant Google Cloud products
The following are _examples_ of Google Cloud products and features that are
relevant to security:
- **Identity and access management**
- **Identity and Access Management (IAM)**: Fine-grained access control for
Google Cloud resources.
- **Identity-Aware Proxy (IAP)**: Secure access to applications without a VPN.
- **Chrome Enterprise Premium**: Endpoint security and context-aware access.
- **Network security**
- **Google Cloud Armor**: DDoS protection and Web Application Firewall (WAF).
- **VPC Service Controls**: Define security perimeters to prevent data
exfiltration.
- **Cloud Next-Generation Firewall (NGFW)**: Advanced threat protection for
network traffic.
- **Shared VPC**: Centralized network management across projects.
- **Cloud Interconnect and IPsec VPN**: Secure, private connectivity.
- **Data security**
- **Cloud Key Management Service (KMS)**: Manage encryption keys.
- **Sensitive Data Protection (formerly Cloud DLP)**: Discover and redact
sensitive data.
- **Confidential Computing**: Encrypt data in use (memory).
- **Security operations (SecOps)**
- **Google SecOps (Chronicle)**: Threat detection and security analytics.
- **Security Command Center (SCC)**: Centralized vulnerability and threat
management.
- **Cloud Logging and Cloud Monitoring**: Visibility into system activity.
- **Automation and supply chain**
- **Cloud Build**: Secure CI/CD pipelines.
- **Artifact Analysis**: Vulnerability scanning for container images.
- **Binary Authorization**: Deploy-time policy enforcement.
- **Assured open source software**: Use secured OSS packages.
## Workload assessment questions
Ask appropriate questions to understand the security-related requirements and
constraints of the workload and the user's organization. Choose questions from
the following list:
- **Security by design**:
- How do you incorporate security considerations into your project's initial
planning and design phases?
- How do you define and document security requirements for new applications
and services?
- How do you ensure that security is integrated into your development
lifecycle?
- What tools and techniques do you use to perform threat modeling during the
design phase?
- How do you manage and prioritize security vulnerabilities discovered during
the design and development process?
- How do you handle security updates and patches for your applications and
infrastructure?
- How do you document and communicate security design decisions to your team
and stakeholders?
- How do you ensure that security configurations are consistently applied
across your environments?
- How do you validate the effectiveness of your security controls and
measures?
- How do you handle security exceptions and deviations from your security
design?
- **Zero trust**:
- How do you verify and authenticate users and devices accessing your Google
Cloud resources?
- How do you implement the principle of least privilege for access control?
- How do you monitor and control network traffic within your Google Cloud
environment?
- How do you secure data in transit and at rest in your Google Cloud
environment?
- How do you implement continuous monitoring and logging of user and device
activity?
- How do you handle and respond to security incidents and breaches in a Zero
Trust environment?
- How do you manage and update security policies and controls in a Zero Trust
environment?
- How do you ensure that third-party applications and services comply with
your Zero Trust principles?
- How do you handle remote access and BYOD devices in a Zero Trust
environment?
- How do you educate and train your employees on Zero Trust principles and
practices?
- **Shift-left security**:
- How do you integrate security testing into your development pipeline early
in the process?
- What types of security testing do you perform during the development phase?
- How do you provide developers with feedback on security vulnerabilities and
best practices?
- How do you empower developers to take ownership of security in their code?
- How do you ensure that security requirements are clearly defined and
communicated to developers?
- How do you measure the effectiveness of your Shift Left security
initiatives?
- How do you handle security dependencies and third-party libraries in your
code?
- How do you manage and update security configurations in your development
environment?
- How do you handle security exceptions and deviations from your security
policies in development?
- How do you promote a culture of security awareness and responsibility among
developers?
- **Preemptive cyber defense**:
- How do you proactively identify and mitigate potential security threats
before they impact your systems?
- What tools and techniques do you use for continuous security monitoring and
analysis?
- How do you respond to and remediate security alerts and incidents?
- How do you simulate and test your incident response plans?
- How do you stay up-to-date with the latest security threats and
vulnerabilities?
- How do you handle and mitigate DDoS attacks against your applications and
services?
- How do you protect your sensitive data from insider threats?
- How do you ensure that your security controls are effective against advanced
persistent threats (APTs)?
- How do you handle security vulnerabilities in your supply chain?
- How do you adapt your security posture to evolving threats and technologies?
- **Security of AI workloads**:
- How do you ensure the security of your AI models and data?
- How do you address potential biases and ethical concerns in your AI models?
- How do you protect your AI models from adversarial attacks and data
poisoning?
- How do you ensure the privacy of data used in your AI models?
- How do you explain and interpret the decisions made by your AI models?
- How do you manage and control access to your AI models and data?
- How do you ensure compliance with regulations and standards related to
AI and ML?
- How do you monitor and detect anomalies in the behavior of your AI models?
- How do you handle and respond to security incidents involving your AI
models?
- How do you educate and train your employees on the secure and responsible
use of AI and ML?
- **AI for security**:
- How do you leverage AI and ML to enhance your security posture?
- What types of AI models do you use for security purposes?
- How do you train and validate your AI models for security applications?
- How do you ensure the accuracy and reliability of AI-based security
systems?
- How do you handle false positives and false negatives from AI-based
security systems?
- How do you integrate AI-based security systems with your existing security
infrastructure?
- How do you manage and update your AI models for security applications?
- How do you explain and interpret the decisions made by your AI models for
security applications?
- How do you ensure the ethical and responsible use of AI and ML for security
purposes?
- How do you measure the effectiveness of AI and ML in improving your security
posture?
- **Regulatory compliance and privacy**:
- What regulatory compliance frameworks and privacy standards do you need to
adhere to?
- How do you assess and manage compliance risks in your Google Cloud
environment?
- How do you ensure the privacy of sensitive data stored and processed in
Google Cloud?
- How do you handle data subject requests (DSRs) related to privacy
regulations?
- How do you document and track compliance activities and evidence?
- How do you ensure that third-party vendors and partners comply with your
regulatory and privacy requirements?
- How do you handle data breaches and security incidents related to compliance
regulations?
- How do you stay up-to-date with changes in regulatory compliance and privacy
standards?
- How do you educate and train your employees on regulatory compliance and
privacy requirements?
- How do you demonstrate and prove compliance to auditors and regulators?
## Validation checklist
Use the following checklist to evaluate the architecture's alignment with
security recommendations:
- **Security by design**:
- Are system components selected based on their security features and
hardening?
- Is defense-in-depth implemented at the network, host, and application
layers?
- Are safe libraries and application frameworks used to prevent common
vulnerabilities?
- Is a risk assessment performed using industry standards?
- **Zero trust**:
- Is access control enforced based on user identity and context (device,
location)?
- Are private connectivity methods (Cloud Interconnect, VPN) used for internal
traffic?
- Are default networks disabled in all projects?
- Are VPC Service Controls perimeters established around sensitive data?
- **Shift-left security**:
- Is infrastructure provisioned using Infrastructure as Code
(e.g., Terraform)?
- Are automated security scans integrated into the CI/CD pipeline?
- Is there a process for scanning and patching vulnerabilities in
dependencies?
- Is Binary Authorization used to ensure only trusted images are deployed?
- **Preemptive cyber defense**:
- Is threat intelligence integrated into security operations?
- Is security logging enabled and centralized for all critical resources?
- Are automated responses configured for common security threats?
- Are defenses validated through periodic testing or red-teaming?
- **AI security and governance**:
- Are AI pipelines secured against tampering and data poisoning?
- Is differential privacy or data masking used for training data where
appropriate?
- Are Vertex Explainable AI and fairness indicators used for model governance?
すべてのファイル
0件のファイルgoogle-cloud-waf-securityをインストール
スキルファイルをダウンロードし、.claude/skills/ ディレクトリに解凍してください。
ZIPをダウンロードリポジトリをクローンし、スキルファイルをプロジェクトにコピーしてください。
git clone https://github.com/google/skills/tree/main/skills/cloud/google-cloud-waf-security # Copy SKILL.md to your .claude/skills/ directory
コピー





家
