옵션
집 Skill 보안 google-cloud-waf-security

google-cloud-waf-security

google/skills google/skills

Google Cloud 워크로드를 ‘Well-Architected Framework’의 보안 영역에 따라 평가하고, 보안 요구 사항을 파악하며, IAM, 네트워크 보안, 데이터 보호 및 운영 보안에 대한 실행 가능한 권장 사항을 제공합니다.

...모든 것을 확장하십시오
11
업데이트 된 시간 2026년 9월 4일

보안 분야를 위한 Google Cloud Well-Architected Framework 역량

개요

Google Cloud Well-Architected Framework의 보안 영역은 클라우드 워크로드 아키텍처의 모든 계층에 보안을 통합하여 견고한 보안 태세를 구축하기 위한 설계 원칙과 모범 사례를 제공합니다. 이 프레임워크는 규정 준수 및 개인정보 보호를 보장하는 동시에 데이터와 시스템의 기밀성 및 무결성을 유지하는 데 중점을 둡니다. 또한 위험 관리, 위협 방어 및 신원 제어에 대한 체계적인 접근 방식을 제공하여, 클라우드 워크로드를 안전하고 대규모로 운영할 수 있도록 지원합니다.

핵심 원칙

Well-Architected Framework의 보안 기둥에 포함된 권장 사항은 다음과 같은 핵심 원칙에 부합합니다.

  • 설계 단계부터 보안을 반영: 애플리케이션 및 인프라의 초기 설계 단계부터 클라우드 보안 및 네트워크 보안 고려 사항을 통합하십시오. Google Cloud는 이 원칙을 적용하는 데 도움이 되는 아키텍처 청사진과 권장 사항을 제공합니다. 기본 문서: https://docs.cloud.google.com/architecture/framework/security/implement-security-by-design.md.txt

  • 제로 트러스트 구현: ‘절대 신뢰하지 말고 항상 검증하라’는 접근 방식을 사용하여, 신뢰에 대한 지속적인 검증을 바탕으로 리소스에 대한 액세스 권한을 부여하십시오. Google Cloud는 Chrome Enterprise Premium 및 Identity-Aware Proxy(IAP)와 같은 제품을 통해 이 원칙을 지원합니다. 참고 문서: https://docs.cloud.google.com/architecture/framework/security/implement-zero-trust.md.txt

  • '시프트 레프트(shift-left)' 보안 구현: 소프트웨어 개발 라이프사이클의 초기 단계에서 보안 통제 조치를 구현합니다. 시스템 변경이 이루어지기 전에 보안 결함을 방지합니다. 시스템 변경이 적용된 후에는 보안 버그를 조기에, 신속하게, 그리고 확실하게 탐지하고 수정합니다. Google Cloud는 Cloud Build, Binary Authorization, Artifact Registry와 같은 제품을 통해 이 원칙을 지원합니다. 참고 문서: https://docs.cloud.google.com/architecture/framework/security/implement-shift-left-security.md.txt

  • 선제적 사이버 방어 구현: 위협 인텔리전스와 같은 견고한 기본 조치를 구현하여 보안에 대한 선제적 접근 방식을 채택하십시오. 이 접근 방식은 보다 효과적인 위협 탐지 및 대응을 위한 기반을 마련하는 데 도움이 됩니다. Google Cloud의 계층적 보안 통제 접근 방식은 이 원칙과 일치합니다. Google Cloud는 Security Command Center, Google Threat Intelligence, Google SecOps와 같은 제품을 통해 이 원칙을 지원합니다. 참조 문서: https://docs.cloud.google.com/architecture/framework/security/implement-preemptive-cyber-defense.md.txt

  • AI를 안전하고 책임감 있게 사용: 책임감 있고 안전한 방식으로 AI 시스템을 개발하고 배포하십시오. 이 원칙에 대한 권장 사항은 Well-Architected Framework의 AI 및 ML 관점과 Google의 Secure AI Framework(SAIF)에 명시된 지침과 일치합니다. 근거 문서: https://docs.cloud.google.com/architecture/framework/security/use-ai-securely-and-responsibly.md.txt

  • 보안을 위한 AI 활용: AI 기능을 활용하여 ‘보안 내 Gemini(Gemini in Security)’ 및 전반적인 플랫폼 보안 기능을 통해 기존 보안 시스템과 프로세스를 개선하십시오. AI를 도구로 활용하여 시정 작업의 자동화를 강화하고 보안 위생을 확보함으로써 다른 시스템의 보안성을 높이십시오. Google Cloud는 Google Threat Intelligence 및 Google SecOps와 같은 제품을 통해 이 원칙을 지원합니다. 기본 문서: https://docs.cloud.google.com/architecture/framework/security/use-ai-for-security.md.txt

  • 규제, 규정 준수 및 개인정보 보호 요구 사항 충족: 업종별 규정, 규정 준수 표준 및 개인정보 보호 요구 사항을 준수하십시오. Google Cloud는 Assured Workloads, Organization Policy Service 및 규정 준수 리소스 센터와 같은 제품을 통해 이러한 의무를 이행할 수 있도록 지원합니다. 참고 문서: https://docs.cloud.google.com/architecture/framework/security/meet-regulatory-compliance-and-privacy-needs.md.txt

관련 Google Cloud 제품

다음은 보안과 관련된 Google Cloud 제품 및 기능의 예시 입니다:

  • ID 및 액세스 관리

    • 신원 및 액세스 관리(IAM): Google Cloud 리소스에 대한 세분화된 액세스 제어.
    • Identity-Aware Proxy(IAP): VPN 없이 애플리케이션에 안전하게 액세스할 수 있습니다.
    • Chrome Enterprise Premium: 엔드포인트 보안 및 컨텍스트 인식형 액세스.
  • 네트워크 보안

    • Google Cloud Armor: DDoS 보호 및 웹 애플리케이션 방화벽(WAF).
    • VPC 서비스 제어: 데이터 유출을 방지하기 위한 보안 경계를 정의합니다. Cloud Next-Generation Firewall(NGFW): 네트워크 트래픽에 대한 고급 위협 보호 기능을 제공합니다.
    • Cloud 차세대 방화벽(NGFW): 네트워크 트래픽에 대한 고급 위협 보호.
    • 공유 VPC: 프로젝트 전반에 걸친 중앙 집중식 네트워크 관리.
    • Cloud Interconnect 및 IPsec VPN: 안전한 사설 연결.
  • 데이터 보안

    • 클라우드 키 관리 서비스(KMS): 암호화 키를 관리합니다.
    • 민감 데이터 보호(이전 명칭: Cloud DLP): 민감 데이터 식별 및 가리기 처리.
    • 기밀 컴퓨팅: 사용 중인 데이터(메모리) 암호화.
  • 보안 운영(SecOps)

    • Google SecOps(Chronicle): 위협 탐지 및 보안 분석.
    • 보안 커맨드 센터(SCC): 중앙 집중식 취약점 및 위협 관리.
    • Cloud Logging 및 Cloud Monitoring: 시스템 활동에 대한 가시성 확보.
  • 자동화 및 공급망

    • Cloud Build: 안전한 CI/CD 파이프라인.
    • 아티팩트 분석: 컨테이너 이미지에 대한 취약점 스캔.
    • 바이너리 승인: 배포 시 정책 적용.
    • 검증된 오픈 소스 소프트웨어: 보안이 강화된 OSS 패키지 사용.

워크로드 평가 질문

워크로드 및 사용자 조직의 보안 관련 요구 사항과 제약 사항을 파악하기 위해 적절한 질문을 하십시오. 다음 목록에서 질문을 선택하십시오:

  • 설계 단계에서의 보안:

    • 프로젝트의 초기 기획 및 설계 단계에 보안 고려 사항을 어떻게 반영하고 있습니까?
    • 새로운 애플리케이션 및 서비스에 대한 보안 요구 사항을 어떻게 정의하고 문서화합니까?
    • 개발 라이프사이클에 보안이 통합되도록 어떻게 보장합니까?
    • 설계 단계에서 위협 모델링을 수행하기 위해 어떤 도구와 기법을 사용합니까?
    • 설계 및 개발 과정에서 발견된 보안 취약점을 어떻게 관리하고 우선순위를 정합니까?
    • 애플리케이션 및 인프라에 대한 보안 업데이트와 패치를 어떻게 처리하고 계십니까?
    • 보안 설계 결정을 문서화하고 팀 및 이해관계자에게 전달하는 방법은 무엇입니까?
    • 보안 구성이 모든 환경에 일관되게 적용되도록 어떻게 보장하고 계신가요?
    • 보안 통제 및 조치의 효과를 어떻게 검증하고 확인합니까?
    • 보안 설계에서 발생하는 예외 사항 및 편차를 어떻게 처리하고 계십니까?
  • 제로 트러스트:

    • Google Cloud 리소스에 액세스하는 사용자와 기기를 어떻게 검증하고 인증하나요?
    • 액세스 제어에 있어 최소 권한 원칙을 어떻게 구현합니까?
    • Google Cloud 환경 내의 네트워크 트래픽을 어떻게 모니터링하고 제어하나요?
    • Google Cloud 환경에서 전송 중이거나 저장된 데이터를 어떻게 보호하나요?
    • 사용자 및 기기의 활동에 대한 지속적인 모니터링과 로깅을 어떻게 구현하나요?
    • 제로 트러스트(Zero Trust) 환경에서 보안 사고 및 침해에 어떻게 대처하고 대응합니까? 제로 트러스트 환경에서 보안 정책과 통제 수단을 어떻게 관리하고 업데이트합니까?
    • 제로 트러스트 환경에서 보안 정책 및 통제 수단을 어떻게 관리하고 업데이트합니까?
    • 타사 애플리케이션 및 서비스가 귀사의 제로 트러스트 원칙을 준수하도록 어떻게 보장하나요?
    • 제로 트러스트 환경에서 원격 액세스 및 BYOD 기기를 어떻게 관리하나요?
    • 직원들에게 제로 트러스트 원칙과 실무에 대해 어떻게 교육하고 훈련시키나요?
  • 시프트 레프트(Shift-left) 보안:

    • 개발 프로세스 초기 단계에서 보안 테스트를 개발 파이프라인에 어떻게 통합하고 있습니까?
    • 개발 단계에서 어떤 유형의 보안 테스트를 수행합니까?
    • 개발자들에게 보안 취약점 및 모범 사례에 대한 피드백을 어떻게 제공합니까?
    • 개발자들이 자신의 코드에 대한 보안 책임을 스스로 지도록 어떻게 독려하고 계신가요?
    • 보안 요구 사항이 명확하게 정의되고 개발자들에게 전달되도록 어떻게 보장하나요?
    • 'Shift Left' 보안 이니셔티브의 효과를 어떻게 측정하고 계신가요?
    • 코드 내의 보안 종속성 및 타사 라이브러리는 어떻게 관리하고 계신가요?
    • 개발 환경의 보안 구성을 어떻게 관리하고 업데이트하고 계십니까?
    • 개발 과정에서 보안 정책에 대한 예외 사항이나 편차를 어떻게 처리하고 있습니까?
    • 개발자들 사이에서 보안 인식과 책임감을 고취하는 문화를 어떻게 조성하고 계십니까?
  • 선제적 사이버 방어:

    • 잠재적인 보안 위협이 시스템에 영향을 미치기 전에 이를 선제적으로 식별하고 완화하기 위해 어떤 조치를 취하고 계신가요?
    • 지속적인 보안 모니터링 및 분석을 위해 어떤 도구와 기법을 사용하고 계십니까?
    • 보안 경보 및 사고에 어떻게 대응하고 해결하고 계십니까?
    • 사고 대응 계획을 어떻게 시뮬레이션하고 테스트합니까?
    • 최신 보안 위협 및 취약점에 대한 정보를 어떻게 최신 상태로 유지하고 계신가요?
    • 애플리케이션 및 서비스를 대상으로 한 DDoS 공격을 어떻게 처리하고 완화하고 있습니까?
    • 내부자 위협으로부터 민감한 데이터를 어떻게 보호하고 계신가요?
    • 고급 지속적 위협(APT)에 대해 보안 통제 수단이 효과적으로 작동하도록 어떻게 보장하고 계십니까?
    • 공급망 내 보안 취약점은 어떻게 처리하고 계십니까?
    • 진화하는 위협과 기술에 맞춰 보안 태세를 어떻게 조정하고 계신가요?
  • AI 워크로드의 보안:

    • AI 모델과 데이터의 보안을 어떻게 보장하고 계십니까?
    • AI 모델에 잠재된 편향성과 윤리적 문제를 어떻게 해결하고 계십니까?
    • AI 모델을 적대적 공격 및 데이터 포이즌링으로부터 어떻게 보호하고 계십니까?
    • AI 모델에 사용되는 데이터의 개인정보 보호를 어떻게 보장하고 계십니까?
    • AI 모델이 내린 결정을 어떻게 설명하고 해석하나요?
    • AI 모델 및 데이터에 대한 접근 권한을 어떻게 관리하고 통제하고 계십니까?
    • AI 및 ML과 관련된 규정 및 표준 준수를 어떻게 보장하고 계십니까? AI 및 ML과 관련된 규정 및 표준 준수를 어떻게 보장하고 계십니까?
    • AI 모델의 동작에서 이상 징후를 어떻게 모니터링하고 탐지합니까?
    • AI 모델과 관련된 보안 사고를 어떻게 처리하고 대응하고 계십니까?
    • AI 및 ML의 안전하고 책임감 있는 사용에 대해 직원들을 어떻게 교육하고 훈련시키나요?
  • 보안을 위한 AI:

    • 보안 태세를 강화하기 위해 AI와 ML을 어떻게 활용하고 계신가요?
    • 보안 목적으로 어떤 유형의 AI 모델을 사용하고 계십니까?
    • 보안 애플리케이션을 위한 AI 모델을 어떻게 훈련하고 검증하고 계십니까?
    • AI 기반 보안 시스템의 정확성과 신뢰성을 어떻게 보장하고 계십니까?
    • AI 기반 보안 시스템에서 발생하는 오탐지 및 누락은 어떻게 처리하나요?
    • AI 기반 보안 시스템을 기존 보안 인프라와 어떻게 통합하고 계신가요?
    • 보안 애플리케이션을 위한 AI 모델을 어떻게 관리하고 업데이트하나요?
    • 보안 애플리케이션을 위한 AI 모델이 내린 결정을 어떻게 설명하고 해석하나요? 보안 목적으로 AI와 머신러닝을 윤리적이고 책임감 있게 사용하는 것을 어떻게 보장하나요?
    • 보안 목적을 위해 AI와 ML을 윤리적이고 책임감 있게 사용하도록 어떻게 보장합니까?
    • 보안 태세 개선에 있어 AI와 ML의 효과를 어떻게 측정합니까? 보안 태세?
  • 규제 준수 및 개인정보 보호:

    • 어떤 규제 준수 프레임워크와 개인정보 보호 표준을 준수해야 합니까?
    • Google Cloud 환경에서 규정 준수 위험을 어떻게 평가하고 관리합니까? Google Cloud에 저장 및 처리되는 민감 데이터의 개인정보 보호를 어떻게 보장합니까?
    • Google Cloud에 저장 및 처리되는 민감한 데이터의 개인정보 보호를 어떻게 보장합니까?
    • 개인정보 보호 규정과 관련된 정보주체 요청(DSR)을 어떻게 처리하고 계십니까?
    • 규정 준수 활동 및 증빙 자료를 어떻게 문서화하고 추적하고 계십니까?
    • 제3자 공급업체 및 파트너가 귀사의 규제 및 개인정보 보호 요건을 준수하도록 어떻게 보장하고 계십니까?
    • 규정 준수 규정과 관련된 데이터 유출 및 보안 사고는 어떻게 처리하고 계신가요?
    • 규제 준수 및 개인정보 보호 표준의 변경 사항을 어떻게 최신 상태로 유지하고 계신가요?
    • 규정 준수 및 개인정보 보호 요건에 대해 직원들을 어떻게 교육하고 훈련시키시나요?
    • 감사관 및 규제 당국에 규정 준수를 어떻게 입증하고 증명합니까?

검증 체크리스트

다음 체크리스트를 사용하여 아키텍처가 보안 권장 사항을 얼마나 잘 준수하는지 평가하십시오:

  • 설계 단계에서의보안(Security by design):

    • 시스템 구성 요소가 보안 기능 및 강화 수준을 기준으로 선정되었나요?
    • 네트워크, 호스트 및 애플리케이션 계층에서 다층 방어 체계가 구현되어 있습니까?
    • 일반적인 취약점을 방지하기 위해 안전한 라이브러리와 애플리케이션 프레임워크가 사용되고 있습니까?
    • 업계 표준을 사용하여 위험 평가가 수행되었습니까?
  • 제로 트러스트:

    • 사용자 신원 및 컨텍스트(기기, 위치)를 기반으로 접근 제어가 시행되고 있습니까?
    • 내부 트래픽에 대해 프라이빗 연결 방식(Cloud Interconnect, VPN)이 사용되고 있습니까?
    • 모든 프로젝트에서 기본 네트워크가 비활성화되어 있습니까?
    • 민감한 데이터 주변에 VPC 서비스 제어 경계(VPC Service Controls)가 설정되어 있습니까?
  • 시프트 레프트 보안:

    • 인프라 프로비저닝이 Infrastructure as Code (예: Terraform)를 사용하여 수행되고 있습니까?
    • 자동화된 보안 스캔이 CI/CD 파이프라인에 통합되어 있습니까?
    • 의존성 내 취약점을 스캔하고 패치하는 프로세스가 구비되어 있습니까?
    • 신뢰할 수 있는 이미지만 배포되도록 보장하기 위해 바이너리 인증을 사용하고 있습니까?
  • 선제적 사이버 방어:

    • 보안 운영에 위협 인텔리전스가 통합되어 있습니까?
    • 모든 중요 리소스에 대해 보안 로깅이 활성화되고 중앙 집중화되어 있습니까?
    • 일반적인 보안 위협에 대한 자동 대응 기능이 구성되어 있습니까?
    • 정기적인 테스트나 레드팀 활동을 통해 방어 체계가 검증되고 있습니까?
  • AI 보안 및 거버넌스:

    • AI 파이프라인이 변조 및 데이터 포이즌링으로부터 안전하게 보호되고 있습니까?
    • 적절한 경우, 훈련 데이터에 차등 프라이버시 또는 데이터 마스킹이 사용되고 있습니까?
    • 모델 거버넌스를 위해 Vertex Explainable AI 및 공정성 지표가 사용되고 있습니까?
GitHub에서 보기
---
name: google-cloud-waf-security
description: Evaluates Google Cloud workloads against the Well-Architected Framework security pillar, identifies security requirements, and provides actionable recommendations for IAM, network security, data protection, and operational security.
---

# Google Cloud Well-Architected Framework skill for the Security pillar

## Overview

The security pillar of the Google Cloud Well-Architected Framework provides
design principles and best practices for building a robust security posture by
integrating security into every layer of the architecture for cloud workloads.
It focuses on maintaining confidentiality and integrity of data and systems
while ensuring compliance and privacy. It provides a structured approach to risk
management, threat defense, and identity control, enabling you to operate cloud
workloads securely and at scale.

## Core principles

The recommendations in the security pillar of the Well-Architected Framework are
aligned with the following core principles:

-  **Implement security by design**: Integrate cloud security and network
   security considerations starting from the initial design phase of your
   applications and infrastructure. Google Cloud provides architecture
   blueprints and recommendations to help you apply this principle. Grounding
   document:
   https://docs.cloud.google.com/architecture/framework/security/implement-security-by-design.md.txt

-  **Implement zero trust**: Use a _never trust, always verify_ approach, where
   access to resources is granted based on continuous verification of trust.
   Google Cloud supports this principle through products like Chrome Enterprise
   Premium and Identity-Aware Proxy (IAP). Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/implement-zero-trust.md.txt

-  **Implement shift-left security**: Implement security controls early in the
   software development lifecycle. Avoid security defects before system changes
   are made. Detect and fix security bugs early, fast, and reliably after the
   system changes are committed. Google Cloud supports this principle through
   products like Cloud Build, Binary Authorization, and Artifact Registry.
   Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/implement-shift-left-security.md.txt

-  **Implement preemptive cyber defense**: Adopt a proactive approach to
   security by implementing robust fundamental measures like threat
   intelligence. This approach helps you build a foundation for more effective
   threat detection and response. Google Cloud's approach to layered security
   controls aligns with this principle. Google Cloud supports this principle
   through products like Security Command Center, Google Threat Intelligence,
   and Google SecOps. Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/implement-preemptive-cyber-defense.md.txt

-  **Use AI securely and responsibly**: Develop and deploy AI systems in a
   responsible and secure manner. The recommendations for this principle are
   aligned with guidance in the AI and ML perspective of the Well-Architected
   Framework and in Google's Secure AI Framework (SAIF). Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/use-ai-securely-and-responsibly.md.txt

-  **Use AI for security**: Use AI capabilities to improve your existing
   security systems and processes through Gemini in Security and overall
   platform-security capabilities. Use AI as a tool to increase the automation
   of remedial work and ensure security hygiene to make other systems more
   secure. Google Cloud supports this principle through products like Google
   Threat Intelligence and Google SecOps. Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/use-ai-for-security.md.txt

-  **Meet regulatory, compliance, and privacy needs**: Adhere to
   industry-specific regulations, compliance standards, and privacy
   requirements. Google Cloud helps you meet these obligations through products
   like Assured Workloads, Organization Policy Service, and our compliance
   resource center. Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/meet-regulatory-compliance-and-privacy-needs.md.txt

## Relevant Google Cloud products

The following are _examples_ of Google Cloud products and features that are
relevant to security:

- **Identity and access management**

  - **Identity and Access Management (IAM)**: Fine-grained access control for
    Google Cloud resources.
  - **Identity-Aware Proxy (IAP)**: Secure access to applications without a VPN.
  - **Chrome Enterprise Premium**: Endpoint security and context-aware access.

- **Network security**

  - **Google Cloud Armor**: DDoS protection and Web Application Firewall (WAF).
  - **VPC Service Controls**: Define security perimeters to prevent data
    exfiltration.
  - **Cloud Next-Generation Firewall (NGFW)**: Advanced threat protection for
    network traffic.
  - **Shared VPC**: Centralized network management across projects.
  - **Cloud Interconnect and IPsec VPN**: Secure, private connectivity.

- **Data security**

  - **Cloud Key Management Service (KMS)**: Manage encryption keys.
  - **Sensitive Data Protection (formerly Cloud DLP)**: Discover and redact
    sensitive data.
  - **Confidential Computing**: Encrypt data in use (memory).

- **Security operations (SecOps)**

  - **Google SecOps (Chronicle)**: Threat detection and security analytics.
  - **Security Command Center (SCC)**: Centralized vulnerability and threat
    management.
  - **Cloud Logging and Cloud Monitoring**: Visibility into system activity.

- **Automation and supply chain**

  - **Cloud Build**: Secure CI/CD pipelines.
  - **Artifact Analysis**: Vulnerability scanning for container images.
  - **Binary Authorization**: Deploy-time policy enforcement.
  - **Assured open source software**: Use secured OSS packages.

## Workload assessment questions

Ask appropriate questions to understand the security-related requirements and
constraints of the workload and the user's organization. Choose questions from
the following list:

- **Security by design**:

  - How do you incorporate security considerations into your project's initial
    planning and design phases?
  - How do you define and document security requirements for new applications
    and services?
  - How do you ensure that security is integrated into your development
    lifecycle?
  - What tools and techniques do you use to perform threat modeling during the
    design phase?
  - How do you manage and prioritize security vulnerabilities discovered during
    the design and development process?
  - How do you handle security updates and patches for your applications and
    infrastructure?
  - How do you document and communicate security design decisions to your team
    and stakeholders?
  - How do you ensure that security configurations are consistently applied
    across your environments?
  - How do you validate the effectiveness of your security controls and
    measures?
  - How do you handle security exceptions and deviations from your security
    design?

- **Zero trust**:

  - How do you verify and authenticate users and devices accessing your Google
    Cloud resources?
  - How do you implement the principle of least privilege for access control?
  - How do you monitor and control network traffic within your Google Cloud
    environment?
  - How do you secure data in transit and at rest in your Google Cloud
    environment?
  - How do you implement continuous monitoring and logging of user and device
    activity?
  - How do you handle and respond to security incidents and breaches in a Zero
    Trust environment?
  - How do you manage and update security policies and controls in a Zero Trust
    environment?
  - How do you ensure that third-party applications and services comply with
    your Zero Trust principles?
  - How do you handle remote access and BYOD devices in a Zero Trust
    environment?
  - How do you educate and train your employees on Zero Trust principles and
    practices?

- **Shift-left security**:

  - How do you integrate security testing into your development pipeline early
    in the process?
  - What types of security testing do you perform during the development phase?
  - How do you provide developers with feedback on security vulnerabilities and
    best practices?
  - How do you empower developers to take ownership of security in their code?
  - How do you ensure that security requirements are clearly defined and
    communicated to developers?
  - How do you measure the effectiveness of your Shift Left security
    initiatives?
  - How do you handle security dependencies and third-party libraries in your
    code?
  - How do you manage and update security configurations in your development
    environment?
  - How do you handle security exceptions and deviations from your security
    policies in development?
  - How do you promote a culture of security awareness and responsibility among
    developers?

- **Preemptive cyber defense**:

  - How do you proactively identify and mitigate potential security threats
    before they impact your systems?
  - What tools and techniques do you use for continuous security monitoring and
    analysis?
  - How do you respond to and remediate security alerts and incidents?
  - How do you simulate and test your incident response plans?
  - How do you stay up-to-date with the latest security threats and
    vulnerabilities?
  - How do you handle and mitigate DDoS attacks against your applications and
    services?
  - How do you protect your sensitive data from insider threats?
  - How do you ensure that your security controls are effective against advanced
    persistent threats (APTs)?
  - How do you handle security vulnerabilities in your supply chain?
  - How do you adapt your security posture to evolving threats and technologies?

- **Security of AI workloads**:

  - How do you ensure the security of your AI models and data?
  - How do you address potential biases and ethical concerns in your AI models?
  - How do you protect your AI models from adversarial attacks and data
    poisoning?
  - How do you ensure the privacy of data used in your AI models?
  - How do you explain and interpret the decisions made by your AI models?
  - How do you manage and control access to your AI models and data?
  - How do you ensure compliance with regulations and standards related to
    AI and ML?
  - How do you monitor and detect anomalies in the behavior of your AI models?
  - How do you handle and respond to security incidents involving your AI
    models?
  - How do you educate and train your employees on the secure and responsible
    use of AI and ML?

- **AI for security**:

  - How do you leverage AI and ML to enhance your security posture?
  - What types of AI models do you use for security purposes?
  - How do you train and validate your AI models for security applications?
  - How do you ensure the accuracy and reliability of AI-based security
    systems?
  - How do you handle false positives and false negatives from AI-based
    security systems?
  - How do you integrate AI-based security systems with your existing security
    infrastructure?
  - How do you manage and update your AI models for security applications?
  - How do you explain and interpret the decisions made by your AI models for
    security applications?
  - How do you ensure the ethical and responsible use of AI and ML for security
    purposes?
  - How do you measure the effectiveness of AI and ML in improving your security
    posture?

- **Regulatory compliance and privacy**:

  - What regulatory compliance frameworks and privacy standards do you need to
    adhere to?
  - How do you assess and manage compliance risks in your Google Cloud
    environment?
  - How do you ensure the privacy of sensitive data stored and processed in
    Google Cloud?
  - How do you handle data subject requests (DSRs) related to privacy
    regulations?
  - How do you document and track compliance activities and evidence?
  - How do you ensure that third-party vendors and partners comply with your
    regulatory and privacy requirements?
  - How do you handle data breaches and security incidents related to compliance
    regulations?
  - How do you stay up-to-date with changes in regulatory compliance and privacy
    standards?
  - How do you educate and train your employees on regulatory compliance and
    privacy requirements?
  - How do you demonstrate and prove compliance to auditors and regulators?

## Validation checklist

Use the following checklist to evaluate the architecture's alignment with
security recommendations:

- **Security by design**:

  - Are system components selected based on their security features and
    hardening?
  - Is defense-in-depth implemented at the network, host, and application
    layers?
  - Are safe libraries and application frameworks used to prevent common
    vulnerabilities?
  - Is a risk assessment performed using industry standards?

- **Zero trust**:

  - Is access control enforced based on user identity and context (device,
    location)?
  - Are private connectivity methods (Cloud Interconnect, VPN) used for internal
    traffic?
  - Are default networks disabled in all projects?
  - Are VPC Service Controls perimeters established around sensitive data?

- **Shift-left security**:

  - Is infrastructure provisioned using Infrastructure as Code
    (e.g., Terraform)?
  - Are automated security scans integrated into the CI/CD pipeline?
  - Is there a process for scanning and patching vulnerabilities in
    dependencies?
  - Is Binary Authorization used to ensure only trusted images are deployed?

- **Preemptive cyber defense**:

  - Is threat intelligence integrated into security operations?
  - Is security logging enabled and centralized for all critical resources?
  - Are automated responses configured for common security threats?
  - Are defenses validated through periodic testing or red-teaming?

- **AI security and governance**:

  - Are AI pipelines secured against tampering and data poisoning?
  - Is differential privacy or data masking used for training data where
    appropriate?
  - Are Vertex Explainable AI and fairness indicators used for model governance?

모든 파일

0개 파일

google-cloud-waf-security 설치

스킬 파일을 다운로드하여 .claude/skills/ 디렉터리에 압축을 풀어주세요.

ZIP 다운로드

저장소를 클론하고 스킬 파일을 프로젝트에 복사하세요.

git clone https://github.com/google/skills/tree/main/skills/cloud/google-cloud-waf-security # Copy SKILL.md to your .claude/skills/ directory

복사 복사
빠른 설정: 스킬 폴더를 .claude/skills/로 복사하세요. Claude가 해당 스킬을 자동으로 감지하여 사용합니다.
저장소 google/skills

관련 스킬

gmgn-portfolio
업데이트 된 시간 2026년 7월 1일
zeroize-audit
업데이트 된 시간 2026년 7월 1일
device-integrity
업데이트 된 시간 2026년 6월 29일
flutter-use-http-package
업데이트 된 시간 2026년 6월 30일
OR