google-cloud-waf-security
google/skills
根據「良好架構框架」(Well-Architected Framework)的安全支柱,評估 Google Cloud 工作負載,釐清安全需求,並針對 IAM、網路安全、資料保護及營運安全提供可執行的建議。
...展開全部Google Cloud「良好架構框架」中「安全性」支柱的技能
概述
Google Cloud 良好架構框架的「安全性」支柱提供 設計原則與最佳實務,透過將安全性整合至雲端工作負載 架構的每個層級,以建立穩健的安全防禦態勢。 該支柱著重於維護資料與系統的機密性及完整性, 同時確保合規性與隱私權。它針對風險 管理、威脅防禦及身分識別控制提供結構化的方法,讓您能夠安全且大規模地 運作雲端工作負載。
核心原則
「良好架構框架」中「安全性支柱」的建議 符合以下核心原則:
「安全設計」:從應用程式與基礎架構的 初期設計階段開始,即整合雲端安全與網路 安全考量。Google Cloud 提供架構 藍圖與建議,協助您實踐此原則。基礎 參考文件: https://docs.cloud.google.com/architecture/framework/security/implement-security-by-design.md.txt
實施零信任:採用「永不信任,始終驗證」的方法, 根據對信任的持續驗證來授予資源存取權限。 Google Cloud 透過 Chrome Enterprise Premium 和 Identity-Aware Proxy (IAP) 等產品支援此原則。參考文件: https://docs.cloud.google.com/architecture/framework/security/implement-zero-trust.md.txt
實施「左移」安全策略:在 軟體開發生命週期的早期階段即實施安全控制措施。在進行系統變更 之前,預先避免安全缺陷。在 系統變更提交後,及早、迅速且可靠地偵測並修復安全漏洞。Google Cloud 透過 Cloud Build、二進位授權 (Binary Authorization) 以及 Artifact Registry 等產品來支援此原則。 參考文件: https://docs.cloud.google.com/architecture/framework/security/implement-shift-left-security.md.txt
實施先發制人的網路防禦:採取主動的安全策略, 透過實施威脅情報等強健的基礎措施。此方法有助於您為更有效的 威脅偵測與應對奠定基礎。Google Cloud 針對分層安全 控制的策略與此原則相符。 Google Cloud 透過 Security Command Center、Google 威脅情報 以及 Google SecOps 等產品來支持此原則。參考文件: https://docs.cloud.google.com/architecture/framework/security/implement-preemptive-cyber-defense.md.txt
安全且負責任地使用 AI:以 負責任且安全的方式開發和部署 AI 系統。此原則的建議 與「良好架構框架」(Well-Architected Framework)中關於 AI 與機器學習的觀點, 以及 Google 的「安全 AI 框架」(SAIF)中的指引相符。參考文件: https://docs.cloud.google.com/architecture/framework/security/use-ai-securely-and-responsibly.md.txt
運用 AI 強化資安:透過「Gemini in Security」及整體 平台資安功能,運用 AI 能力來改善現有的 資安系統與流程。將 AI 作為工具,以提升 修復工作的自動化程度,並確保資安衛生,從而使其他系統更加 安全。Google Cloud 透過 Google 威脅情報(Google Threat Intelligence)和 Google SecOps 等產品來支持此原則。基礎文件: https://docs.cloud.google.com/architecture/framework/security/use-ai-for-security.md.txt
滿足法規、合規與隱私需求:遵守 特定產業的法規、合規標準及隱私 要求。Google Cloud 透過 「Assured Workloads」、「組織政策服務」以及我們的合規 資源中心等產品,協助您履行這些義務。參考文件: https://docs.cloud.google.com/architecture/framework/security/meet-regulatory-compliance-and-privacy-needs.md.txt
相關的 Google Cloud 產品
以下是與安全性相關的 Google Cloud 產品與功能 範例:
身分與存取管理
- 身分與存取管理 (IAM):針對 Google Cloud 資源提供細粒度的存取控制。
- 身分識別感知代理 (IAP):無需 VPN 即可安全存取應用程式。
- Chrome Enterprise Premium:端點安全與情境感知存取。
網路安全
- Google Cloud Armor:DDoS 防護與 Web 應用程式防火牆(WAF)。
- VPC 服務控制:定義安全邊界以防止資料 外洩。
- 雲端新一代防火牆 (NGFW):針對 網路流量提供進階威脅防護。
- 共享 VPC:跨專案的集中式網路管理。
- Cloud Interconnect 與 IPsec VPN:安全、私有的連線。
資料安全
- 雲端金鑰管理服務 (KMS):管理加密金鑰。
- 敏感資料保護(前身為 Cloud DLP):偵測並遮蔽 敏感資料。
- 機密運算:加密使用中的資料(記憶體)。
安全運作 (SecOps)
- Google SecOps(Chronicle):威脅偵測與安全分析。
- 安全指揮中心 (SCC):集中式漏洞與威脅 管理。
- Cloud Logging 與 Cloud Monitoring:系統活動的可視化。
自動化與供應鏈
- Cloud Build:安全的 CI/CD 管道。
- Artifact Analysis:針對容器映像的漏洞掃描。
- 二進位檔授權:部署時的政策強制執行。
- 經過驗證的開源軟體:使用經過安全驗證的 OSS 套件。
工作負載評估問題
提出適當的問題,以了解工作負載及使用者所屬組織的 安全相關需求與限制。請從 下列清單中選擇問題:
安全設計:
- 您如何將安全考量納入專案的初期 規劃與設計階段?
- 您如何定義並記錄新應用程式 與服務的安全性需求?
- 您如何確保將安全性整合至開發 生命週期中?
- 您在設計階段會使用哪些工具和技術來進行 威脅建模?
- 您如何管理並為在 設計與開發過程中發現的安全漏洞設定優先級?
- 您如何處理應用程式與 基礎架構的安全性更新與修補程式?
- 您如何將安全設計決策記錄下來,並向團隊 及利害關係人傳達?
- 您如何確保安全設定能跨環境 一致地套用?
- 您如何驗證安全控制與 措施的有效性?
- 您如何處理安全例外情況以及與安全 設計的偏離?
零信任:
- 您如何驗證並認證存取 Google Cloud 資源的使用者與裝置?
- 您如何在存取控制中實施「最小權限原則」?
- 您如何監控與管控 Google Cloud 環境內的網路流量?
- 您如何在 Google Cloud 環境中保護傳輸中及靜止狀態下的資料?
- 您如何對使用者和裝置的 活動實施持續監控與記錄?
- 在零信任 環境中,您如何處理並應對安全事件與資料外洩?
- 您如何在零信任 環境中管理與更新安全政策及控制措施?
- 您如何確保第三方應用程式與服務符合 您的零信任原則?
- 您如何在零信任 環境中處理遠端存取及自帶裝置(BYOD)?
- 您如何對員工進行零信任原則與 實務的教育與培訓?
「左移」安全策略:
- 您如何在開發流程的早期階段 將安全測試整合至開發管線中?
- 在開發階段會進行哪些類型的安全測試?
- 您如何向開發人員提供有關安全漏洞與 最佳實務的回饋?
- 您如何賦能開發人員,使其對自身程式碼的安全性負責?
- 您如何確保安全需求被明確定義並 傳達給開發人員?
- 您如何衡量「左移」安全 措施的成效?
- 您如何處理程式碼中的 安全性依賴項與第三方函式庫?
- 您如何管理並更新開發環境中的 安全設定?
- 在開發過程中,該如何處理安全例外情況以及與安全 政策不符的情況?
- 您如何在開發人員之間 推廣安全意識與責任感的文化?
預先防禦:
- 您如何在潛在安全威脅 影響系統之前,主動識別並加以緩解?
- 您使用哪些工具和技術進行持續的安全監控與 分析?
- 您如何回應並處理安全警報與事件?
- 您如何模擬並測試事件應變計畫?
- 您如何掌握最新的安全威脅與 漏洞資訊?
- 您如何處理並緩解針對您的應用程式和 服務發動的 DDoS 攻擊?
- 您如何保護敏感資料免受內部威脅的侵害?
- 您如何確保自身的安全控制措施能有效抵禦 進階持續性威脅(APT)?
- 您如何處理供應鏈中的安全漏洞?
- 您如何讓安全態勢適應不斷演變的威脅與技術?
AI 工作負載的安全性:
- 您如何確保 AI 模型與資料的安全性?
- 您如何處理 AI 模型中的潛在偏見與倫理疑慮?
- 您如何保護 AI 模型免受敵對攻擊和資料 中毒的威脅?
- 您如何確保 AI 模型所用資料的隱私?
- 您如何解釋和詮釋 AI 模型所做出的決策?
- 您如何管理與控制對 AI 模型及資料的存取權限?
- 您如何確保符合與 人工智慧(AI)和機器學習(ML)相關的法規與標準?
- 您如何監控並偵測 AI 模型行為中的異常情況?
- 您如何處理及應對涉及貴公司 AI 模型的安全事件?
- 您如何教育和培訓員工,使其能安全且負責任地 使用 AI 和 ML?
AI 應用於資安:
- 您如何運用 AI 與 ML 來強化您的資安防禦態勢?
- 您使用哪些類型的 AI 模型來達成資安目的?
- 您如何針對安全應用對 AI 模型進行訓練與驗證?
- 您如何確保基於人工智慧的安全 系統的準確性與可靠性?
- 您如何處理基於人工智慧的 安全系統所產生的誤報與漏報?
- 您如何將基於人工智慧的安全系統與現有的安全 基礎架構整合?
- 您如何管理及更新用於安全應用的 AI 模型?
- 您如何解釋和詮釋 AI 模型在 安全應用中做出的決策?
- 您如何確保在安全 用途上以符合倫理且負責任的方式使用人工智慧與機器學習?
- 您如何衡量人工智慧與機器學習在提升您的 資安防禦態勢方面的成效?
法規遵循與隱私權:
- 您需要遵守哪些法規遵循框架與隱私標準? 您如何在 Google Cloud 環境中評估與管理合規風險?
- 您如何評估並管理 Google Cloud 環境中的 合規風險?
- 您如何確保儲存及處理於 Google Cloud 中的敏感資料之隱私?
- 您如何處理與隱私法規相關的 資料當事人請求(DSR)?
- 您如何記錄並追蹤合規活動與相關證據?
- 您如何確保第三方供應商和合作夥伴遵守您的 法規與隱私要求?
- 您如何處理與合規法規相關的 資料外洩及安全事件?
- 您如何隨時掌握法規遵循與隱私 標準的最新變動?
- 您如何針對法規遵循與 隱私權要求對員工進行教育與培訓?
- 您如何向稽核人員及監管機構展示並證明合規狀況?
驗證檢查清單
請使用以下檢查清單,評估架構是否符合 安全建議:
「安全設計」:
- 系統元件的選用是否基於其安全性特徵與 強化措施?
- 是否已在網路、主機及應用程式 層級實施多層次防禦?
- 是否採用安全的函式庫與應用程式框架,以防範常見 的漏洞?
- 是否已依據業界標準進行風險評估?
零信任:
- 是否依據使用者身分與情境(裝置、 位置)實施存取控制?
- 內部 流量是否採用私有連線方式(雲端互連、VPN)?
- 是否已在所有專案中停用預設網路?
- 是否已在敏感資料周圍建立 VPC 服務控制邊界?
左移安全:
- 是否採用「基礎架構即代碼」 (例如 Terraform)來配置基礎架構?
- 是否已將自動化安全掃描整合至 CI/CD 管道中?
- 是否有針對 依賴項中的漏洞進行掃描與修補的流程?
- 是否採用二進位授權機制,以確保僅部署可信的映像檔?
預先防禦:
- 威脅情報是否已整合至安全運作中?
- 是否已為所有關鍵資源啟用並集中管理安全日誌?
- 是否針對常見的安全威脅配置了自動化回應機制?
- 是否透過定期測試或紅隊演練來驗證防禦機制?
AI 安全與治理:
- AI 處理流程是否已受到保護,防止遭篡改與資料中毒?
- 在適當的情況下,是否對訓練資料採用差分隱私或資料遮罩技術?
- 是否使用 Vertex 可解釋人工智慧及公平性指標來進行模型治理?
---
name: google-cloud-waf-security
description: Evaluates Google Cloud workloads against the Well-Architected Framework security pillar, identifies security requirements, and provides actionable recommendations for IAM, network security, data protection, and operational security.
---
# Google Cloud Well-Architected Framework skill for the Security pillar
## Overview
The security pillar of the Google Cloud Well-Architected Framework provides
design principles and best practices for building a robust security posture by
integrating security into every layer of the architecture for cloud workloads.
It focuses on maintaining confidentiality and integrity of data and systems
while ensuring compliance and privacy. It provides a structured approach to risk
management, threat defense, and identity control, enabling you to operate cloud
workloads securely and at scale.
## Core principles
The recommendations in the security pillar of the Well-Architected Framework are
aligned with the following core principles:
- **Implement security by design**: Integrate cloud security and network
security considerations starting from the initial design phase of your
applications and infrastructure. Google Cloud provides architecture
blueprints and recommendations to help you apply this principle. Grounding
document:
https://docs.cloud.google.com/architecture/framework/security/implement-security-by-design.md.txt
- **Implement zero trust**: Use a _never trust, always verify_ approach, where
access to resources is granted based on continuous verification of trust.
Google Cloud supports this principle through products like Chrome Enterprise
Premium and Identity-Aware Proxy (IAP). Grounding document:
https://docs.cloud.google.com/architecture/framework/security/implement-zero-trust.md.txt
- **Implement shift-left security**: Implement security controls early in the
software development lifecycle. Avoid security defects before system changes
are made. Detect and fix security bugs early, fast, and reliably after the
system changes are committed. Google Cloud supports this principle through
products like Cloud Build, Binary Authorization, and Artifact Registry.
Grounding document:
https://docs.cloud.google.com/architecture/framework/security/implement-shift-left-security.md.txt
- **Implement preemptive cyber defense**: Adopt a proactive approach to
security by implementing robust fundamental measures like threat
intelligence. This approach helps you build a foundation for more effective
threat detection and response. Google Cloud's approach to layered security
controls aligns with this principle. Google Cloud supports this principle
through products like Security Command Center, Google Threat Intelligence,
and Google SecOps. Grounding document:
https://docs.cloud.google.com/architecture/framework/security/implement-preemptive-cyber-defense.md.txt
- **Use AI securely and responsibly**: Develop and deploy AI systems in a
responsible and secure manner. The recommendations for this principle are
aligned with guidance in the AI and ML perspective of the Well-Architected
Framework and in Google's Secure AI Framework (SAIF). Grounding document:
https://docs.cloud.google.com/architecture/framework/security/use-ai-securely-and-responsibly.md.txt
- **Use AI for security**: Use AI capabilities to improve your existing
security systems and processes through Gemini in Security and overall
platform-security capabilities. Use AI as a tool to increase the automation
of remedial work and ensure security hygiene to make other systems more
secure. Google Cloud supports this principle through products like Google
Threat Intelligence and Google SecOps. Grounding document:
https://docs.cloud.google.com/architecture/framework/security/use-ai-for-security.md.txt
- **Meet regulatory, compliance, and privacy needs**: Adhere to
industry-specific regulations, compliance standards, and privacy
requirements. Google Cloud helps you meet these obligations through products
like Assured Workloads, Organization Policy Service, and our compliance
resource center. Grounding document:
https://docs.cloud.google.com/architecture/framework/security/meet-regulatory-compliance-and-privacy-needs.md.txt
## Relevant Google Cloud products
The following are _examples_ of Google Cloud products and features that are
relevant to security:
- **Identity and access management**
- **Identity and Access Management (IAM)**: Fine-grained access control for
Google Cloud resources.
- **Identity-Aware Proxy (IAP)**: Secure access to applications without a VPN.
- **Chrome Enterprise Premium**: Endpoint security and context-aware access.
- **Network security**
- **Google Cloud Armor**: DDoS protection and Web Application Firewall (WAF).
- **VPC Service Controls**: Define security perimeters to prevent data
exfiltration.
- **Cloud Next-Generation Firewall (NGFW)**: Advanced threat protection for
network traffic.
- **Shared VPC**: Centralized network management across projects.
- **Cloud Interconnect and IPsec VPN**: Secure, private connectivity.
- **Data security**
- **Cloud Key Management Service (KMS)**: Manage encryption keys.
- **Sensitive Data Protection (formerly Cloud DLP)**: Discover and redact
sensitive data.
- **Confidential Computing**: Encrypt data in use (memory).
- **Security operations (SecOps)**
- **Google SecOps (Chronicle)**: Threat detection and security analytics.
- **Security Command Center (SCC)**: Centralized vulnerability and threat
management.
- **Cloud Logging and Cloud Monitoring**: Visibility into system activity.
- **Automation and supply chain**
- **Cloud Build**: Secure CI/CD pipelines.
- **Artifact Analysis**: Vulnerability scanning for container images.
- **Binary Authorization**: Deploy-time policy enforcement.
- **Assured open source software**: Use secured OSS packages.
## Workload assessment questions
Ask appropriate questions to understand the security-related requirements and
constraints of the workload and the user's organization. Choose questions from
the following list:
- **Security by design**:
- How do you incorporate security considerations into your project's initial
planning and design phases?
- How do you define and document security requirements for new applications
and services?
- How do you ensure that security is integrated into your development
lifecycle?
- What tools and techniques do you use to perform threat modeling during the
design phase?
- How do you manage and prioritize security vulnerabilities discovered during
the design and development process?
- How do you handle security updates and patches for your applications and
infrastructure?
- How do you document and communicate security design decisions to your team
and stakeholders?
- How do you ensure that security configurations are consistently applied
across your environments?
- How do you validate the effectiveness of your security controls and
measures?
- How do you handle security exceptions and deviations from your security
design?
- **Zero trust**:
- How do you verify and authenticate users and devices accessing your Google
Cloud resources?
- How do you implement the principle of least privilege for access control?
- How do you monitor and control network traffic within your Google Cloud
environment?
- How do you secure data in transit and at rest in your Google Cloud
environment?
- How do you implement continuous monitoring and logging of user and device
activity?
- How do you handle and respond to security incidents and breaches in a Zero
Trust environment?
- How do you manage and update security policies and controls in a Zero Trust
environment?
- How do you ensure that third-party applications and services comply with
your Zero Trust principles?
- How do you handle remote access and BYOD devices in a Zero Trust
environment?
- How do you educate and train your employees on Zero Trust principles and
practices?
- **Shift-left security**:
- How do you integrate security testing into your development pipeline early
in the process?
- What types of security testing do you perform during the development phase?
- How do you provide developers with feedback on security vulnerabilities and
best practices?
- How do you empower developers to take ownership of security in their code?
- How do you ensure that security requirements are clearly defined and
communicated to developers?
- How do you measure the effectiveness of your Shift Left security
initiatives?
- How do you handle security dependencies and third-party libraries in your
code?
- How do you manage and update security configurations in your development
environment?
- How do you handle security exceptions and deviations from your security
policies in development?
- How do you promote a culture of security awareness and responsibility among
developers?
- **Preemptive cyber defense**:
- How do you proactively identify and mitigate potential security threats
before they impact your systems?
- What tools and techniques do you use for continuous security monitoring and
analysis?
- How do you respond to and remediate security alerts and incidents?
- How do you simulate and test your incident response plans?
- How do you stay up-to-date with the latest security threats and
vulnerabilities?
- How do you handle and mitigate DDoS attacks against your applications and
services?
- How do you protect your sensitive data from insider threats?
- How do you ensure that your security controls are effective against advanced
persistent threats (APTs)?
- How do you handle security vulnerabilities in your supply chain?
- How do you adapt your security posture to evolving threats and technologies?
- **Security of AI workloads**:
- How do you ensure the security of your AI models and data?
- How do you address potential biases and ethical concerns in your AI models?
- How do you protect your AI models from adversarial attacks and data
poisoning?
- How do you ensure the privacy of data used in your AI models?
- How do you explain and interpret the decisions made by your AI models?
- How do you manage and control access to your AI models and data?
- How do you ensure compliance with regulations and standards related to
AI and ML?
- How do you monitor and detect anomalies in the behavior of your AI models?
- How do you handle and respond to security incidents involving your AI
models?
- How do you educate and train your employees on the secure and responsible
use of AI and ML?
- **AI for security**:
- How do you leverage AI and ML to enhance your security posture?
- What types of AI models do you use for security purposes?
- How do you train and validate your AI models for security applications?
- How do you ensure the accuracy and reliability of AI-based security
systems?
- How do you handle false positives and false negatives from AI-based
security systems?
- How do you integrate AI-based security systems with your existing security
infrastructure?
- How do you manage and update your AI models for security applications?
- How do you explain and interpret the decisions made by your AI models for
security applications?
- How do you ensure the ethical and responsible use of AI and ML for security
purposes?
- How do you measure the effectiveness of AI and ML in improving your security
posture?
- **Regulatory compliance and privacy**:
- What regulatory compliance frameworks and privacy standards do you need to
adhere to?
- How do you assess and manage compliance risks in your Google Cloud
environment?
- How do you ensure the privacy of sensitive data stored and processed in
Google Cloud?
- How do you handle data subject requests (DSRs) related to privacy
regulations?
- How do you document and track compliance activities and evidence?
- How do you ensure that third-party vendors and partners comply with your
regulatory and privacy requirements?
- How do you handle data breaches and security incidents related to compliance
regulations?
- How do you stay up-to-date with changes in regulatory compliance and privacy
standards?
- How do you educate and train your employees on regulatory compliance and
privacy requirements?
- How do you demonstrate and prove compliance to auditors and regulators?
## Validation checklist
Use the following checklist to evaluate the architecture's alignment with
security recommendations:
- **Security by design**:
- Are system components selected based on their security features and
hardening?
- Is defense-in-depth implemented at the network, host, and application
layers?
- Are safe libraries and application frameworks used to prevent common
vulnerabilities?
- Is a risk assessment performed using industry standards?
- **Zero trust**:
- Is access control enforced based on user identity and context (device,
location)?
- Are private connectivity methods (Cloud Interconnect, VPN) used for internal
traffic?
- Are default networks disabled in all projects?
- Are VPC Service Controls perimeters established around sensitive data?
- **Shift-left security**:
- Is infrastructure provisioned using Infrastructure as Code
(e.g., Terraform)?
- Are automated security scans integrated into the CI/CD pipeline?
- Is there a process for scanning and patching vulnerabilities in
dependencies?
- Is Binary Authorization used to ensure only trusted images are deployed?
- **Preemptive cyber defense**:
- Is threat intelligence integrated into security operations?
- Is security logging enabled and centralized for all critical resources?
- Are automated responses configured for common security threats?
- Are defenses validated through periodic testing or red-teaming?
- **AI security and governance**:
- Are AI pipelines secured against tampering and data poisoning?
- Is differential privacy or data masking used for training data where
appropriate?
- Are Vertex Explainable AI and fairness indicators used for model governance?
所有檔案
0 個檔案安裝 google-cloud-waf-security
請下載技能檔案,並將其解壓縮至您的 .claude/skills/ 目錄中。
下載 ZIP複製儲存庫並將技能檔案複製到您的專案中。
git clone https://github.com/google/skills/tree/main/skills/cloud/google-cloud-waf-security # Copy SKILL.md to your .claude/skills/ directory
複製





首頁
