選項
首頁首頁 Skill 安全 google-cloud-waf-security

google-cloud-waf-security

google/skills google/skills

根據「良好架構框架」(Well-Architected Framework)的安全支柱,評估 Google Cloud 工作負載,釐清安全需求,並針對 IAM、網路安全、資料保護及營運安全提供可執行的建議。

...展開全部
11
更新時間 2026-09-04

Google Cloud「良好架構框架」中「安全性」支柱的技能

概述

Google Cloud 良好架構框架的「安全性」支柱提供 設計原則與最佳實務,透過將安全性整合至雲端工作負載 架構的每個層級,以建立穩健的安全防禦態勢。 該支柱著重於維護資料與系統的機密性及完整性, 同時確保合規性與隱私權。它針對風險 管理、威脅防禦及身分識別控制提供結構化的方法,讓您能夠安全且大規模地 運作雲端工作負載。

核心原則

「良好架構框架」中「安全性支柱」的建議 符合以下核心原則:

  • 「安全設計」:從應用程式與基礎架構的 初期設計階段開始,整合雲端安全與網路 安全考量。Google Cloud 提供架構 藍圖與建議,協助您實踐此原則。基礎 參考文件: https://docs.cloud.google.com/architecture/framework/security/implement-security-by-design.md.txt

  • 實施零信任:採用「永不信任,始終驗證」的方法, 根據對信任的持續驗證來授予資源存取權限。 Google Cloud 透過 Chrome Enterprise Premium 和 Identity-Aware Proxy (IAP) 等產品支援此原則。參考文件: https://docs.cloud.google.com/architecture/framework/security/implement-zero-trust.md.txt

  • 實施「左移」安全策略:在 軟體開發生命週期的早期階段即實施安全控制措施。在進行系統變更 之前,預先避免安全缺陷。在 系統變更提交後,及早、迅速且可靠地偵測並修復安全漏洞。Google Cloud 透過 Cloud Build、二進位授權 (Binary Authorization) 以及 Artifact Registry 等產品來支援此原則。 參考文件: https://docs.cloud.google.com/architecture/framework/security/implement-shift-left-security.md.txt

  • 實施先發制人的網路防禦:採取主動的安全策略, 透過實施威脅情報等強健的基礎措施。此方法有助於您為更有效的 威脅偵測與應對奠定基礎。Google Cloud 針對分層安全 控制的策略與此原則相符。 Google Cloud 透過 Security Command Center、Google 威脅情報 以及 Google SecOps 等產品來支持此原則。參考文件: https://docs.cloud.google.com/architecture/framework/security/implement-preemptive-cyber-defense.md.txt

  • 安全且負責任地使用 AI:以 負責任且安全的方式開發和部署 AI 系統。此原則的建議 與「良好架構框架」(Well-Architected Framework)中關於 AI 與機器學習的觀點, 以及 Google 的「安全 AI 框架」(SAIF)中的指引相符。參考文件: https://docs.cloud.google.com/architecture/framework/security/use-ai-securely-and-responsibly.md.txt

  • 運用 AI 強化資安:透過「Gemini in Security」及整體 平台資安功能,運用 AI 能力來改善現有的 資安系統與流程。將 AI 作為工具,以提升 修復工作的自動化程度,並確保資安衛生,從而使其他系統更加 安全。Google Cloud 透過 Google 威脅情報(Google Threat Intelligence)和 Google SecOps 等產品來支持此原則。基礎文件: https://docs.cloud.google.com/architecture/framework/security/use-ai-for-security.md.txt

  • 滿足法規、合規與隱私需求:遵守 特定產業的法規、合規標準及隱私 要求。Google Cloud 透過 「Assured Workloads」、「組織政策服務」以及我們的合規 資源中心等產品,協助您履行這些義務。參考文件: https://docs.cloud.google.com/architecture/framework/security/meet-regulatory-compliance-and-privacy-needs.md.txt

相關的 Google Cloud 產品

以下是與安全性相關的 Google Cloud 產品與功能 範例

  • 身分與存取管理

    • 身分與存取管理 (IAM):針對 Google Cloud 資源提供細粒度的存取控制。
    • 身分識別感知代理 (IAP):無需 VPN 即可安全存取應用程式。
    • Chrome Enterprise Premium:端點安全與情境感知存取。
  • 網路安全

    • Google Cloud Armor:DDoS 防護與 Web 應用程式防火牆(WAF)。
    • VPC 服務控制:定義安全邊界以防止資料 外洩。
    • 雲端新一代防火牆 (NGFW):針對 網路流量提供進階威脅防護。
    • 共享 VPC:跨專案的集中式網路管理。
    • Cloud Interconnect 與 IPsec VPN:安全、私有的連線。
  • 資料安全

    • 雲端金鑰管理服務 (KMS):管理加密金鑰。
    • 敏感資料保護(前身為 Cloud DLP):偵測並遮蔽 敏感資料。
    • 機密運算:加密使用中的資料(記憶體)。
  • 安全運作 (SecOps)

    • Google SecOps(Chronicle):威脅偵測與安全分析。
    • 安全指揮中心 (SCC):集中式漏洞與威脅 管理。
    • Cloud Logging 與 Cloud Monitoring:系統活動的可視化。
  • 自動化與供應鏈

    • Cloud Build:安全的 CI/CD 管道。
    • Artifact Analysis:針對容器映像的漏洞掃描。
    • 二進位檔授權:部署時的政策強制執行。
    • 經過驗證的開源軟體:使用經過安全驗證的 OSS 套件。

工作負載評估問題

提出適當的問題,以了解工作負載及使用者所屬組織的 安全相關需求與限制。請從 下列清單中選擇問題:

  • 安全設計

    • 您如何將安全考量納入專案的初期 規劃與設計階段?
    • 您如何定義並記錄新應用程式 與服務的安全性需求?
    • 您如何確保將安全性整合至開發 生命週期中?
    • 您在設計階段會使用哪些工具和技術來進行 威脅建模?
    • 您如何管理並為在 設計與開發過程中發現的安全漏洞設定優先級?
    • 您如何處理應用程式與 基礎架構的安全性更新與修補程式?
    • 您如何將安全設計決策記錄下來,並向團隊 及利害關係人傳達?
    • 您如何確保安全設定能跨環境 一致地套用?
    • 您如何驗證安全控制與 措施的有效性?
    • 您如何處理安全例外情況以及與安全 設計的偏離?
  • 零信任

    • 您如何驗證並認證存取 Google Cloud 資源的使用者與裝置?
    • 您如何在存取控制中實施「最小權限原則」?
    • 您如何監控與管控 Google Cloud 環境內的網路流量?
    • 您如何在 Google Cloud 環境中保護傳輸中及靜止狀態下的資料?
    • 您如何對使用者和裝置的 活動實施持續監控與記錄?
    • 在零信任 環境中,您如何處理並應對安全事件與資料外洩?
    • 您如何在零信任 環境中管理與更新安全政策及控制措施?
    • 您如何確保第三方應用程式與服務符合 您的零信任原則?
    • 您如何在零信任 環境中處理遠端存取及自帶裝置(BYOD)?
    • 您如何對員工進行零信任原則與 實務的教育與培訓?
  • 「左移」安全策略

    • 您如何在開發流程的早期階段 將安全測試整合至開發管線中?
    • 在開發階段會進行哪些類型的安全測試?
    • 您如何向開發人員提供有關安全漏洞與 最佳實務的回饋?
    • 您如何賦能開發人員,使其對自身程式碼的安全性負責?
    • 您如何確保安全需求被明確定義並 傳達給開發人員?
    • 您如何衡量「左移」安全 措施的成效?
    • 您如何處理程式碼中的 安全性依賴項與第三方函式庫?
    • 您如何管理並更新開發環境中的 安全設定?
    • 在開發過程中,該如何處理安全例外情況以及與安全 政策不符的情況?
    • 您如何在開發人員之間 推廣安全意識與責任感的文化?
  • 預先防禦

    • 您如何在潛在安全威脅 影響系統之前,主動識別並加以緩解?
    • 您使用哪些工具和技術進行持續的安全監控與 分析?
    • 您如何回應並處理安全警報與事件?
    • 您如何模擬並測試事件應變計畫?
    • 您如何掌握最新的安全威脅與 漏洞資訊?
    • 您如何處理並緩解針對您的應用程式和 服務發動的 DDoS 攻擊?
    • 您如何保護敏感資料免受內部威脅的侵害?
    • 您如何確保自身的安全控制措施能有效抵禦 進階持續性威脅(APT)?
    • 您如何處理供應鏈中的安全漏洞?
    • 您如何讓安全態勢適應不斷演變的威脅與技術?
  • AI 工作負載的安全性

    • 您如何確保 AI 模型與資料的安全性?
    • 您如何處理 AI 模型中的潛在偏見與倫理疑慮?
    • 您如何保護 AI 模型免受敵對攻擊和資料 中毒的威脅?
    • 您如何確保 AI 模型所用資料的隱私?
    • 您如何解釋和詮釋 AI 模型所做出的決策?
    • 您如何管理與控制對 AI 模型及資料的存取權限?
    • 您如何確保符合與 人工智慧(AI)和機器學習(ML)相關的法規與標準?
    • 您如何監控並偵測 AI 模型行為中的異常情況?
    • 您如何處理及應對涉及貴公司 AI 模型的安全事件?
    • 您如何教育和培訓員工,使其能安全且負責任地 使用 AI 和 ML?
  • AI 應用於資安

    • 您如何運用 AI 與 ML 來強化您的資安防禦態勢?
    • 您使用哪些類型的 AI 模型來達成資安目的?
    • 您如何針對安全應用對 AI 模型進行訓練與驗證?
    • 您如何確保基於人工智慧的安全 系統的準確性與可靠性?
    • 您如何處理基於人工智慧的 安全系統所產生的誤報與漏報?
    • 您如何將基於人工智慧的安全系統與現有的安全 基礎架構整合?
    • 您如何管理及更新用於安全應用的 AI 模型?
    • 您如何解釋和詮釋 AI 模型在 安全應用中做出的決策?
    • 您如何確保在安全 用途上以符合倫理且負責任的方式使用人工智慧與機器學習?
    • 您如何衡量人工智慧與機器學習在提升您的 資安防禦態勢方面的成效?
  • 法規遵循與隱私權

    • 您需要遵守哪些法規遵循框架與隱私標準? 您如何在 Google Cloud 環境中評估與管理合規風險?
    • 您如何評估並管理 Google Cloud 環境中的 合規風險?
    • 您如何確保儲存及處理於 Google Cloud 中的敏感資料之隱私?
    • 您如何處理與隱私法規相關的 資料當事人請求(DSR)?
    • 您如何記錄並追蹤合規活動與相關證據?
    • 您如何確保第三方供應商和合作夥伴遵守您的 法規與隱私要求?
    • 您如何處理與合規法規相關的 資料外洩及安全事件?
    • 您如何隨時掌握法規遵循與隱私 標準的最新變動?
    • 您如何針對法規遵循與 隱私權要求對員工進行教育與培訓?
    • 您如何向稽核人員及監管機構展示並證明合規狀況?

驗證檢查清單

請使用以下檢查清單,評估架構是否符合 安全建議:

  • 「安全設計」:

    • 系統元件的選用是否基於其安全性特徵與 強化措施?
    • 是否已在網路、主機及應用程式 層級實施多層次防禦?
    • 是否採用安全的函式庫與應用程式框架,以防範常見 的漏洞?
    • 是否已依據業界標準進行風險評估?
  • 零信任

    • 是否依據使用者身分與情境(裝置、 位置)實施存取控制?
    • 內部 流量是否採用私有連線方式(雲端互連、VPN)?
    • 是否已在所有專案中停用預設網路?
    • 是否已在敏感資料周圍建立 VPC 服務控制邊界?
  • 左移安全

    • 是否採用「基礎架構即代碼」 (例如 Terraform)來配置基礎架構?
    • 是否已將自動化安全掃描整合至 CI/CD 管道中?
    • 是否有針對 依賴項中的漏洞進行掃描與修補的流程?
    • 是否採用二進位授權機制,以確保僅部署可信的映像檔?
  • 預先防禦

    • 威脅情報是否已整合至安全運作中?
    • 是否已為所有關鍵資源啟用並集中管理安全日誌?
    • 是否針對常見的安全威脅配置了自動化回應機制?
    • 是否透過定期測試或紅隊演練來驗證防禦機制?
  • AI 安全與治理

    • AI 處理流程是否已受到保護,防止遭篡改與資料中毒?
    • 在適當的情況下,是否對訓練資料採用差分隱私或資料遮罩技術?
    • 是否使用 Vertex 可解釋人工智慧及公平性指標來進行模型治理?
在 GitHub 上查看
---
name: google-cloud-waf-security
description: Evaluates Google Cloud workloads against the Well-Architected Framework security pillar, identifies security requirements, and provides actionable recommendations for IAM, network security, data protection, and operational security.
---

# Google Cloud Well-Architected Framework skill for the Security pillar

## Overview

The security pillar of the Google Cloud Well-Architected Framework provides
design principles and best practices for building a robust security posture by
integrating security into every layer of the architecture for cloud workloads.
It focuses on maintaining confidentiality and integrity of data and systems
while ensuring compliance and privacy. It provides a structured approach to risk
management, threat defense, and identity control, enabling you to operate cloud
workloads securely and at scale.

## Core principles

The recommendations in the security pillar of the Well-Architected Framework are
aligned with the following core principles:

-  **Implement security by design**: Integrate cloud security and network
   security considerations starting from the initial design phase of your
   applications and infrastructure. Google Cloud provides architecture
   blueprints and recommendations to help you apply this principle. Grounding
   document:
   https://docs.cloud.google.com/architecture/framework/security/implement-security-by-design.md.txt

-  **Implement zero trust**: Use a _never trust, always verify_ approach, where
   access to resources is granted based on continuous verification of trust.
   Google Cloud supports this principle through products like Chrome Enterprise
   Premium and Identity-Aware Proxy (IAP). Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/implement-zero-trust.md.txt

-  **Implement shift-left security**: Implement security controls early in the
   software development lifecycle. Avoid security defects before system changes
   are made. Detect and fix security bugs early, fast, and reliably after the
   system changes are committed. Google Cloud supports this principle through
   products like Cloud Build, Binary Authorization, and Artifact Registry.
   Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/implement-shift-left-security.md.txt

-  **Implement preemptive cyber defense**: Adopt a proactive approach to
   security by implementing robust fundamental measures like threat
   intelligence. This approach helps you build a foundation for more effective
   threat detection and response. Google Cloud's approach to layered security
   controls aligns with this principle. Google Cloud supports this principle
   through products like Security Command Center, Google Threat Intelligence,
   and Google SecOps. Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/implement-preemptive-cyber-defense.md.txt

-  **Use AI securely and responsibly**: Develop and deploy AI systems in a
   responsible and secure manner. The recommendations for this principle are
   aligned with guidance in the AI and ML perspective of the Well-Architected
   Framework and in Google's Secure AI Framework (SAIF). Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/use-ai-securely-and-responsibly.md.txt

-  **Use AI for security**: Use AI capabilities to improve your existing
   security systems and processes through Gemini in Security and overall
   platform-security capabilities. Use AI as a tool to increase the automation
   of remedial work and ensure security hygiene to make other systems more
   secure. Google Cloud supports this principle through products like Google
   Threat Intelligence and Google SecOps. Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/use-ai-for-security.md.txt

-  **Meet regulatory, compliance, and privacy needs**: Adhere to
   industry-specific regulations, compliance standards, and privacy
   requirements. Google Cloud helps you meet these obligations through products
   like Assured Workloads, Organization Policy Service, and our compliance
   resource center. Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/meet-regulatory-compliance-and-privacy-needs.md.txt

## Relevant Google Cloud products

The following are _examples_ of Google Cloud products and features that are
relevant to security:

- **Identity and access management**

  - **Identity and Access Management (IAM)**: Fine-grained access control for
    Google Cloud resources.
  - **Identity-Aware Proxy (IAP)**: Secure access to applications without a VPN.
  - **Chrome Enterprise Premium**: Endpoint security and context-aware access.

- **Network security**

  - **Google Cloud Armor**: DDoS protection and Web Application Firewall (WAF).
  - **VPC Service Controls**: Define security perimeters to prevent data
    exfiltration.
  - **Cloud Next-Generation Firewall (NGFW)**: Advanced threat protection for
    network traffic.
  - **Shared VPC**: Centralized network management across projects.
  - **Cloud Interconnect and IPsec VPN**: Secure, private connectivity.

- **Data security**

  - **Cloud Key Management Service (KMS)**: Manage encryption keys.
  - **Sensitive Data Protection (formerly Cloud DLP)**: Discover and redact
    sensitive data.
  - **Confidential Computing**: Encrypt data in use (memory).

- **Security operations (SecOps)**

  - **Google SecOps (Chronicle)**: Threat detection and security analytics.
  - **Security Command Center (SCC)**: Centralized vulnerability and threat
    management.
  - **Cloud Logging and Cloud Monitoring**: Visibility into system activity.

- **Automation and supply chain**

  - **Cloud Build**: Secure CI/CD pipelines.
  - **Artifact Analysis**: Vulnerability scanning for container images.
  - **Binary Authorization**: Deploy-time policy enforcement.
  - **Assured open source software**: Use secured OSS packages.

## Workload assessment questions

Ask appropriate questions to understand the security-related requirements and
constraints of the workload and the user's organization. Choose questions from
the following list:

- **Security by design**:

  - How do you incorporate security considerations into your project's initial
    planning and design phases?
  - How do you define and document security requirements for new applications
    and services?
  - How do you ensure that security is integrated into your development
    lifecycle?
  - What tools and techniques do you use to perform threat modeling during the
    design phase?
  - How do you manage and prioritize security vulnerabilities discovered during
    the design and development process?
  - How do you handle security updates and patches for your applications and
    infrastructure?
  - How do you document and communicate security design decisions to your team
    and stakeholders?
  - How do you ensure that security configurations are consistently applied
    across your environments?
  - How do you validate the effectiveness of your security controls and
    measures?
  - How do you handle security exceptions and deviations from your security
    design?

- **Zero trust**:

  - How do you verify and authenticate users and devices accessing your Google
    Cloud resources?
  - How do you implement the principle of least privilege for access control?
  - How do you monitor and control network traffic within your Google Cloud
    environment?
  - How do you secure data in transit and at rest in your Google Cloud
    environment?
  - How do you implement continuous monitoring and logging of user and device
    activity?
  - How do you handle and respond to security incidents and breaches in a Zero
    Trust environment?
  - How do you manage and update security policies and controls in a Zero Trust
    environment?
  - How do you ensure that third-party applications and services comply with
    your Zero Trust principles?
  - How do you handle remote access and BYOD devices in a Zero Trust
    environment?
  - How do you educate and train your employees on Zero Trust principles and
    practices?

- **Shift-left security**:

  - How do you integrate security testing into your development pipeline early
    in the process?
  - What types of security testing do you perform during the development phase?
  - How do you provide developers with feedback on security vulnerabilities and
    best practices?
  - How do you empower developers to take ownership of security in their code?
  - How do you ensure that security requirements are clearly defined and
    communicated to developers?
  - How do you measure the effectiveness of your Shift Left security
    initiatives?
  - How do you handle security dependencies and third-party libraries in your
    code?
  - How do you manage and update security configurations in your development
    environment?
  - How do you handle security exceptions and deviations from your security
    policies in development?
  - How do you promote a culture of security awareness and responsibility among
    developers?

- **Preemptive cyber defense**:

  - How do you proactively identify and mitigate potential security threats
    before they impact your systems?
  - What tools and techniques do you use for continuous security monitoring and
    analysis?
  - How do you respond to and remediate security alerts and incidents?
  - How do you simulate and test your incident response plans?
  - How do you stay up-to-date with the latest security threats and
    vulnerabilities?
  - How do you handle and mitigate DDoS attacks against your applications and
    services?
  - How do you protect your sensitive data from insider threats?
  - How do you ensure that your security controls are effective against advanced
    persistent threats (APTs)?
  - How do you handle security vulnerabilities in your supply chain?
  - How do you adapt your security posture to evolving threats and technologies?

- **Security of AI workloads**:

  - How do you ensure the security of your AI models and data?
  - How do you address potential biases and ethical concerns in your AI models?
  - How do you protect your AI models from adversarial attacks and data
    poisoning?
  - How do you ensure the privacy of data used in your AI models?
  - How do you explain and interpret the decisions made by your AI models?
  - How do you manage and control access to your AI models and data?
  - How do you ensure compliance with regulations and standards related to
    AI and ML?
  - How do you monitor and detect anomalies in the behavior of your AI models?
  - How do you handle and respond to security incidents involving your AI
    models?
  - How do you educate and train your employees on the secure and responsible
    use of AI and ML?

- **AI for security**:

  - How do you leverage AI and ML to enhance your security posture?
  - What types of AI models do you use for security purposes?
  - How do you train and validate your AI models for security applications?
  - How do you ensure the accuracy and reliability of AI-based security
    systems?
  - How do you handle false positives and false negatives from AI-based
    security systems?
  - How do you integrate AI-based security systems with your existing security
    infrastructure?
  - How do you manage and update your AI models for security applications?
  - How do you explain and interpret the decisions made by your AI models for
    security applications?
  - How do you ensure the ethical and responsible use of AI and ML for security
    purposes?
  - How do you measure the effectiveness of AI and ML in improving your security
    posture?

- **Regulatory compliance and privacy**:

  - What regulatory compliance frameworks and privacy standards do you need to
    adhere to?
  - How do you assess and manage compliance risks in your Google Cloud
    environment?
  - How do you ensure the privacy of sensitive data stored and processed in
    Google Cloud?
  - How do you handle data subject requests (DSRs) related to privacy
    regulations?
  - How do you document and track compliance activities and evidence?
  - How do you ensure that third-party vendors and partners comply with your
    regulatory and privacy requirements?
  - How do you handle data breaches and security incidents related to compliance
    regulations?
  - How do you stay up-to-date with changes in regulatory compliance and privacy
    standards?
  - How do you educate and train your employees on regulatory compliance and
    privacy requirements?
  - How do you demonstrate and prove compliance to auditors and regulators?

## Validation checklist

Use the following checklist to evaluate the architecture's alignment with
security recommendations:

- **Security by design**:

  - Are system components selected based on their security features and
    hardening?
  - Is defense-in-depth implemented at the network, host, and application
    layers?
  - Are safe libraries and application frameworks used to prevent common
    vulnerabilities?
  - Is a risk assessment performed using industry standards?

- **Zero trust**:

  - Is access control enforced based on user identity and context (device,
    location)?
  - Are private connectivity methods (Cloud Interconnect, VPN) used for internal
    traffic?
  - Are default networks disabled in all projects?
  - Are VPC Service Controls perimeters established around sensitive data?

- **Shift-left security**:

  - Is infrastructure provisioned using Infrastructure as Code
    (e.g., Terraform)?
  - Are automated security scans integrated into the CI/CD pipeline?
  - Is there a process for scanning and patching vulnerabilities in
    dependencies?
  - Is Binary Authorization used to ensure only trusted images are deployed?

- **Preemptive cyber defense**:

  - Is threat intelligence integrated into security operations?
  - Is security logging enabled and centralized for all critical resources?
  - Are automated responses configured for common security threats?
  - Are defenses validated through periodic testing or red-teaming?

- **AI security and governance**:

  - Are AI pipelines secured against tampering and data poisoning?
  - Is differential privacy or data masking used for training data where
    appropriate?
  - Are Vertex Explainable AI and fairness indicators used for model governance?

所有檔案

0 個檔案

安裝 google-cloud-waf-security

請下載技能檔案,並將其解壓縮至您的 .claude/skills/ 目錄中。

下載 ZIP

複製儲存庫並將技能檔案複製到您的專案中。

git clone https://github.com/google/skills/tree/main/skills/cloud/google-cloud-waf-security # Copy SKILL.md to your .claude/skills/ directory

複製 複製
快速設定: 將技能資料夾複製到 .claude/skills/ Claude 會自動偵測並使用該技能
儲存庫 google/skills

相關技能

gmgn-portfolio
更新時間 2026-07-01
zeroize-audit
更新時間 2026-07-01
device-integrity
更新時間 2026-06-29
flutter-use-http-package
更新時間 2026-06-30
OR