选项
首页首页 Skill 安全 google-cloud-waf-security

google-cloud-waf-security

google/skills google/skills

根据“良好架构框架”(Well-Architected Framework)的安全支柱评估 Google Cloud 工作负载,确定安全要求,并针对身份与访问管理(IAM)、网络安全、数据保护和运营安全提供可操作的建议。

...展开全部
11
更新时间 2026-09-04

Google Cloud 良好架构框架中的“安全”支柱相关技能

概述

Google Cloud 良好架构框架的安全支柱提供了 设计原则和最佳实践,通过将安全措施融入云工作负载架构的 每个层级,从而构建稳健的安全态势。 该支柱侧重于维护数据和系统的机密性与完整性, 同时确保合规性和隐私保护。它为风险 管理、威胁防御和身份控制提供了一种结构化的方法,使您能够安全且大规模地 运行云工作负载。

核心原则

“良好架构框架”安全支柱中的建议 符合以下核心原则:

  • “安全设计”原则:从应用程序和基础设施的 初期设计阶段开始,就将云安全和网络 安全考量融入其中。Google Cloud 提供了架构 蓝图和建议,以帮助您应用这一原则。基础 文档: https://docs.cloud.google.com/architecture/framework/security/implement-security-by-design.md.txt

  • 实施零信任:采用“永不信任,始终验证”的方法, 根据对信任的持续验证来授予资源访问权限。 Google Cloud 通过 Chrome Enterprise Premium 和身份感知代理 (IAP) 等产品支持这一原则。参考文档: https://docs.cloud.google.com/architecture/framework/security/implement-zero-trust.md.txt

  • 实施“左移”安全策略:在 软件开发生命周期的早期阶段实施安全控制措施。在系统变更 实施之前,就避免安全缺陷的发生。在 系统变更提交后,尽早、快速且可靠地检测并修复安全漏洞。Google Cloud 通过 Cloud Build、二进制授权和 Artifact Registry 等产品支持这一原则。 参考文档: https://docs.cloud.google.com/architecture/framework/security/implement-shift-left-security.md.txt

  • 实施先发制人的网络防御:采取主动的安全策略, 通过实施威胁情报等强有力的基础措施。这种方法有助于您为更有效的 威胁检测和响应奠定基础。Google Cloud 采用的分层安全 控制方法与这一原则相一致。 Google Cloud 通过 Security Command Center、Google 威胁情报 和 Google SecOps 等产品支持这一原则。参考文档: https://docs.cloud.google.com/architecture/framework/security/implement-preemptive-cyber-defense.md.txt

  • 安全且负责任地使用 AI:以 负责任且安全的方式开发和部署 AI 系统。该原则的建议 与《Well-Architected 框架》中关于 AI 和机器学习的指导方针 以及 Google 的安全 AI 框架 (SAIF) 保持一致。依据文档: https://docs.cloud.google.com/architecture/framework/security/use-ai-securely-and-responsibly.md.txt

  • 利用 AI 提升安全性:通过“Gemini in Security”以及整体 平台安全能力,利用 AI 功能来改进现有的 安全系统和流程。将 AI 作为工具,提高 补救工作的自动化程度,并确保安全规范,从而使其他系统更加 安全。Google Cloud 通过 Google 威胁情报和 Google SecOps 等产品来支持这一原则。基础文档: https://docs.cloud.google.com/architecture/framework/security/use-ai-for-security.md.txt

  • 满足监管、合规和隐私需求:遵守 行业特定法规、合规标准和隐私 要求。Google Cloud 通过 “受保障的工作负载”(Assured Workloads)、“组织策略服务”(Organization Policy Service)以及我们的合规 资源中心等产品,帮助您履行这些义务。参考文档: https://docs.cloud.google.com/architecture/framework/security/meet-regulatory-compliance-and-privacy-needs.md.txt

相关的 Google Cloud 产品

以下是与安全相关的 Google Cloud 产品和功能的 示例

  • 身份与访问管理

    • 身份和访问管理 (IAM):针对 Google Cloud 资源的精细化访问控制。
    • 身份感知代理(IAP):无需 VPN 即可安全访问应用程序。
    • Chrome Enterprise Premium:端点安全与基于上下文的访问控制。
  • 网络安全

    • Google Cloud Armor:DDoS 防护和 Web 应用程序防火墙 (WAF)。
    • VPC 服务控制:定义安全边界以防止数据 外泄。
    • 云新一代防火墙(NGFW):针对 网络流量的高级威胁防护。
    • 共享 VPC:跨项目的集中式网络管理。
    • Cloud Interconnect 和 IPsec VPN:安全、私有的连接。
  • 数据安全

    • 云密钥管理服务(KMS):管理加密密钥。
    • 敏感数据保护(原云 DLP):发现并屏蔽 敏感数据。
    • 机密计算:对正在使用的数据(内存)进行加密。
  • 安全运维 (SecOps)

    • Google SecOps(Chronicle):威胁检测与安全分析。
    • 安全指挥中心 (SCC):集中化的漏洞和威胁 管理。
    • Cloud Logging 和 Cloud Monitoring:系统活动可视化。
  • 自动化与供应链

    • Cloud Build:安全的 CI/CD 管道。
    • 构建产物分析:针对容器镜像的漏洞扫描。
    • 二进制授权:部署时的策略执行。
    • 可信开源软件:使用经过安全加固的开源软件包。

工作负载评估问题

提出适当的问题,以了解工作负载及用户组织在安全方面的相关要求和 限制。请从 以下列表中选择问题:

  • 安全设计

    • 您如何将安全考量纳入项目的初期 规划和设计阶段?
    • 您如何定义并记录新应用程序 和服务的安全要求?
    • 您如何确保将安全性融入开发 生命周期?
    • 在设计阶段,您使用哪些工具和技术 来进行威胁建模?
    • 您如何管理和优先处理在 设计与开发过程中发现的安全漏洞?
    • 您如何处理应用程序和 基础设施的安全更新与补丁?
    • 您如何将安全设计决策记录下来,并传达给团队 和利益相关者?
    • 您如何确保安全配置在 各个环境中得到一致应用?
    • 您如何验证安全控制和 措施的有效性?
    • 您如何处理安全例外情况以及与安全 设计方案的偏差?
  • 零信任

    • 您如何验证并认证访问 Google Cloud 资源的用户和设备?
    • 您如何在访问控制中实施最小权限原则?
    • 您如何监控和控制 Google Cloud 环境内的网络流量?
    • 您如何保障 Google Cloud 环境中传输中和静止状态下的数据安全?
    • 您如何对用户和设备的 活动实施持续监控和日志记录?
    • 在零 信任环境中,您如何处理和应对安全事件及数据泄露?
    • 您如何在零信任 环境中管理和更新安全策略及控制措施?
    • 您如何确保第三方应用程序和服务符合 您的零信任原则?
    • 在零信任 环境中,您如何处理远程访问和自带设备(BYOD)?
    • 您如何对员工进行零信任原则和 实践的教育与培训?
  • “左移”安全

    • 您如何在开发流程的早期阶段 将安全测试整合到开发管道中?
    • 在开发阶段,您会进行哪些类型的安全测试?
    • 您如何向开发人员提供有关安全漏洞和 最佳实践的反馈?
    • 您如何赋能开发人员,使其对代码中的安全问题承担起责任?
    • 您如何确保安全要求被明确定义并 传达给开发人员?
    • 您如何衡量“左移”安全 举措的有效性?
    • 您如何处理代码中的 安全依赖项和第三方库?
    • 您如何管理和更新开发环境中的 安全配置?
    • 在开发过程中,如何处理安全例外情况以及与安全 政策的偏差?
    • 您如何在开发者中 倡导安全意识和责任感的文化?
  • 预防性网络防御

    • 您如何在潜在安全威胁 影响系统之前主动识别并加以缓解?
    • 您使用哪些工具和技术进行持续的安全监控和 分析?
    • 您如何响应并处理安全警报和安全事件?
    • 您如何模拟和测试事件响应计划?
    • 您如何及时掌握最新的安全威胁和 漏洞信息?
    • 您如何应对并缓解针对应用程序和 服务的 DDoS 攻击?
    • 您如何保护敏感数据免受内部威胁?
    • 您如何确保安全控制措施能有效抵御高级 持续性威胁(APT)?
    • 您如何处理供应链中的安全漏洞?
    • 您如何根据不断演变的威胁和技术调整安全态势?
  • AI 工作负载的安全性

    • 您如何确保AI模型和数据的安全?
    • 您如何解决AI模型中潜在的偏见和伦理问题?
    • 您如何保护AI模型免受对抗性攻击和数据 中毒的侵害?
    • 您如何确保AI模型中使用的数据隐私?
    • 您如何解释和解读AI模型做出的决策?
    • 您如何管理和控制对人工智能模型及数据的访问权限?
    • 您如何确保符合与 AI和ML相关的法规和标准?
    • 如何监控和检测人工智能模型行为中的异常?
    • 您如何处理和应对涉及人工智能 模型的安全事件?
    • 您如何对员工进行教育和培训,使其能够安全且负责任地 使用AI和ML?
  • 人工智能在安全领域的应用

    • 您如何利用AI和ML来增强安全防护能力?
    • 您使用哪些类型的人工智能模型来保障安全?
    • 您如何针对安全应用对AI模型进行训练和验证?
    • 您如何确保基于人工智能的安全 系统的准确性和可靠性?
    • 您如何处理基于人工智能的 安全系统产生的误报和漏报?
    • 您如何将基于人工智能的安全系统与现有的安全 基础设施进行集成?
    • 您如何管理和更新用于安全应用的人工智能模型?
    • 您如何解释和解读人工智能模型在 安全应用中做出的决策?
    • 如何确保在安全 领域中以符合伦理且负责任的方式使用人工智能和机器学习?
    • 如何衡量人工智能和机器学习在提升安全 态势方面的有效性?
  • 合规与隐私

    • 您需要遵守哪些合规框架和隐私标准?
    • 您如何评估和管理 Google Cloud 环境中的合规风险?
    • 如何确保存储和处理在 Google Cloud 中的敏感数据的隐私?
    • 您如何处理与隐私法规相关的 数据主体请求(DSR)?
    • 您如何记录和追踪合规活动及证据?
    • 您如何确保第三方供应商和合作伙伴遵守您的 法规和隐私要求?
    • 您如何处理与合规 法规相关的数据泄露和安全事件?
    • 您如何及时掌握合规与隐私 标准的最新变化?
    • 您如何对员工进行合规和 隐私要求的教育与培训?
    • 您如何向审计师和监管机构展示并证明合规性?

验证检查表

请使用以下检查清单,评估架构是否符合 安全建议:

  • 设计安全

    • 系统组件的选择是否基于其安全特性和 加固措施?
    • 是否已在网络、主机和应用程序 层实施了深度防御?
    • 是否使用了安全的库和应用程序框架来防范常见的 漏洞?
    • 是否已按照行业标准进行了风险评估?
  • 零信任

    • 是否根据用户身份和上下文(设备、 位置)实施了访问控制?
    • 是否使用私有连接方式(云互连、VPN)处理内部 流量?
    • 是否已在所有项目中禁用默认网络?
    • 是否已在敏感数据周围建立了VPC服务控制边界?
  • 左移安全

    • 是否使用“基础设施即代码” (例如 Terraform)来配置基础设施?
    • 是否已将自动化安全扫描集成到 CI/CD 管道中?
    • 是否有针对依赖项中漏洞的扫描和修补流程?
    • 是否使用二进制授权来确保仅部署受信任的镜像?
  • 预防性网络防御

    • 是否将威胁情报整合到安全运维中?
    • 是否已为所有关键资源启用并集中管理安全日志?
    • 是否针对常见安全威胁配置了自动化响应机制?
    • 是否通过定期测试或红队演练对防御措施进行验证?
  • AI安全与治理

    • AI 管道是否具备防范篡改和数据中毒的安全措施?
    • 在适当的情况下,是否对训练数据使用了 差分隐私或数据掩码技术?
    • 是否在模型治理中使用了 Vertex 可解释人工智能和公平性指标?
在 GitHub 上查看
---
name: google-cloud-waf-security
description: Evaluates Google Cloud workloads against the Well-Architected Framework security pillar, identifies security requirements, and provides actionable recommendations for IAM, network security, data protection, and operational security.
---

# Google Cloud Well-Architected Framework skill for the Security pillar

## Overview

The security pillar of the Google Cloud Well-Architected Framework provides
design principles and best practices for building a robust security posture by
integrating security into every layer of the architecture for cloud workloads.
It focuses on maintaining confidentiality and integrity of data and systems
while ensuring compliance and privacy. It provides a structured approach to risk
management, threat defense, and identity control, enabling you to operate cloud
workloads securely and at scale.

## Core principles

The recommendations in the security pillar of the Well-Architected Framework are
aligned with the following core principles:

-  **Implement security by design**: Integrate cloud security and network
   security considerations starting from the initial design phase of your
   applications and infrastructure. Google Cloud provides architecture
   blueprints and recommendations to help you apply this principle. Grounding
   document:
   https://docs.cloud.google.com/architecture/framework/security/implement-security-by-design.md.txt

-  **Implement zero trust**: Use a _never trust, always verify_ approach, where
   access to resources is granted based on continuous verification of trust.
   Google Cloud supports this principle through products like Chrome Enterprise
   Premium and Identity-Aware Proxy (IAP). Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/implement-zero-trust.md.txt

-  **Implement shift-left security**: Implement security controls early in the
   software development lifecycle. Avoid security defects before system changes
   are made. Detect and fix security bugs early, fast, and reliably after the
   system changes are committed. Google Cloud supports this principle through
   products like Cloud Build, Binary Authorization, and Artifact Registry.
   Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/implement-shift-left-security.md.txt

-  **Implement preemptive cyber defense**: Adopt a proactive approach to
   security by implementing robust fundamental measures like threat
   intelligence. This approach helps you build a foundation for more effective
   threat detection and response. Google Cloud's approach to layered security
   controls aligns with this principle. Google Cloud supports this principle
   through products like Security Command Center, Google Threat Intelligence,
   and Google SecOps. Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/implement-preemptive-cyber-defense.md.txt

-  **Use AI securely and responsibly**: Develop and deploy AI systems in a
   responsible and secure manner. The recommendations for this principle are
   aligned with guidance in the AI and ML perspective of the Well-Architected
   Framework and in Google's Secure AI Framework (SAIF). Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/use-ai-securely-and-responsibly.md.txt

-  **Use AI for security**: Use AI capabilities to improve your existing
   security systems and processes through Gemini in Security and overall
   platform-security capabilities. Use AI as a tool to increase the automation
   of remedial work and ensure security hygiene to make other systems more
   secure. Google Cloud supports this principle through products like Google
   Threat Intelligence and Google SecOps. Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/use-ai-for-security.md.txt

-  **Meet regulatory, compliance, and privacy needs**: Adhere to
   industry-specific regulations, compliance standards, and privacy
   requirements. Google Cloud helps you meet these obligations through products
   like Assured Workloads, Organization Policy Service, and our compliance
   resource center. Grounding document:
   https://docs.cloud.google.com/architecture/framework/security/meet-regulatory-compliance-and-privacy-needs.md.txt

## Relevant Google Cloud products

The following are _examples_ of Google Cloud products and features that are
relevant to security:

- **Identity and access management**

  - **Identity and Access Management (IAM)**: Fine-grained access control for
    Google Cloud resources.
  - **Identity-Aware Proxy (IAP)**: Secure access to applications without a VPN.
  - **Chrome Enterprise Premium**: Endpoint security and context-aware access.

- **Network security**

  - **Google Cloud Armor**: DDoS protection and Web Application Firewall (WAF).
  - **VPC Service Controls**: Define security perimeters to prevent data
    exfiltration.
  - **Cloud Next-Generation Firewall (NGFW)**: Advanced threat protection for
    network traffic.
  - **Shared VPC**: Centralized network management across projects.
  - **Cloud Interconnect and IPsec VPN**: Secure, private connectivity.

- **Data security**

  - **Cloud Key Management Service (KMS)**: Manage encryption keys.
  - **Sensitive Data Protection (formerly Cloud DLP)**: Discover and redact
    sensitive data.
  - **Confidential Computing**: Encrypt data in use (memory).

- **Security operations (SecOps)**

  - **Google SecOps (Chronicle)**: Threat detection and security analytics.
  - **Security Command Center (SCC)**: Centralized vulnerability and threat
    management.
  - **Cloud Logging and Cloud Monitoring**: Visibility into system activity.

- **Automation and supply chain**

  - **Cloud Build**: Secure CI/CD pipelines.
  - **Artifact Analysis**: Vulnerability scanning for container images.
  - **Binary Authorization**: Deploy-time policy enforcement.
  - **Assured open source software**: Use secured OSS packages.

## Workload assessment questions

Ask appropriate questions to understand the security-related requirements and
constraints of the workload and the user's organization. Choose questions from
the following list:

- **Security by design**:

  - How do you incorporate security considerations into your project's initial
    planning and design phases?
  - How do you define and document security requirements for new applications
    and services?
  - How do you ensure that security is integrated into your development
    lifecycle?
  - What tools and techniques do you use to perform threat modeling during the
    design phase?
  - How do you manage and prioritize security vulnerabilities discovered during
    the design and development process?
  - How do you handle security updates and patches for your applications and
    infrastructure?
  - How do you document and communicate security design decisions to your team
    and stakeholders?
  - How do you ensure that security configurations are consistently applied
    across your environments?
  - How do you validate the effectiveness of your security controls and
    measures?
  - How do you handle security exceptions and deviations from your security
    design?

- **Zero trust**:

  - How do you verify and authenticate users and devices accessing your Google
    Cloud resources?
  - How do you implement the principle of least privilege for access control?
  - How do you monitor and control network traffic within your Google Cloud
    environment?
  - How do you secure data in transit and at rest in your Google Cloud
    environment?
  - How do you implement continuous monitoring and logging of user and device
    activity?
  - How do you handle and respond to security incidents and breaches in a Zero
    Trust environment?
  - How do you manage and update security policies and controls in a Zero Trust
    environment?
  - How do you ensure that third-party applications and services comply with
    your Zero Trust principles?
  - How do you handle remote access and BYOD devices in a Zero Trust
    environment?
  - How do you educate and train your employees on Zero Trust principles and
    practices?

- **Shift-left security**:

  - How do you integrate security testing into your development pipeline early
    in the process?
  - What types of security testing do you perform during the development phase?
  - How do you provide developers with feedback on security vulnerabilities and
    best practices?
  - How do you empower developers to take ownership of security in their code?
  - How do you ensure that security requirements are clearly defined and
    communicated to developers?
  - How do you measure the effectiveness of your Shift Left security
    initiatives?
  - How do you handle security dependencies and third-party libraries in your
    code?
  - How do you manage and update security configurations in your development
    environment?
  - How do you handle security exceptions and deviations from your security
    policies in development?
  - How do you promote a culture of security awareness and responsibility among
    developers?

- **Preemptive cyber defense**:

  - How do you proactively identify and mitigate potential security threats
    before they impact your systems?
  - What tools and techniques do you use for continuous security monitoring and
    analysis?
  - How do you respond to and remediate security alerts and incidents?
  - How do you simulate and test your incident response plans?
  - How do you stay up-to-date with the latest security threats and
    vulnerabilities?
  - How do you handle and mitigate DDoS attacks against your applications and
    services?
  - How do you protect your sensitive data from insider threats?
  - How do you ensure that your security controls are effective against advanced
    persistent threats (APTs)?
  - How do you handle security vulnerabilities in your supply chain?
  - How do you adapt your security posture to evolving threats and technologies?

- **Security of AI workloads**:

  - How do you ensure the security of your AI models and data?
  - How do you address potential biases and ethical concerns in your AI models?
  - How do you protect your AI models from adversarial attacks and data
    poisoning?
  - How do you ensure the privacy of data used in your AI models?
  - How do you explain and interpret the decisions made by your AI models?
  - How do you manage and control access to your AI models and data?
  - How do you ensure compliance with regulations and standards related to
    AI and ML?
  - How do you monitor and detect anomalies in the behavior of your AI models?
  - How do you handle and respond to security incidents involving your AI
    models?
  - How do you educate and train your employees on the secure and responsible
    use of AI and ML?

- **AI for security**:

  - How do you leverage AI and ML to enhance your security posture?
  - What types of AI models do you use for security purposes?
  - How do you train and validate your AI models for security applications?
  - How do you ensure the accuracy and reliability of AI-based security
    systems?
  - How do you handle false positives and false negatives from AI-based
    security systems?
  - How do you integrate AI-based security systems with your existing security
    infrastructure?
  - How do you manage and update your AI models for security applications?
  - How do you explain and interpret the decisions made by your AI models for
    security applications?
  - How do you ensure the ethical and responsible use of AI and ML for security
    purposes?
  - How do you measure the effectiveness of AI and ML in improving your security
    posture?

- **Regulatory compliance and privacy**:

  - What regulatory compliance frameworks and privacy standards do you need to
    adhere to?
  - How do you assess and manage compliance risks in your Google Cloud
    environment?
  - How do you ensure the privacy of sensitive data stored and processed in
    Google Cloud?
  - How do you handle data subject requests (DSRs) related to privacy
    regulations?
  - How do you document and track compliance activities and evidence?
  - How do you ensure that third-party vendors and partners comply with your
    regulatory and privacy requirements?
  - How do you handle data breaches and security incidents related to compliance
    regulations?
  - How do you stay up-to-date with changes in regulatory compliance and privacy
    standards?
  - How do you educate and train your employees on regulatory compliance and
    privacy requirements?
  - How do you demonstrate and prove compliance to auditors and regulators?

## Validation checklist

Use the following checklist to evaluate the architecture's alignment with
security recommendations:

- **Security by design**:

  - Are system components selected based on their security features and
    hardening?
  - Is defense-in-depth implemented at the network, host, and application
    layers?
  - Are safe libraries and application frameworks used to prevent common
    vulnerabilities?
  - Is a risk assessment performed using industry standards?

- **Zero trust**:

  - Is access control enforced based on user identity and context (device,
    location)?
  - Are private connectivity methods (Cloud Interconnect, VPN) used for internal
    traffic?
  - Are default networks disabled in all projects?
  - Are VPC Service Controls perimeters established around sensitive data?

- **Shift-left security**:

  - Is infrastructure provisioned using Infrastructure as Code
    (e.g., Terraform)?
  - Are automated security scans integrated into the CI/CD pipeline?
  - Is there a process for scanning and patching vulnerabilities in
    dependencies?
  - Is Binary Authorization used to ensure only trusted images are deployed?

- **Preemptive cyber defense**:

  - Is threat intelligence integrated into security operations?
  - Is security logging enabled and centralized for all critical resources?
  - Are automated responses configured for common security threats?
  - Are defenses validated through periodic testing or red-teaming?

- **AI security and governance**:

  - Are AI pipelines secured against tampering and data poisoning?
  - Is differential privacy or data masking used for training data where
    appropriate?
  - Are Vertex Explainable AI and fairness indicators used for model governance?

所有文件

0 个文件

安装 google-cloud-waf-security

下载技能文件并将其解压到 .claude/skills/ 目录中。

下载ZIP

克隆仓库并复制技能文件到您的项目中。

git clone https://github.com/google/skills/tree/main/skills/cloud/google-cloud-waf-security # Copy SKILL.md to your .claude/skills/ directory

复制 复制
快速设置: 将技能文件夹复制到 .claude/skills/ Claude 会自动检测并使用该技能
仓库 google/skills

相关技能

gmgn-portfolio
更新时间 2026-07-01
zeroize-audit
更新时间 2026-07-01
device-integrity
更新时间 2026-06-29
flutter-use-http-package
更新时间 2026-06-30
OR