Encryption in Transit: The Next Level in Cloud Security - Build What's Next

Hi There, Thank you for downloading the whitepaper

Whitepaper

Encryption in Transit: The Next Level in Cloud Security

READ FULL INTRODOWNLOAD AGAIN

5418

Of your peers have already downloaded this article

4:30 Minutes

The most insightful time you'll spend today!

Blog

Private Services Connect in Google Cloud Regions Enables Customers to Consume Services Faster

4612

Of your peers have already read this article.

2:00 Minutes

The most insightful time you'll spend today!

Google's Private Service Connect is now available for customers to create private and secure connections from their cloud networks to services like Cloud Storage or Cloud Bigtable and third-party services like Elastic, MongoDB or Snowflake!

At Google Cloud, we believe in making it simple and secure to consume services whether they’re from Google, a third party or customer-owned. With Private Service Connect, we have adopted a service-centric approach to our network that abstracts the underlying networking infrastructure. And today, we are announcing Private Service Connect is generally available in all Google Cloud regions.

Private Service Connect allows you to create private and secure connections from your cloud networks to services like Cloud Storage or Cloud Bigtable and third-party services like Elastic, MongoDB or Snowflake. It creates service endpoints in your VPCs that provide private connectivity and policy enforcement, allowing you to easily connect to services across different networks and organizations.

Customers told us they want to consume services faster while making sure that the connectivity is private and secure. In the past, achieving this was a challenge: networking teams had to negotiate IP address blocks, mutually agree on policies and coordinate as applications evolved to newer versions. With Private Service Connect, you can delegate the consumption and delivery of services to different teams without having to coordinate between teams.

How it works

private service connent.jpg

Private Service Connect makes it easy to consume services by leveraging service endpoints that are locally managed. The services can be in different projects or managed by different organizations. Access to the service is controlled by strict governance and IAM policies. Application teams and developers can focus on delivering their services easily by exposing their ‘service attachment’. No more worrying about networking constructs—Private Service Connect takes care of connecting to the service on the Google backbone for them.  

Benefits to our partners

Being able to consume services from a variety of software vendors and service providers makes it possible for enterprises to innovate faster. For that, developers need to be able to compose services from third-party vendors, Google managed services, as well as their own services. To help, third-party partners can use Private Service Connect to deliver multi-tenant services securely and at massive scale, and make the connectivity to their services appear as if they are running on the enterprises’ network. Private Service Connect will also integrate with Service Directory to register many producer services, making service consumption even simpler. 

“In today’s environment, where seamless access to real-time market information and the ability to handle increasingly vast volumes of data is essential, our clients are demanding native connectivity in the cloud. Google’s Private Service Connect offers the performance and reliability required by the types of mission critical apps that rely on Bloomberg’s tick for tick market data feed, B-PIPE.” —Cory Albert, Global Head of Cloud Strategy, Enterprise Data at Bloomberg 

“One of the key goals for Elastic on Google Cloud is to monitor and protect our customers’ data. Google Cloud’s Private Service Connect with Elastic Cloud furthers our commitment to our customers that together we make it quick, easy and secure to gain insights and intelligence from their data.” —Uri Cohen, Product Lead for Elastic Cloud

“MongoDB’s partnership with Google is an integral part of our strategy to support modern apps and mission-critical databases and to become a cloud data company. Private Service Connect allows our customers to connect to MongoDB Atlas on Google Cloud seamlessly and securely and we’re excited for customers to have this additional and important capability.”—Andrew Davidson, VP of Cloud Product, MongoDB

Check out the Google Cloud Console to try it today.

Blog

Best Kept Security Secrets: How Assured Workloads Accelerates Security

1222

Of your peers have already read this article.

5:00 Minutes

The most insightful time you'll spend today!

Google Cloud's Assured Workloads enhances compliance and security for regulated sectors, revolutionizing the "govcloud" experience by balancing regulation with cloud innovation. Find out more...

Digital transformation is now a strategic imperative for organizations across every industry. For governments and regulated businesses, moving services to the cloud poses a unique set of challenges.

As a vital enabler of transformation, the cloud can unlock innovation and help keep pace with the accelerating pace of digital business. Unfortunately, many government agencies and firms in regulated industries don’t have the luxury of adopting new systems at will. They must deal with issues such as limited resources, lack of digital skills, and siloed operations. However, they also face cloud-specific challenges, including: 

  • Data sovereignty: Regulated industries and the public sector often have concerns about the location of data, how it is protected, who else can access it, and whether it is stored in a secure location.
  • Compliance: Government agencies and regulated businesses must ensure that their data and cloud use are compliant with all applicable government requirements, privacy and data protection laws, and other regulations.
  • Security: Compliance is a natural component of any strong approach to security. As a result, government regulations and industry standards mandate a responsibility to secure and protect data from unauthorized access or use. 
  • Cost: Every organization wants to ensure it’s getting good value for their money when using cloud computing, but especially government agencies that are more likely to be working with fixed budgets and fewer resources. 

To address the unique requirements of governments and other highly regulated organizations, some cloud providers have built separate government clouds (“GovClouds”) that run in specialized, stand-alone data centers that make it easier to meet specific requirements around data residency, personnel controls, and other government standards. However, isolated GovCloud environments come with limitations: They can restrict the ability to integrate regulated data with data from other sources, they create siloed infrastructure that can slow down access to new features and technologies, and they usually require more resources to manage and maintain, which translates into higher costs for end-users of GovCloud services.

But what if you could get the features of a government cloud — the certifications and strict controls on data residency and personnel access — on a commercial cloud? 

This is where Assured Workloads comes in. Assured Workloads is a unique Google Cloud service that allows governments and organizations from regulated industries to meet stringent compliance requirements at scale on commercial cloud infrastructure. 

What is Assured Workloads?

Assured Workloads provides a set of security controls and guardrails you can apply to your cloud environments, making it easier to achieve compliance while maintaining the advantages of a full commercial cloud. It includes features like data residency controls for specific compliance types, data and personnel access controls, and real-time monitoring for compliance violations to ensure you implement and maintain the cloud controls required by your compliance regimes. 

Check out our Best Kept Security Secrets series

Assured Workloads can make it easier for agencies and businesses in regulated sectors to meet compliance requirements by providing: 

  • A secure and compliant environment: With Assured Workloads, you can create controlled environments for your regulated workloads and automatically enforce data location and resource deployment. It’s designed for customers that need to meet strict security and compliance requirements, such as the government, healthcare, and financial services sectors. 
  • Broad security capabilities: Assured Workloads provides comprehensive security for your regulated workloads. Data is encrypted at rest and in transit by default and includes additional features, such as encryption key management according to your compliance regime and Identity and Access Management (IAM) for authentication, authorization, and user access management. 
  • Support for multiple compliance frameworks: Assured Workloads is designed to create regulated boundaries on public cloud infrastructure that support multiple compliance frameworks across sectors, including FedRAMP, IL5, PCI DSS, SOC 2, HIPAA, and HITRUST, allowing customers to segment and label their regulated data.
  • Control data residency: Assured Workloads gives you the ability to control the regions where data at rest is stored. 
  • Assured support: Assured Workloads’ approach ensures only Google Cloud support personnel meeting specific geographical locations and personnel conditions support customers’ workloads.

Instead of having to configure, manage, and maintain the right controls and guardrails yourself, you select the regulatory framework you need to follow. Assured Workloads automatically configures and deploys the controls needed to help meet your requirements. 

With these specific capabilities, governments can simplify compliance configurations and monitor for violations without missing out on Google Cloud’s innovative technologies, scalability, performance, reliability, and cost savings that are hallmarks of our commercial Cloud offering. 

How it works

When you use Assured Workloads to create controlled environments in Google Cloud, you will be required to set up an Assured Workloads folder. This folder acts as the regulatory boundary to help enforce your chosen compliance framework. They are created with preconfigured platform controls, which are packaged based on the specified regulated data type, personnel controls, and data location. 

Assured Workloads automatically restricts developers to using products and services that are in-scope for your selected compliance framework. Security controls are mapped to Assured Workloads folders, so any Google Cloud resources you deploy in an Assured Workloads folder inherit the same controls. This also helps ensure that only Google Cloud personnel who meet your compliance requirements have the ability to support your resources and prevents resources from being deployed outside of compliant regions. 

Depending on your compliance regime, Assured Workloads supports several different options for encryption. You can use any Google key management service unless your compliance requirements mandate otherwise, including Cloud Key Management Service, Cloud External Key Manager, or customer-managed encryption keys (CMEK). You can also choose Google-managed keys, which provide on-by-default FIPS-validated encryption. 

Here are a few common use cases that companies are already accomplishing with Assured Workloads:

However, Assured Workloads is more than a better government cloud or a tool for highly regulated businesses. Assured Workloads is a packaged solution that provides security by default and removes toil and complexity for users. Users can reduce the time and effort required to meet their compliance requirements and also improve the security of their data.

Do I need Assured Workloads? 

We believe that cloud adoption for governments, government suppliers and contractors, and other strictly regulated businesses shouldn’t have to happen in a separate, isolated cloud environment that forces tradeoffs in terms of service availability, scale, and cost. Assured Workloads is a new approach to running regulated workloads that transforms the “govcloud” into a capability that cuts down on the friction of compliance without sacrificing any of the cloud-y goodness. 

To learn more about Assured Workloads, please review these resources: 

Request a free trial today and experience how Aside Assured Workloads helps you achieve compliance-based outcomes.

Blog

Find the Best Kept Security Secrets to Harness the Power of Organization Policy Service

2685

Of your peers have already read this article.

2:30 Minutes

The most insightful time you'll spend today!

Explore the comprehensive guide to Google Cloud’s Organization Policy Service and learn how to enhance security, compliance, and efficiency within your cloud environment. Read more...

The canvas of cloud resources is vast, ready for an ambitious organization to craft their digital masterpiece (or perhaps just their business.) Yet before the first brush of paint is applied, a painter in the cloud needs to think about their frame: What shape should it take, what material is it made of, how will it look as a border against the canvas of their cloud service. Google Cloud’s Organization Policy Service is just such a frame, a broad set of tools for our customer’s security teams to set broad yet unbendable limits for engineers before they start working.

Google Cloud’s Organization (org) Policy Service is one of our most dramatic features but is often under-appreciated by security teams. It provides for a separation of duties by focusing on what users can do, and lets the administrator set restrictions on specific resources to determine how they can be configured. This drives defense in depth from configuration errors as well as defense in depth from attacks. An org policy lets the administrator enforce compliance and conformance at a higher level than Identity and Access Management, which focuses on which users can access specific resources.

Org policies can reduce toil and can improve security at the scale needed by today’s cloud users. Financial services provider HSBC is one of Google Cloud’s largest customers and has been using org policies for years to help it manage cloud resources across its highly-regulated enterprise environment. As the company explains in this video, HSBC’s creative use of org policies manages more than 15,000 service accounts and 40,000 IT professionals. They control 6.5 million virtual machines per year. That’s 22,500 virtual machines per day, and only 2,500 of those VMs exist for more than 24 hours

HSBC prefers org policies instead of other preventative controls because they are native to Google Cloud and can be enforced independently of how the request originated (such as from Infrastructure-as-Code, Google Cloud services interacting with each other, or a user in the UI.) Detecting resource violations is expensive for many customers, and often comes too late to prevent harm. Org Policies can be deployed to prevent violations from occurring and eliminate detection and remediation costs.

Importantly, HSBC’s custom installation is designed so that org policy violations are immediately discoverable, which can help HSBC personnel quickly understand how to quickly and accurately correct an error condition. When an action violates org policy, an error code is returned telling the resource requester which policy was violated. Corresponding logs are generated for administrators to monitor and provide further troubleshooting.

Diagram of the organization policy workflow


Here are two additional use cases that further illustrate the power of organization policies.

  • Organizations that operate in a region with rigorous data residency requirements can configure and enable the Location org policy to help ensure that all resources created (such as VMs, clusters, and buckets) are deployed in a particular cloud region.
  • Admins who want to ensure that only trusted workloads are deployed for Google Kubernetes Engine (GKE) or Cloud Run may want to restrict developers to only use verified images in their deployment processes. They can create a custom org policy that targets GKE cluster resource type and create and update methods to block the creation or update of any clusters that do not have binary authorization enforced.

How it works

Google Cloud offers more than 80 org policies that can be used to restrict and govern interactions with Google Cloud services and resources across important domains such as security, reliability, and compliance. Org policies can help:

  • Restrict resource and service access to the organization domain only, secure public access to resources, or stop service account key abuse.
  • Enforce use of global or regional DNS, and global or regional load balancing, to Improve service reliability and availability.
  • Specify which services can access resources, in which regions, and at what times in support of compliance objectives.
  • Secure Virtual Private Cloud (VPC) networks and reduce data exfiltration risk by preventing data from leaving a specific perimeter.

See the Organization Policy Service list of constraints for more about org policies and constraints.

You can also use the recently introduced Custom Organization Policies to tailor guardrails so they meet your specific compliance and security requirements. With Custom Organization Policies, security administrators can create their own constraints using Common Expression Language (CEL) to define which resource configurations are allowed or denied. Administrators can develop and deploy new policies and constraints in minutes.

With great power comes great responsibility, so with that in mind we will soon be introducing Dry Run for Custom Org Policies. It will let users put a policy in an audit-only mode to observe behavior during real operations without putting production workloads at risk.

Getting started

1. Setting up your first org policy is straightforward. An organization policy administrator enables a new organization policy on a Google Cloud organization, folder, or project in scope. Once set, the administrator then determines and applies the constraints. Here’s how it works:Design your constraint, which is a particular type of restriction against either a single Google Cloud service or a group of Google Cloud services. You can choose from the list of available built-in constraints by configuring desired restrictions and exceptions (based on tags) or create custom org policies.

It’s important to remember that descendants of the targeted resource hierarchy node inherit the org policy. By applying an organization policy to the root organization node, you can drive enforcement of that organization policy and configuration of restrictions across your organization.

2. Deploy the org policy to evaluate and allow or deny resource Create, Update, and Delete operations. This can be done through the Google Cloud console, gCloud, or via API.

3. Monitor audit logs and your Security Command Center Premium findings to detect and respond to policy violations.

Do I need an org policy?

Org policies can help maintain security and compliance at scale while also allowing development teams to work rapidly. Because they give you the ability to set broad guardrails, they can help ensure compliance without adding operational overhead and monitor policy violations.

To learn more about org policy, please review these resources:

Blog

Google’s BeyondCorp to Accelerate U.S. Govt’s Zero Trust Journey

3006

Of your peers have already read this article.

3:00 Minutes

The most insightful time you'll spend today!

Security attacks from 2020, raised concerns on the exploitability of the govt resources. U.S. Federal agencies to improve security are directed to implement Zero Trust architectures. Learn how Google's BeyondCorp accelerates this journey.

In May, the White House issued an Executive Order aiming to improve the nation’s cybersecurity defenses and requiring US Federal agencies to develop plans to implement Zero Trust architectures in alignment with National Institute of Standards and Technology National Institute of Standards and Technology (NIST) guidance. This Executive Order also calls on agencies to accelerate cloud adoption, with a preference for cloud capabilities that implement or advance the adoption of Zero Trust

Zero Trust moves front and center 

The White House guidance is timely and necessary given the surge of ransomware and other cyber attacks over the past year targeting remote workers and VPNs, software supply chains, identity infrastructure and email, and various critical infrastructure sectors. These attacks have raised concerns about cyber-risk across the board, including pervasive IT monocultures that persist, unquestioned, despite their exploitability by attackers. 

White House

This order ties together multiple strands of US cybersecurity best practices and policy that have evolved over the past decade, including stronger identity and access controls, expanded use of encryption and authentication, increased monitoring and visibility, and prioritizing high-value IT assets. Yet the urgent challenge of cybersecurity requires more than simply adding to the existing proliferation of cyber tools or ratcheting up traditional measures around hygiene and compliance. The Administration’s focus on Zero Trust marks a critical shift to prioritizing architectures in which the strategic coordination of layered cyber defenses drives improved cyber outcomes.  

In many ways then, the demand for accelerating the adoption of Zero Trust in federal IT is not a new requirement, as departments and agencies are already implementing many of the core technical components that can contribute to achieving the goals laid out in the executive order.  

What is new, however, is the fact that Zero Trust, when done right, is primarily an outcomes-oriented approach to security. Successfully implementing Zero Trust can drive down cyber risk, transform the daily security experience of users, reduce management complexity and toil for IT managers, and improve the overall productivity of the workforce. 

Outcomes, not just technology 

Successfully implementing Zero Trust is not about the individual technology components and inputs themselves.  Instead, what matters most is how security components are integrated and orchestrated to achieve and enforce a simple set of core principles: 

  • Connecting from a particular network must not determine which services you can access
  • Access to services and data is granted based on what we know about you and your device
  • All access to services must be authenticated, authorized and encrypted.  

Using this set of principles as our north star, Google began our Zero Trust journey, with BeyondCorp, over a decade ago, under similar circumstances to those driving federal cybersecurity policy now. Google had been targeted by nation-state cyber attacks (Operation Aurora), and in the aftermath, we recognized that providing remote access with VPNs was not sustainable or efficient for business performance, especially at a time when Google’s global workforce was growing rapidly. Something had to change.

To improve our security posture and user experience, we had to reimagine our infrastructure and production networks. This ultimately drove innovations in how we protect our supply chains and resulted in a complete rethinking of the scale, analytics and visibility needed to fully modernize and transform enterprise security. The journey forced us to consolidate redundant systems, understand usage patterns better, and transform how people experience security day to day.

Safe Cybersecurity

A shift in technology and a change in mindset

When we developed BeyondCorp, we had to reimagine our infrastructure and production networks in order to affect a better security posture and user experience. This ultimately drove innovations in how we protect our supply chains and resulted in a complete rethinking of the scale, analytics and visibility needed to fully modernize and transform enterprise security. 

Moving to a Zero Trust approach drastically changed how Google’s end users did business and reduced the toil on both individual users and IT professionals to do their part to secure the enterprise, further fostering  the innovation, architectures, operational integrations and best practices we see today. Now, the layered defenses and invisible security our users experience have been incorporated into Google’s secure cloud offerings, so our customers can experience the same benefits and provide their users with a secure and productive work environment. 

Leadership for a cross-team journey

Of course, change isn’t trivial, especially in government. A shift in behavior, user experience, collaboration, tools and infrastructure requires planning, change management, and executive support.  To make the Zero Trust journey a success, organizations need the long-term focus and vision of leadership to drive meaningful change. For traditional security and technology leaders, accelerating the journey to Zero Trust will require them to think less tactically and and act more strategically, in order to focus more on outcomes and less on inputs, and to integrate, harmonize, orchestrate and automate what were previously standalone IT and security efforts.  For non-technology leaders, their engagement and leadership is essential – and much more likely – given the visible benefits to collaboration, culture, and the business from what could otherwise be seen as a technology-centric initiative.      

Done right, Zero Trust brings a sea change from how most people experience security.  The crossroads of the Zero Trust journey present organizations with two clear choices: stick with an old and not-so-secure security model that’s clunky and burdensome, or adopt a new model that’s more intuitive, easy, and secure.  

Jump start your own journey

Today, the same opportunity exists to transform government security, operations, and organizational models by implementing Zero Trust. By sharing lessons learned from Google’s BeyondCorp journey and building core security capabilities into many of our cloud products, our goal is to help government agencies  accelerate their own Zero Trust journey, transforming the security posture of their highest value and most-critical applications and data.  

To learn more, watch our on-demand sessions from the Google Cloud Government Security Summit,

About the authors

Dan Prieto previously served in the White House as Director for Cybersecurity Policy on the staff of the National Security Council.  He also served as CTO and Director of the Defense Industrial Base Cybersecurity Program in the Office of the Department of Defense CIO.

Max Saltonstall tells stories about Google Cloud, how we use similar Cloudy tools inside Google, and what diverse solutions Cloud’s many customers have created. At Google he’s worked within DoubleClick, Corporate Engineering, Staffing and the Cloud CTO Office.

4532

Of your peers have already watched this video.

31:00 Minutes

The most insightful time you'll spend today!

Explainer

How Google Secures its Data Centers: Watch Video

Security is in the DNA of Google Cloud’s dozens of data centers, complex network and workloads scattered the globe. Take a tour to the nucleus of data center’s six layers of physical security designed to keep unauthorized access at bay, and also learn about Google Cloud’s security fundamentals to leverage the same philosophy on Google Cloud. Watch now!

More Relevant Stories for Your Company

Blog

Predicting Cyber Attacks: Security Command Center Introduces Attack Path Simulation

To help secure increasingly complex and dynamic cloud environments, many security teams are turning to attack path analysis tools. These tools can enable them to better prioritize security findings and discover pathways that adversaries can exploit to access and compromise cloud assets such as virtual machines, databases, and storage buckets.

Blog

Launches and Stories on Google Cloud Security from Q1: Fresh off the Boat!

The security world keeps changing, with new tools and new threats in the ever-evolving arms race that is cybersecurity. To keep you up to speed on all that Google Cloud is doing to help safeguard your data and your applications, welcome to the first installment of the Security Roundup. In

Blog

Takeaways from the Google Cloud Public Sector Summit on Prioritizing Tech Investments

Editor’s note: Today’s post highlights five takeaways from our session at the first ever Google Cloud Public Sector Summit. To watch the full session, check out All the Right Moves: Prioritizing Investments in Technology. Now more than ever, government agencies need to invest in digital services to fulfill their missions and better

Blog

reCAPTCHA Keeps Unemployment Claims and COVID Vaccine Registration Portals Threat-free

More people than ever have been conducting more of their lives online due to the COVID-19 pandemic. This creates a new landscape for fraudsters to create and release new attacks. Research commissioned by Forrester Consulting showed 84% of companies have seen an increase in bot attacks. 71% of organizations have seen an

SHOW MORE STORIES