5Designing for security and compliance
- 5.1IAM, least privilege, and organizational governance
Understand designing least privilege with IAM (avoid basic roles; predefined/custom roles), service accounts and Workload Identity Federation, enforcing constraints with organization policies, and designing permission inheritance and guardrails along the resource hierarchy.
- 5.2Data protection and compliance
Understand encryption at rest/in transit and key management (GMEK/CMEK/CSEK/Cloud KMS), discovering and protecting sensitive data (Sensitive Data Protection / Cloud DLP), data residency and sovereignty, and regulatory compliance via Assured Workloads and audit logs.

