Instiq
Chapter 5 · Trust and security with Google Cloud·v1.0.0·Updated 6/16/2026·~15 min

What's changed: Created Cloud Digital Leader Chapter 5 (Domain 5 "Trust and security": cloud trust and Google’s secure infrastructure = CIA/defense in depth/encryption (at rest, in transit)/zero trust (BeyondCorp)/Cloud IAM (least privilege); trust principles, compliance, and security operations = data residency/sovereignty/compliance certifications/Security Command Center/Sensitive Data Protection (DLP)).

5.1Cloud trust and Google’s secure infrastructure

Key points

Understand the security basics of confidentiality, integrity, and availability (CIA), common threats, defense in depth, encryption at rest and in transit, zero trust (BeyondCorp), and Cloud IAM for least-privilege access control—from the perspective of Google’s secure infrastructure.

Cloud adoption rests on the trust of "can it be used safely." Security basics are the CIA triad: confidentiality (only authorized people can see it), integrity (it is not tampered with), and availability (usable when needed). To protect these, Google layers multiple defenses from data centers through hardware, network, and operations.

5.1.1Defense in depth and encryption

Defense in depth layers multiple defenses rather than relying on one control; even if a layer is breached, another contains the damage. The core of data protection is encryption: Google Cloud encrypts both at rest and in transit by default. Google manages keys by default, and customers can manage their own keys (CMEK) when required. The Google Cloud premise is that data is encrypted without any special configuration.

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.