What's changed: Created Cloud Digital Leader Chapter 5 (Domain 5 "Trust and security": cloud trust and Google’s secure infrastructure = CIA/defense in depth/encryption (at rest, in transit)/zero trust (BeyondCorp)/Cloud IAM (least privilege); trust principles, compliance, and security operations = data residency/sovereignty/compliance certifications/Security Command Center/Sensitive Data Protection (DLP)).
5.2Trust principles, compliance, and security operations
Understand data residency and sovereignty, industry and regional compliance certifications, Google’s transparency and privacy principles, and security operations services such as Security Command Center for visualizing cloud-wide risk and Sensitive Data Protection for protecting sensitive data.
Using cloud with confidence requires not only encryption and IAM but governance over "where data resides, which regulations it complies with, and how risk is monitored." Google publishes trust principles and provides services to support them.
5.2.1Data residency and sovereignty
Data residency refers to which geographic location (region) data is stored in. Many countries and industries require, e.g., "store within the country," and Google Cloud meets this by letting you choose the region. The deeper concept of data sovereignty requires that data be subject to that country’s laws. These are key decision factors when adopting cloud in heavily regulated industries (finance, public sector, healthcare).
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

