What's changed: Created Cloud Digital Leader Chapter 5 (Domain 5 "Trust and security": cloud trust and Google’s secure infrastructure = CIA/defense in depth/encryption (at rest, in transit)/zero trust (BeyondCorp)/Cloud IAM (least privilege); trust principles, compliance, and security operations = data residency/sovereignty/compliance certifications/Security Command Center/Sensitive Data Protection (DLP)).
5.2Trust principles, compliance, and security operations
Understand data residency and sovereignty, industry and regional compliance certifications, Google’s transparency and privacy principles, and security operations services such as Security Command Center for visualizing cloud-wide risk and Sensitive Data Protection for protecting sensitive data.
Using cloud with confidence requires not only encryption and IAM but governance over "where data resides, which regulations it complies with, and how risk is monitored." Google publishes trust principles and provides services to support them.
5.2.1Data residency and sovereignty
Data residency refers to which geographic location (region) data is stored in. Many countries and industries require, e.g., "store within the country," and Google Cloud meets this by letting you choose the region. The deeper concept of data sovereignty requires that data be subject to that country’s laws. These are key decision factors when adopting cloud in heavily regulated industries (finance, public sector, healthcare).
5.2.2Compliance and transparency
Google Cloud holds many compliance certifications—ISO 27001, SOC 1/2/3, PCI DSS, and various national regulations—which customers can leverage in their own audits. Current status is available in the Compliance Resource Center. On privacy, Google states principles such as "customer data belongs to the customer," "we do not use it for advertising," and "access is logged transparently." These form the trust foundation for regulated industries moving to the cloud.
5.2.3Security operations services
| Service | Role | When to use |
|---|---|---|
| Security Command Center | Visualize cloud-wide risk/threats | Centrally monitor misconfig/vulns |
| Sensitive Data Protection (DLP) | Discover/classify/mask sensitive data | Detect and protect PII |
| Cloud IAM | Access control (least privilege) | Who may do what |
Security Command Center is the center of security posture management, centrally visualizing misconfigurations, vulnerabilities, and threats across the cloud environment. Sensitive Data Protection (formerly Cloud DLP) automatically discovers, classifies, and masks sensitive data such as PII in stored data. Combined with Cloud IAM, these enable operations that "know what to protect, protect it with least privilege, and continuously monitor risk."
Common: requirement → term/service. E.g., "store data within the country" = data residency; "subject to that country’s laws" = data sovereignty; "audits via ISO/SOC/PCI certifications" = compliance; "centrally visualize cloud-wide risk" = Security Command Center; "discover and mask PII" = Sensitive Data Protection (DLP).
Watch the mix-ups: (1) data residency (where stored) vs data sovereignty (which laws apply) differ. (2) Security Command Center (posture visibility/threat detection) vs Sensitive Data Protection (discover/protect sensitive data) have different roles. (3) Google holds the certifications, but configuration and operations remain shared responsibility (the customer still has duties).
5.2.4Section summary
- Data residency (storage location = region choice) and data sovereignty (applicable law) are distinct
- Google Cloud holds many certs (ISO/SOC/PCI); customers leverage them for audits, but operations are shared responsibility
- Security Command Center = centralized risk visibility; Sensitive Data Protection (DLP) = discover/protect sensitive data
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. Which term refers to which geographic location (region) data is stored in?
Q2. Which Google Cloud service centrally visualizes misconfigurations, vulnerabilities, and threats across the cloud?
Q3. Which service automatically discovers, classifies, and masks sensitive data such as PII?
Q4. How do certifications like ISO 27001, SOC, and PCI DSS mainly help in cloud adoption?
Q5. Which concept requires that data be subject to a particular country’s laws?
Q6. Which is a correct Google privacy principle?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

