What's changed: Created Professional Cloud Security Engineer Chapter 5 (Domain 5 "Compliance": determining technical needs, shared responsibility model, scoping, mapping requirements to services/controls, Access Transparency/Access Approval; Assured Workloads, organization policies (pre-built/custom), regionalization of data and services (resource location constraint), network/access segmentation, audit-log coverage).
5.2Compliance controls and regionalization
Understand configuring security controls that support compliance (Assured Workloads, organization policies, Access Transparency, Access Approval, regionalization of data and services) and implementing the mapping of compliance requirements to Google Cloud services/controls (network/access segmentation, audit-log coverage).
This is the stage of "enforcing requirements as controls." Combine managed controls for regulated environments with data-residency enforcement to maintain continuous compliance.
5.2.1Assured Workloads and enforcing controls
To run workloads in a controlled environment meeting regulatory requirements (data residency, personnel controls, sovereignty), use Assured Workloads (auto-applies controls aligned to a compliance regime). Enforce general guardrails with organization policies (pre-built/custom)—disallow external IPs, restrict resource regions—inherited down the hierarchy. For Google-side access, enable Access Transparency (visibility) and Access Approval (pre-approval). Map "a managed control set for regulated environments = Assured Workloads" and "org-wide guardrails = organization policies."
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

