Instiq
Chapter 5 · Supporting compliance requirements·v1.0.0·Updated 6/15/2026·~14 min

What's changed: Created Professional Cloud Security Engineer Chapter 5 (Domain 5 "Compliance": determining technical needs, shared responsibility model, scoping, mapping requirements to services/controls, Access Transparency/Access Approval; Assured Workloads, organization policies (pre-built/custom), regionalization of data and services (resource location constraint), network/access segmentation, audit-log coverage).

5.2Compliance controls and regionalization

Key points

Understand configuring security controls that support compliance (Assured Workloads, organization policies, Access Transparency, Access Approval, regionalization of data and services) and implementing the mapping of compliance requirements to Google Cloud services/controls (network/access segmentation, audit-log coverage).

This is the stage of "enforcing requirements as controls." Combine managed controls for regulated environments with data-residency enforcement to maintain continuous compliance.

5.2.1Assured Workloads and enforcing controls

To run workloads in a controlled environment meeting regulatory requirements (data residency, personnel controls, sovereignty), use Assured Workloads (auto-applies controls aligned to a compliance regime). Enforce general guardrails with organization policies (pre-built/custom)—disallow external IPs, restrict resource regions—inherited down the hierarchy. For Google-side access, enable Access Transparency (visibility) and Access Approval (pre-approval). Map "a managed control set for regulated environments = Assured Workloads" and "org-wide guardrails = organization policies."

5.2.2Regionalization and segmentation

For data-sovereignty requirements, use regionalization of data and services (data residency) to confine storage/processing to a geography (enforced via the org-policy resource location constraint). Implement compliance per the mapping: network segmentation (VPC/subnets/firewall/VPC Service Controls), access segmentation (IAM least privilege/separation of duties), and audit-log coverage (Cloud Audit Logs, Data Access, aggregated sinks) to produce evidence. Map "confine storage/processing to a region = regionalization + resource location constraint."

Exam point

Common: requirement → means. E.g., "apply a control set aligned to a compliance regime" = Assured Workloads; "confine data to a country/region" = regionalization (resource location constraint); "disallow external IPs org-wide" = organization policy; "evidence of data isolation" = VPC Service Controls + network segmentation; "access isolation" = IAM least privilege + separation of duties.

Warning

Watch the mix-ups: (1) Assured Workloads (a control set for regulated environments) vs individual org policies differ in granularity—Assured Workloads applies comprehensively. (2) Regionalization is enforced by the resource location constraint—don't leave it to the app. (3) Compliance means "being able to show evidence"—keep audit-log coverage and control mapping.

Diagram of Assured Workloads (control set for regulated environments), organization policies (e.g., no external IP), regionalization (resource location constraint), and network/access segmentation + audit-log coverage to produce evidence.
Enforce as controls

5.2.3Section summary

  • Regulated environment = Assured Workloads; org-wide guardrails = organization policies; Google access via Access Transparency/Approval
  • Data sovereignty = regionalization (enforced by resource location constraint)
  • Implementation = network/access segmentation + audit-log coverage to produce evidence

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. To run workloads in a controlled environment that applies a set of data-residency/personnel/sovereignty controls aligned to a regulatory regime, which is best?

Q2. To enforce at the org level a requirement that data storage/processing stay within a specific country/region, which is best?

Q3. To enforce an org-wide guardrail "no VMs with external IPs" via inheritance, which is best?

Q4. To map a compliance requirement "isolate network and access" to Google Cloud controls, which combination is best?

Q5. To stay "able to show evidence" in a compliance audit, which is most important?

Check your understandingPractice questions for Chapter 5: Supporting compliance requirements

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.