Network and Data Security - GCP Professional Cloud Security Engineer¶
Overview¶
Network security architecture, data protection, encryption, DLP, and security controls for protecting GCP resources and data.
Network Security¶
VPC Security Controls¶
Private Google Access: Access Google APIs without external IPs VPC Service Controls: Perimeter security for APIs Private Service Connect: Private access to SaaS Shared VPC: Centralized network management
VPC Service Controls Example:
# Create access policy
gcloud access-context-manager policies create --organization=ORG_ID --title="Corporate Policy"
# Create perimeter
gcloud access-context-manager perimeters create secure_perimeter \
--policy=POLICY_ID \
--resources=projects/PROJECT_NUMBER \
--restricted-services=storage.googleapis.com,bigquery.googleapis.com \
--access-levels=LEVEL_NAME
Firewall Rules¶
Hierarchy: 1. Hierarchical firewall policies (org/folder level) 2. VPC firewall rules (network level) 3. Implicit deny all ingress 4. Implicit allow all egress
Best Practices:
# Deny-all baseline
gcloud compute firewall-rules create deny-all \
--network=my-vpc \
--action=deny \
--rules=all \
--priority=65534
# Allow specific traffic
gcloud compute firewall-rules create allow-ssh-from-iap \
--network=my-vpc \
--allow=tcp:22 \
--source-ranges=35.235.240.0/20 \
--target-service-accounts=bastion-sa@project.iam.gserviceaccount.com
Cloud Armor¶
DDoS Protection and WAF:
# Create security policy
gcloud compute security-policies create my-policy
# Rate limiting rule
gcloud compute security-policies rules create 100 \
--security-policy=my-policy \
--expression="origin.region_code == 'CN'" \
--action=deny-403
# OWASP rules
gcloud compute security-policies rules create 200 \
--security-policy=my-policy \
--expression="evaluatePreconfiguredExpr('sqli-v33-stable')" \
--action=deny-403
Identity-Aware Proxy (IAP)¶
Zero Trust Access:
# Enable IAP
gcloud iap web enable \
--resource-type=backend-services \
--service=SERVICE_NAME
# Grant access
gcloud iap web add-iam-policy-binding \
--resource-type=backend-services \
--service=SERVICE_NAME \
--member=user:alice@example.com \
--role=roles/iap.httpsResourceAccessor
Data Protection¶
Encryption¶
Data at Rest: - Google-managed encryption keys (default) - Customer-managed encryption keys (CMEK) - Customer-supplied encryption keys (CSEK)
CMEK Implementation:
# Create key ring and key
gcloud kms keyrings create my-keyring --location=us-central1
gcloud kms keys create my-key \
--keyring=my-keyring \
--location=us-central1 \
--purpose=encryption
# Grant service account access
gcloud kms keys add-iam-policy-binding my-key \
--keyring=my-keyring \
--location=us-central1 \
--member=serviceAccount:service-PROJECT_NUMBER@compute-system.iam.gserviceaccount.com \
--role=roles/cloudkms.cryptoKeyEncrypterDecrypter
# Create encrypted disk
gcloud compute disks create encrypted-disk \
--size=100GB \
--kms-key=projects/PROJECT/locations/us-central1/keyRings/my-keyring/cryptoKeys/my-key
Data in Transit: - TLS 1.2+ for external connections - Google Front End (GFE) SSL/TLS termination - BoringSSL for internal Google traffic - VPN/Interconnect for hybrid
Data Loss Prevention (DLP)¶
Sensitive Data Discovery:
from google.cloud import dlp_v2
def inspect_content(project, content):
dlp = dlp_v2.DlpServiceClient()
inspect_config = {
"info_types": [
{"name": "EMAIL_ADDRESS"},
{"name": "PHONE_NUMBER"},
{"name": "CREDIT_CARD_NUMBER"},
{"name": "US_SOCIAL_SECURITY_NUMBER"}
],
"min_likelihood": dlp_v2.Likelihood.LIKELY,
"limits": {"max_findings_per_request": 0}
}
item = {"value": content}
parent = f"projects/{project}"
response = dlp.inspect_content(
request={"parent": parent, "inspect_config": inspect_config, "item": item}
)
return response.result.findings
De-identification:
def deidentify_with_mask(project, content):
dlp = dlp_v2.DlpServiceClient()
deidentify_config = {
"info_type_transformations": {
"transformations": [
{
"primitive_transformation": {
"character_mask_config": {
"masking_character": "*",
"number_to_mask": 0
}
}
}
]
}
}
response = dlp.deidentify_content(
request={
"parent": f"projects/{project}",
"deidentify_config": deidentify_config,
"item": {"value": content}
}
)
return response.item.value
Secret Management¶
Secret Manager:
from google.cloud import secretmanager
def create_secret(project_id, secret_id, secret_value):
client = secretmanager.SecretManagerServiceClient()
parent = f"projects/{project_id}"
# Create secret
secret = client.create_secret(
request={
"parent": parent,
"secret_id": secret_id,
"secret": {"replication": {"automatic": {}}}
}
)
# Add version
version = client.add_secret_version(
request={
"parent": secret.name,
"payload": {"data": secret_value.encode("UTF-8")}
}
)
return version.name
def access_secret(project_id, secret_id, version_id="latest"):
client = secretmanager.SecretManagerServiceClient()
name = f"projects/{project_id}/secrets/{secret_id}/versions/{version_id}"
response = client.access_secret_version(request={"name": name})
return response.payload.data.decode("UTF-8")
Security Monitoring¶
Security Command Center¶
Asset Discovery and Vulnerability Scanning:
# List findings
gcloud scc findings list ORGANIZATION_ID \
--filter="state=\"ACTIVE\"" \
--format="table(category, resourceName, eventTime)"
# Create notification
gcloud scc notifications create my-notification \
--organization=ORG_ID \
--pubsub-topic=projects/PROJECT/topics/scc-notifications \
--filter="state=\"ACTIVE\" AND severity=\"HIGH\""
Cloud Audit Logs¶
Types: - Admin Activity: Free, always enabled - Data Access: Optional, additional cost - System Events: Free, always enabled - Policy Denied: Free, always enabled
Monitoring IAM Changes:
SELECT
timestamp,
protoPayload.authenticationInfo.principalEmail as user,
protoPayload.methodName as action,
protoPayload.resourceName as resource
FROM
`project.dataset.cloudaudit_googleapis_com_activity_*`
WHERE
protoPayload.serviceName = "iam.googleapis.com"
AND timestamp > TIMESTAMP_SUB(CURRENT_TIMESTAMP(), INTERVAL 24 HOUR)
ORDER BY timestamp DESC;
Compliance Frameworks¶
GDPR Implementation¶
Requirements: 1. Data residency (EU regions) 2. Data encryption (CMEK) 3. Access controls (IAM) 4. Audit logging (Cloud Audit Logs) 5. Data deletion (automated workflows) 6. DLP for PII detection
HIPAA Implementation¶
BAA-Eligible Services: - Compute Engine, GKE, Cloud Run - Cloud Storage, Cloud SQL, BigQuery - Cloud Pub/Sub, Dataflow - Cloud KMS, Secret Manager
Configuration:
# Enable audit logs for Data Access
gcloud projects get-iam-policy PROJECT_ID > policy.yaml
# Edit policy to enable Data Access logs
# Apply updated policy
gcloud projects set-iam-policy PROJECT_ID policy.yaml
# Use CMEK
gcloud compute instances create hipaa-instance \
--boot-disk-kms-key=projects/PROJECT/locations/LOCATION/keyRings/KEYRING/cryptoKeys/KEY
Best Practices¶
Network Security¶
- Use VPC Service Controls for sensitive data
- Implement private connectivity
- Enable VPC Flow Logs
- Use Cloud Armor for public services
- IAP for internal applications
- Network segmentation
- Regular firewall audits
Data Security¶
- Encrypt sensitive data (CMEK)
- Use DLP for discovery
- Implement least privilege
- Secret Manager for credentials
- Regular data classification
- Retention policies
- Data masking in non-prod
Monitoring¶
- Enable all audit log types
- Export logs to BigQuery
- Real-time alerts for security events
- Security Command Center
- Regular security assessments
- Incident response procedures
Common Scenarios¶
Scenario: PCI DSS compliance for payment data Solution: VPC Service Controls, CMEK, DLP, network segmentation, Cloud Armor, comprehensive audit logging
Scenario: Zero Trust architecture Solution: IAP, BeyondCorp, context-aware access, Workload Identity, no external IPs, VPC Service Controls
Scenario: Multi-region data residency Solution: Regional resources, organization policies restricting locations, CMEK with regional keys, DLP scanning
Study Tips¶
- Practice VPC Service Controls configuration
- Understand encryption options (CMEK vs CSEK)
- Implement DLP inspections
- Configure Cloud Armor rules
- Set up comprehensive audit logging
- Know compliance requirements (GDPR, HIPAA, PCI)
- Security monitoring with SCC
Key Commands¶
# VPC Service Controls
gcloud access-context-manager perimeters create PERIMETER_NAME
# Cloud KMS
gcloud kms keys create KEY_NAME --keyring=KEYRING --location=LOCATION --purpose=encryption
# DLP (use client libraries)
# Cloud Armor
gcloud compute security-policies create POLICY_NAME
# IAP
gcloud iap web enable --resource-type=backend-services --service=SERVICE_NAME
# Audit Logs
gcloud logging read "protoPayload.serviceName=\"iam.googleapis.com\""