Scan with Phone

Scan to instantly open and share this page on your mobile device.

Link copied to clipboard!

Group 11: Security & Identity

Identity, access control, and security services: Cloud IAM (identity & access), Cloud Identity (user management), Security Command Center (security insights), KMS (key management), Secret Manager (secrets storage), Cloud HSM (hardware security), Certificate Authority (SSL/TLS certs). Implement defense-in-depth with least privilege principles.

Security Layers: IAM for access control; Identity for user management; Security Command Center for monitoring; KMS for encryption keys; Secret Manager for credentials; HSM for high-security keys; Certificate Authority for SSL/TLS. Apply zero-trust principles.

Services & Security Domains

Cloud IAM

Domain: Access control and authorization.

Best for: Resource-level permissions, service accounts, role-based access control.

Features: Policies, roles, conditions, audit logs, impersonation.

Cloud Identity

Domain: User and device identity management.

Best for: User provisioning, SSO, multi-factor authentication, device management.

Features: Directory services, SSO, MFA, device policies, group management.

Security Command Center

Domain: Security monitoring and compliance.

Best for: Threat detection, vulnerability assessment, compliance monitoring.

Features: Security findings, asset inventory, compliance dashboards, threat detection.

Cloud KMS

Domain: Encryption key management.

Best for: Encryption keys, key rotation, envelope encryption, compliance.

Features: Key creation, rotation, versioning, access controls, audit logs.

Secret Manager

Domain: Secrets and credential storage.

Best for: API keys, passwords, certificates, database credentials.

Features: Encrypted storage, versioning, access controls, audit trails.

Cloud HSM

Domain: Hardware-based key protection.

Best for: FIPS 140-2 Level 3, regulatory compliance, high-security requirements.

Features: FIPS certified, dedicated tenancy, bring-your-own-key, high performance.

Certificate Authority Service

Domain: SSL/TLS certificate management.

Best for: Private PKI, certificate lifecycle, mTLS, code signing.

Features: CA hierarchy, certificate templates, CRL/OCSP, automated renewal.

Key Differentiators

ServiceSecurity LayerCompliance LevelUse CaseComplexity
IAMAccess ControlStandardResource permissionsMedium
IdentityUser ManagementStandardUser authenticationMedium
Security Command CenterMonitoringHighThreat detectionLow
KMSEncryptionHighKey managementMedium
Secret ManagerSecretsStandardCredential storageLow
Cloud HSMHardware SecurityVery HighFIPS complianceHigh
Certificate AuthorityPKIHighCertificate managementHigh

Selection Model

Scoring 0–10. Choose security services based on compliance, threat model, and operational requirements.

Score_IAM = 0.40*C_accessControlNeeds + 0.25*C_userManagement + 0.20*C_encryptionRequirements + 0.15*(10 - C_hardwareSecurity) Score_Identity = 0.40*C_userManagement + 0.25*C_accessControlNeeds + 0.20*(10 - C_encryptionRequirements) + 0.15*(10 - C_hardwareSecurity) Score_SecurityCommandCenter = 0.35*C_threatMonitoring + 0.25*C_regulatoryCompliance + 0.20*C_accessControlNeeds + 0.15*(10 - C_secretsManagement) + 0.05*C_userManagement Score_KMS = 0.35*C_encryptionRequirements + 0.25*C_regulatoryCompliance + 0.20*C_secretsManagement + 0.15*(10 - C_userManagement) + 0.05*C_accessControlNeeds Score_SecretManager = 0.40*C_secretsManagement + 0.25*C_accessControlNeeds + 0.20*(10 - C_hardwareSecurity) + 0.15*(10 - C_pkiRequirements) Score_CloudHSM = 0.40*C_hardwareSecurity + 0.30*C_regulatoryCompliance + 0.20*C_encryptionRequirements + 0.10*(10 - C_userManagement) Score_CertificateAuthority = 0.40*C_pkiRequirements + 0.25*C_encryptionRequirements + 0.20*C_regulatoryCompliance + 0.15*(10 - C_userManagement)

Current Scores:

{{score.name}}: {{score.value | number:1}}

Interpretation Guidelines

  • IAM > 7.0: Essential for any GCP deployment with multiple resources or users.
  • Identity > 7.0: Required for organizations managing user access and SSO integration.
  • Security Command Center > 7.0: Critical for production environments and compliance monitoring.
  • KMS > 7.0: Necessary for encrypted data storage and regulatory compliance.
  • Secret Manager > 7.0: Must-have for applications using credentials and API keys.
  • Cloud HSM > 7.0: Choose for FIPS 140-2 Level 3 requirements and high-security environments.
  • Certificate Authority > 7.0: Ideal for private PKI and internal certificate management.

Security Anti-Patterns

  • Overprivileged access: Don't grant broad permissions when specific roles suffice.
  • Hardcoded secrets: Never embed credentials in code; use Secret Manager.
  • Ignored security findings: Don't deploy Security Command Center without acting on findings.
  • Unencrypted sensitive data: Always use KMS for sensitive data encryption.
  • Default service accounts: Create specific service accounts with minimal permissions.
next