Group 11: Security & Identity
Identity, access control, and security services: Cloud IAM (identity & access), Cloud Identity (user management), Security Command Center (security insights), KMS (key management), Secret Manager (secrets storage), Cloud HSM (hardware security), Certificate Authority (SSL/TLS certs). Implement defense-in-depth with least privilege principles.
Services & Security Domains
Cloud IAM
Domain: Access control and authorization.
Best for: Resource-level permissions, service accounts, role-based access control.
Features: Policies, roles, conditions, audit logs, impersonation.
Cloud Identity
Domain: User and device identity management.
Best for: User provisioning, SSO, multi-factor authentication, device management.
Features: Directory services, SSO, MFA, device policies, group management.
Security Command Center
Domain: Security monitoring and compliance.
Best for: Threat detection, vulnerability assessment, compliance monitoring.
Features: Security findings, asset inventory, compliance dashboards, threat detection.
Cloud KMS
Domain: Encryption key management.
Best for: Encryption keys, key rotation, envelope encryption, compliance.
Features: Key creation, rotation, versioning, access controls, audit logs.
Secret Manager
Domain: Secrets and credential storage.
Best for: API keys, passwords, certificates, database credentials.
Features: Encrypted storage, versioning, access controls, audit trails.
Cloud HSM
Domain: Hardware-based key protection.
Best for: FIPS 140-2 Level 3, regulatory compliance, high-security requirements.
Features: FIPS certified, dedicated tenancy, bring-your-own-key, high performance.
Certificate Authority Service
Domain: SSL/TLS certificate management.
Best for: Private PKI, certificate lifecycle, mTLS, code signing.
Features: CA hierarchy, certificate templates, CRL/OCSP, automated renewal.
Key Differentiators
| Service | Security Layer | Compliance Level | Use Case | Complexity |
|---|---|---|---|---|
| IAM | Access Control | Standard | Resource permissions | Medium |
| Identity | User Management | Standard | User authentication | Medium |
| Security Command Center | Monitoring | High | Threat detection | Low |
| KMS | Encryption | High | Key management | Medium |
| Secret Manager | Secrets | Standard | Credential storage | Low |
| Cloud HSM | Hardware Security | Very High | FIPS compliance | High |
| Certificate Authority | PKI | High | Certificate management | High |
Selection Model
Scoring 0–10. Choose security services based on compliance, threat model, and operational requirements.
Current Scores:
Interpretation Guidelines
- IAM > 7.0: Essential for any GCP deployment with multiple resources or users.
- Identity > 7.0: Required for organizations managing user access and SSO integration.
- Security Command Center > 7.0: Critical for production environments and compliance monitoring.
- KMS > 7.0: Necessary for encrypted data storage and regulatory compliance.
- Secret Manager > 7.0: Must-have for applications using credentials and API keys.
- Cloud HSM > 7.0: Choose for FIPS 140-2 Level 3 requirements and high-security environments.
- Certificate Authority > 7.0: Ideal for private PKI and internal certificate management.
Security Anti-Patterns
- Overprivileged access: Don't grant broad permissions when specific roles suffice.
- Hardcoded secrets: Never embed credentials in code; use Secret Manager.
- Ignored security findings: Don't deploy Security Command Center without acting on findings.
- Unencrypted sensitive data: Always use KMS for sensitive data encryption.
- Default service accounts: Create specific service accounts with minimal permissions.