Soru

Zorluk: OrtaRegulatory Compliance, Data Sovereignty, and Data Governance

A financial services organization based in Singapore is migrating its core transactional platform to Google Cloud. To comply with regional regulatory compliance and data sovereignty mandates, the enterprise must ensure that all storage resources and key management services are strictly restricted to the asia-southeast1 region. Additionally, any access by Google support engineers to customer data for operational tasks must require prior explicit approval from the customer's security team. Which TWO architectural mechanisms should a Cloud Architect implement to fulfill these compliance requirements?

  1. Enforce an Organization Policy using the Resource Locations constraint (constraints/gcp.resourceLocations) limited to the asia-southeast1 region.Cevap
  2. Enable Access Approval at the organization or project level to mandate explicit customer authorization before Google support personnel can inspect resources.Cevap
  3. C
    Mandate Customer-Supplied Encryption Keys (CSEK) across all storage services to manually govern key storage locations.
  4. D
    Grant the primitive IAM Owner role (roles/owner) to the internal compliance team to oversee resource deployment geographic restrictions.

Cevap

Enforce an Organization Policy using the Resource Locations constraint (constraints/gcp.resourceLocations) limited to the asia-southeast1 region, and enable Access Approval at the organization or project level to mandate explicit customer authorization before Google support personnel can inspect resources.
Data residency and sovereign access requirements are effectively satisfied by pairing the Resource Locations organization policy constraint (to programmatically restrict resource and KMS location boundaries) with Access Approval (to enforce explicit customer approval for Google support interventions).

Adım Adım Çözüm

1
Address the regional data sovereignty mandate for resources and key management.
Configure the constraints/gcp.resourceLocations Organization Policy to allow resource creation only in asia-southeast1.
Organization Policies restrict resource creation geographically across all supported Google Cloud services within the resource hierarchy.
2
Address the constraint regarding Google support administrative access oversight.
Configure Access Approval for the GCP organization or target project.
Access Approval provides a human-in-the-loop mechanism requiring customer authorization before Google personnel can access data for support or troubleshooting.

Anahtar Kavram

Data Sovereignty and Support Access Control via Resource Location Constraints and Access Approval
Bu soruyu puanla