Compliance in Australia with Assured Workloads
Key Takeaways
This video demonstrates how to use Assured Workloads to support data residency and compliance requirements in Australia, specifically using Google Cloud's Assured Workloads feature to enforce security controls and maintain compliance.
Full Transcript
hi I'm Chloe a developer advocate for Google cloud and in this video I'll walk you through how you can use assured workloads to support your data residency and other compliance and security requirements in Australia [Music] Google Cloud customers use assured workloads to help protect the sensitive data they store and process on Google Cloud assured workloads enforces security controls and guard rails needed to protect infrastructure while maintaining compliance for customers who wish to establish Australian data residency customers can specify the Google Cloud regions in Australia where their data will be stored and ensure that it will remain there assured workloads implements a Google Cloud platform organization policy that restricts customer data to being stored in a specific region customers can choose from the current cloud regions in Australia Melbourne and Sydney this is coupled with our new assured support service which means that customer support will be provided from only five countries United States Australia Canada New Zealand and the United Kingdom this ensures that only Personnel in one of those locations are allowed to provide support to a regulated customer in Australia this control also restricts access to customer data to individuals who meet this requirement during the resolution of a customer initiated support case through assured workloads controls support meets the requirements of the Australian government's information security registered assessors program and the hosting certification framework which is administered by the Australian government's digital transformation agency let's take a closer look on how to get started with assured workloads for Australia first visit the Google Cloud console at cloud.google.com console before you can set up an assured workloads environment you must select an organization then navigate to the compliance section in the compliance section you will have to create a new assured workloads folder or use an existing assured workloads folder within your organization's Cloud hierarchy for each existing folder you can see its name creation time compliance type data region and labels click create to create a new assured workloads folder you will first need to check that you meet the prerequisites for folder creation this means having access transparency enabled for your organization this provides you an audit trail of support actions a premium subscription to assured workloads this is required for assured workloads for Australia next select the geographic area in which you aim to meet data residency requirements assured workloads offers control in Australia but also in the EU the US and Canada as of today let's pick Australia as you can see assured support provides customers 24 7 access to Google Cloud technical support from five specific countries United States Canada Australia United Kingdom and New Zealand support is provided in the English language it sets data location controls to available Australia regions let's pick Australia regions with assured support and click next specify the Australia region you would like to restrict your workload to select australia-southeast one which corresponds to the Sydney region and click next select the parent folder you registered earlier as the place where your new folder will live then give your assured workloads folder a name and click next the last step is configuring your key management project in key ring this will create a separate Key Management project within your assured workloads folder and a key ring in which to place your keys the key ring sets you up to utilize customer managed encryption keys or externally managed encryption keys click next this brings you to the review section where you can review compliance type details folder name and location as well as supported products click create to create the assured workloads folder now you will see the new assured workloads folder in your list from this point forward any folder or project created inside of this folder will inherit the guardrails you specified now that your folder is created you are able to set up encryption keys you'll see the encryption section which shows you information about the separate Key Management project created for you click on the project name to open it when entering a project inside the assured workloads regulatory boundary customers are presented with a regulatory intercept that warns them about entering sensitive data in the environment and logs their acknowledgment and access to the project now let's take a look at how you can create a cloud resource within your assured workloads folder create a new project within the assured workloads folder you created earlier make sure to set the location appropriately once your project is created select it and acknowledge the compliance agreement navigate to the cloud storage section of the console click create bucket give your bucket a name select the default options for location storage class and access control as you can see we have several options to store our data we can select from different multi-region options however because of the data residency controls we set previously this should not succeed we'll create this bucket and ensure that we're enforcing Public Access prevention this alert lets us know that it is blocking our ability to deploy this bucket in the United States since it violates the constraints for the resource location in other words only a valid region would be a valid selection so if we select the correct dual region you'll see that we're able to create a bucket in a location that aligns with our data residency requirements that we specified when we first created the assured workloads folder at this point any files or objects uploaded to this bucket and their resources will be located in the Sydney region all the currently supported services and assured workloads are listed in our documentation under supported products see our Link in the description to stay current on what's new as we're adding more services regularly so there you have it a walkthrough of how you can get started with assured workloads in Australia to easily deploy supplementary data protection measures for workloads on Google Cloud to learn more visit cloud.google.com assured Dash workloads take a look at the description on this video for more assured workloads resources and to see videos on how to build cloud workloads with compliance in mind thanks for watching thank you [Music]
Original Description
In this video, Chloe Condon walks through how you can use Assured Workloads to support your data residency and other compliance and security requirements in Australia.
Resources:
Check out the GitHub repository → https://goo.gle/3QtAiFa
Assured Workloads Australia quick start guide → https://goo.gle/44ZoDlB
Assured Workloads playlist → https://goo.gle/AssuredWorkloads
Subscribe to Google Cloud Tech → https://goo.gle/GoogleCloudTech
#AssuredWorkloads
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from Google Cloud Tech · Google Cloud Tech · 40 of 60
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
▶
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
I’m going for it #GoogleCloudCertified
Google Cloud Tech
I had to get #GoogleCloudCertified
Google Cloud Tech
Be better overall at what you do #GoogleCloudCertified
Google Cloud Tech
Cloud Monitoring on our radar #Analysis #Uptime
Google Cloud Tech
Introduction to Generative AI Studio
Google Cloud Tech
How to use Github Actions with Google's Workload Identity Federation
Google Cloud Tech
Introduction to Responsible AI
Google Cloud Tech
Networking updates and CDMC-certified architecture
Google Cloud Tech
Create and use a Cloud Storage bucket
Google Cloud Tech
How to digitize text from documents
Google Cloud Tech
Faster analytical queries with AlloyDB
Google Cloud Tech
Next ‘23 sessions and FaaS Wave
Google Cloud Tech
Introduction to Assured Open Source Software
Google Cloud Tech
BigQuery Cost Optimization: Storage
Google Cloud Tech
BigQuery Cost Optimization: Compute
Google Cloud Tech
BigQuery Cost Optimization: Select Queries
Google Cloud Tech
Remote Field Equipment Management with Manufacturing Data Engine
Google Cloud Tech
Supercharging your applications with Cloud SQL Enterprise Plus
Google Cloud Tech
Vector Support on our radar #GenAI
Google Cloud Tech
Architecting a blockchain startup with Google Cloud
Google Cloud Tech
Kubernetes and multitasking updates!
Google Cloud Tech
GKE: Using Kubernetes Events
Google Cloud Tech
How to configure firewall rules for Cloud Composer
Google Cloud Tech
Vertex AI Embeddings API + Matching Engine: Grounding LLMs made easy
Google Cloud Tech
Geospatial analytics on our radar #EarthEngine #BigQuery
Google Cloud Tech
Ensuring requests are set in Kubernetes
Google Cloud Tech
Cloud Next 2023, Google research program, and more!
Google Cloud Tech
How to migrate projects between organizations with Resource Manager
Google Cloud Tech
How to run #MySQL in Google Cloud
Google Cloud Tech
#GenerativeAI for enterprises and #Next2023
Google Cloud Tech
How Google Photos scales to store 4 trillion photos and videos
Google Cloud Tech
Google Cross-Cloud Interconnect (Demo 2)
Google Cloud Tech
GKE Cost Optimization Golden Signals: Introduction
Google Cloud Tech
GKE Cost Optimization Golden Signals: Workload Rightsizing
Google Cloud Tech
GKE Load Balancing: Overview
Google Cloud Tech
GKE Load Balancing: Best Practices
Google Cloud Tech
Disaster Recovery in GKE
Google Cloud Tech
How to configure IP masquerade agent in GKE Standard clusters
Google Cloud Tech
Enable and use GKE Control plane logs
Google Cloud Tech
Compliance in Australia with Assured Workloads
Google Cloud Tech
Creating budgets and budget alerts in Google Cloud #FinOps
Google Cloud Tech
Cloud SQL Enterprise Plus on our radar #mySQL
Google Cloud Tech
What's Next for Google Cloud?
Google Cloud Tech
How Loveholidays scaled with Contact Center AI
Google Cloud Tech
What is fleet team management in GKE?
Google Cloud Tech
Troubleshoot VPC Network Peering
Google Cloud Tech
Introduction to DocAI and Contact Center AI
Google Cloud Tech
Cloud Run Direct VPC egress explained
Google Cloud Tech
Database deployment options in GKE
Google Cloud Tech
Analyze cloud billing data with #BigQuery
Google Cloud Tech
Tips to becoming a world-class Prompt Engineer
Google Cloud Tech
Serverless is simple. Do I need CI/CD?
Google Cloud Tech
Accelerating model deployment with MLOps
Google Cloud Tech
How Hawaii's Department of Human Services scaled with CCAI
Google Cloud Tech
Pricing API on our #Radar
Google Cloud Tech
How Recommendations AI for Media can boost customer retention
Google Cloud Tech
Troubleshooting: Node Not Ready Status
Google Cloud Tech
One weekend until Cloud Next 2023!
Google Cloud Tech
#GoogleCloudNext starts tomorrow!
Google Cloud Tech
#GoogleCloudNext will be demand!
Google Cloud Tech
Related AI Lessons
⚡
⚡
⚡
⚡
When AI Asks for More Electricity Than a Country Can Imagine
Medium · AI
You Are Not Behind. The World Is.
Medium · AI
Career choice with the advent of AI - pure Computer Science or learn software with a background of core engineering area
Dev.to AI
The AI Hype Cycle: Calm Before the Next Breakthrough?
Medium · Programming
🎓
Tutor Explanation
DeepCamp AI