A global pharmaceutical company is using Google Cloud to host its research data. They have a strict organizational policy that requires all Cloud Storage buckets to be created with a specific set of default IAM permissions, preventing public access and enforcing data residency for certain regions. They want to ensure that even if a developer forgets to apply these permissions, the bucket creation fails or is automatically corrected to meet the policy. How should they enforce this across all projects in their organization?
- AApply Organization Policies with custom constraints on Cloud Storage bucket creation.
- BConfigure Security Command Center to detect and flag non-compliant buckets.
- CImplement a Cloud Function that triggers on bucket creation to modify permissions.
- DUse Cloud IAM policies at the project level.
Show answer & explanationAnswer & explanation
Correct answer: A. Apply Organization Policies with custom constraints on Cloud Storage bucket creation.
Organization Policies, specifically with custom constraints, can enforce granular rules like default IAM permissions or data residency for new resources like Cloud Storage buckets across an entire organization. This ensures that non-compliant resources cannot be created or are automatically configured to comply, preventing developers from bypassing critical security controls. While custom constraints require more setup than predefined ones, they offer the flexibility needed for specific default IAM policies.
Why the other options are wrong
- B. Security Command Center detects non-compliance but doesn't prevent resource creation or automatically correct configurations based on organization-wide policies.
- C. A Cloud Function could correct permissions *after* creation, but it doesn't prevent the initial non-compliant creation and is reactive, not preventative at the organizational level.
- D. Cloud IAM policies define permissions but do not enforce default configurations for new resources or prevent non-compliant creations globally.
Organization Policy Custom Constraints
An extension of Google Cloud's Organization Policy Service that allows administrators to define highly specific, custom rules for resource configurations beyond the predefined constraints.
- Provides fine-grained control over resource properties.
- Enables enforcement of unique organizational compliance requirements.
- Can be used to prevent creation of non-compliant resources.
Memory trick: Custom Org Policies are like 'Tailored Guards' – they enforce your unique rules before anything non-compliant can even appear.