Professional Cloud ArchitectDesign for security and complianceMedium
A healthcare provider is deploying a new patient records application on Google Cloud. The application will store Protected Health Information (PHI) and must comply with HIPAA regulations, which mandate strict access controls, auditability, and data integrity. The provider wants to implement a robust identity and access management strategy that aligns with the principle of least privilege, ensuring that users only have the minimum necessary permissions to perform their job functions. Which Google Cloud IAM feature is most appropriate for assigning granular permissions based on predefined job roles?
- ACustom roles
- BService accounts
- CBasic roles
- DOrganizational policies
Show answer & explanationAnswer & explanation
Correct answer: A. Custom roles
Custom roles in IAM allow defining a specific set of permissions tailored to a job function, enabling the principle of least privilege. This is crucial for HIPAA compliance, which requires granular control over access to PHI.
Why the other options are wrong
- B. Service accounts are identities for applications or virtual machines, not for human users requiring job-based access control.
- C. Basic roles (Owner, Editor, Viewer) are broad and grant excessive permissions, violating the principle of least privilege for sensitive data.
- D. Organizational policies enforce constraints across an organization, like disabling certain services, but they don't define granular user permissions.
Google Cloud IAM Custom Roles
Custom roles in Google Cloud IAM allow administrators to define a specific set of permissions tailored to an organization's needs, enabling granular access control.
- Enforce the principle of least privilege.
- Combine specific permissions from Google-defined roles.
- Can be applied at the project, folder, or organization level.
Memory trick: IAM Roles: Basic, Predefined, Custom, Service. Choose Wisely.