Professional Cloud ArchitectDesign for security and complianceMedium

A multinational enterprise is migrating thousands of legacy applications to Google Cloud. They need to establish a consistent security policy across all projects and folders within their organization, such as restricting resource creation to specific regions, enforcing specific VM image families, and preventing the use of external IP addresses on VMs. Which Google Cloud service should be used to centrally manage and enforce these organizational-wide policies?

  1. ASecurity Command Center
  2. BIdentity and Access Management (IAM)
  3. CCloud Asset Inventory
  4. DOrganization Policy Service
Show answer & explanation

Correct answer: D. Organization Policy Service

Organization Policy Service (part of Resource Manager) is designed to centrally control resource configuration across an entire Google Cloud organization, enabling administrators to define constraints like allowed regions or external IP usage. IAM controls who can do what but not what resources can be created. Security Command Center is for security posture management and threat detection. Cloud Asset Inventory tracks resources but doesn't enforce policies.

Why the other options are wrong

  • A. Security Command Center is used for security posture management, vulnerability detection, and threat monitoring, not for enforcing organizational-wide resource configuration policies.
  • B. IAM (Identity and Access Management) controls 'who' can do 'what' on 'which' resources, but it does not enforce 'what kinds of resources' can be created or 'how' they are configured at an organizational level.
  • C. Cloud Asset Inventory provides a centralized inventory of all Google Cloud assets but does not enforce policies or constraints on their creation or configuration.

Google Cloud Organization Policy Service

A service that provides centralized programmatic control over your organization's Google Cloud resources, allowing you to define constraints and enforce compliance.

  • Applies policies at the Organization, Folder, or Project level.
  • Uses constraints to restrict resource behaviors.
  • Integrates with Resource Manager for hierarchical enforcement.

Memory trick: Organization Policy: Rules for All, Preventing Falls.

More Design for security and compliance questions