Professional Cloud ArchitectDesign for security and complianceEasy

A multinational enterprise is migrating thousands of legacy applications to Google Cloud. They have a strict corporate policy that dictates all new Google Cloud projects must have specific services disabled (e.g., Cloud Shell, App Engine) and must enforce uniform network configurations across all projects. This policy needs to be enforced organization-wide to prevent non-compliant resource deployments. Which Google Cloud service should they use to achieve this consistent, organization-wide policy enforcement?

  1. AResource Manager
  2. BCloud Deployment Manager
  3. COrganization Policy Service
  4. DIdentity and Access Management (IAM)
Show answer & explanation

Correct answer: C. Organization Policy Service

Google Cloud's Organization Policy Service allows administrators to programmatically control resource configurations across an entire organization. It enables setting constraints on resource creation, such as disabling specific services or enforcing network settings, which is exactly what the company needs for organization-wide policy enforcement.

Why the other options are wrong

  • A. Resource Manager organizes resources hierarchically but doesn't enforce policies on resource configurations.
  • B. Cloud Deployment Manager is an infrastructure-as-code tool for deploying resources, not for setting organization-wide constraints on allowed services or configurations.
  • D. IAM controls who can do what, but not what *can* be done or configured within a project at an organizational level.

Organization Policy Service

The Organization Policy Service allows administrators to programmatically control resource configurations across an entire Google Cloud organization.

  • Sets constraints on resource behavior and configuration.
  • Enforces policies across projects, folders, and the organization.
  • Prevents non-compliant resource deployments.

Memory trick: Organization Policy Service is the 'rulebook' for your entire Google Cloud organization.

More Design for security and compliance questions