Professional Cloud ArchitectManage implementationMedium
A healthcare provider is developing a new patient portal application on Google Cloud. The application will handle Protected Health Information (PHI) and must comply with HIPAA regulations. The operations team needs to ensure that all data access is auditable and that any unauthorized attempts to access PHI are logged and alerted. Which Google Cloud service combination should you recommend to meet these auditing and alerting requirements?
- ACloud Audit Logs for administrative and data access logs, and Cloud Monitoring for alerts on specific log entries.
- BSecurity Command Center for vulnerability scanning and Cloud Identity for user authentication.
- CCloud Logging for audit logs and Cloud Monitoring for alerts on log entries.
- DData Loss Prevention (DLP) API for PHI detection and BigQuery for storing audit trails.
Show answer & explanationAnswer & explanation
Correct answer: A. Cloud Audit Logs for administrative and data access logs, and Cloud Monitoring for alerts on specific log entries.
Cloud Audit Logs automatically records administrative activities and data access for Google Cloud services, which is crucial for HIPAA compliance. Cloud Monitoring can then be configured to create alerts based on specific patterns found in these audit logs (e.g., unauthorized access attempts).
Why the other options are wrong
- B. Security Command Center focuses on security posture management and vulnerability scanning; Cloud Identity is for user management. Neither directly provides auditable data access logs or alerting on them.
- C. Cloud Logging is a general logging service; Cloud Audit Logs specifically provides the required audit trail for GCP services.
- D. DLP API detects sensitive data but doesn't provide auditable access logs. BigQuery can store logs but is not the primary service for generating them or real-time alerting.
Cloud Audit Logs & Monitoring
Cloud Audit Logs records administrative activities and data access events for Google Cloud resources. Cloud Monitoring allows setting up alerts based on metrics and log patterns, including those from audit logs.
- Cloud Audit Logs are immutable and retained for a specific period.
- Includes Admin Activity, Data Access, and System Event logs.
- Cloud Monitoring can trigger notifications (email, SMS, PagerDuty) based on audit log events.
Memory trick: For HIPAA, we must log every step and yell if someone steps out of line.