Your organization wants to be General Data Protection Regulation (GDPR) compliant. You want to ensure that your DevOps teams can only create Google Cloud resources in the Europe regions.
What should you do?
A.
Use Identity-Aware Proxy (IAP) with Access Context Manager to restrict the location of Google Cloud resources.
B.
Use the org policy constraint 'Google Cloud Platform – Resource Location Restriction' on your Google Cloud organization node.
C.
Use the org policy constraint 'Restrict Resource Service Usage' on your Google Cloud organization node.
D.
Use Identity and Access Management (IAM) custom roles to ensure that your DevOps team can only create resources in the Europe regions.
I will go with A; since requirement for access to devops only is met through IAP and Access context manager ensures jurisdictional requirements around data.
B. Use the org policy constraint 'Google Cloud Platform – Resource Location Restriction' on your Google Cloud organization node:
This policy constraint allows you to restrict the regions where Google Cloud resources can be created within your organization. By setting this constraint, you can ensure that resources are only deployed in the Europe regions, aligning with GDPR requirements for data processing and storage.
Wouldn't that affect everyone under the organization? The location restriction is supposed to be applied only to the devops team and I imagine there are other teams/groups within the organization as well.
I think While custom IAM roles can control permissions within projects, they do not inherently enforce geographic location restrictions on resource creation. Your thoughts ?
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
mjcts
8Â months, 3Â weeks agob6f53d8
9Â months agossk119
9Â months, 2Â weeks agopradoUA
1Â year, 1Â month agopfilourenco
1Â year, 2Â months agoMithung30
1Â year, 2Â months agoppandher
1Â year, 2Â months agoYohanes411
1Â year agoppandher
1Â year agoppandher
1Â year ago