Install
openclaw skills install skills-sh:google/skills/google-cloud-waf-securityGoogle Cloud Well-Architected Framework skill for the Security pillar ## Overview The security pillar of the Google Cloud Well-Architected Framework provides design principles and best practices for building a robust security posture by integrating security into every layer of…
openclaw skills install skills-sh:google/skills/google-cloud-waf-securityThe security pillar of the Google Cloud Well-Architected Framework provides design principles and best practices for building a robust security posture by integrating security into every layer of the architecture for cloud workloads. It focuses on maintaining confidentiality and integrity of data and systems while ensuring compliance and privacy. It provides a structured approach to risk management, threat defense, and identity control, enabling you to operate cloud workloads securely and at scale.
When this skill is activated, follow these steps to evaluate and improve the security posture of the specified Google Cloud workload:
The recommendations in the security pillar of the Well-Architected Framework are aligned with the following core principles:
Implement security by design: Integrate cloud security and network security considerations starting from the initial design phase of your applications and infrastructure. Google Cloud provides architecture blueprints and recommendations to help you apply this principle. Grounding document: https://docs.cloud.google.com/architecture/framework/security/implement-security-by-design.md.txt
Implement zero trust: Use a never trust, always verify approach, where access to resources is granted based on continuous verification of trust. Google Cloud supports this principle through products like Chrome Enterprise Premium, Identity-Aware Proxy (IAP) and IAM Recommender. Grounding document: https://docs.cloud.google.com/architecture/framework/security/implement-zero-trust.md.txt
Implement shift-left security: Implement security controls early in the software development lifecycle. Avoid security defects before system changes are made. Detect and fix security bugs early, fast, and reliably after the system changes are committed. Google Cloud supports this principle through products like Cloud Build, Binary Authorization, and Artifact Registry. Grounding document: https://docs.cloud.google.com/architecture/framework/security/implement-shift-left-security.md.txt
Implement preemptive cyber defense: Adopt a proactive approach to security by implementing robust fundamental measures like threat intelligence. This approach helps you build a foundation for more effective threat detection and response. Google Cloud's approach to layered security controls aligns with this principle. Google Cloud supports this principle through products like Security Command Center, Google Threat Intelligence, and Google SecOps. Grounding document: https://docs.cloud.google.com/architecture/framework/security/implement-preemptive-cyber-defense.md.txt
Use AI securely and responsibly: Develop and deploy AI systems in a responsible and secure manner. The recommendations for this principle are aligned with guidance in the AI and ML perspective of the Well-Architected Framework and in Google's Secure AI Framework (SAIF). Grounding document: https://docs.cloud.google.com/architecture/framework/security/use-ai-securely-and-responsibly.md.txt
Use AI for security: Use AI capabilities to improve your existing security systems and processes through Gemini in Security and overall platform-security capabilities. Use AI as a tool to increase the automation of remedial work and ensure security hygiene to make other systems more secure. Google Cloud supports this principle through products like Google Threat Intelligence and Google SecOps. Grounding document: https://docs.cloud.google.com/architecture/framework/security/use-ai-for-security.md.txt
Meet regulatory, compliance, and privacy needs: Adhere to industry-specific regulations, compliance standards, and privacy requirements. Google Cloud helps you meet these obligations through products like Assured Workloads, Organization Policy Service, and our compliance resource center. Grounding document: https://docs.cloud.google.com/architecture/framework/security/meet-regulatory-compliance-and-privacy-needs.md.txt
Shared responsibilities and shared fate on Google Cloud: Understand that Google is responsible for the security of the cloud and you're responsible for the security of your workloads in the cloud. Recognize how this division of responsibilities varies based on the workload type. Learn what Google does to help ensure that security of the cloud. Take appropriate actions to help ensure that your workloads are secure in the cloud. Grounding document: https://docs.cloud.google.com/architecture/framework/security/shared-responsibility-shared-fate.md.txt
The following are examples of Google Cloud products and features that are relevant to security:
Identity and access management
Network security
Data security
Security operations (SecOps)
Automation and supply chain
Ask appropriate questions to understand the security-related requirements and constraints of the workload and the user's organization. Choose questions from the following list:
Security by design:
Zero trust:
Shift-left security:
Preemptive cyber defense:
Security of AI workloads:
AI for security:
Regulatory compliance and privacy:
Use the following checklist to evaluate the architecture's alignment with security recommendations:
Security by design:
Zero trust:
Shift-left security:
Preemptive cyber defense:
AI security and governance:
79125c2ccebb