Google Infrastructure Security Design Overview
Google Infrastructure SecurityDesign OverviewMarch 2022Table of contentsIntroduction3Secure low-level infrastructure4Security of physical premises4Hardware Design and provenance4Secure boot stack and machine identity4Secure service deployment5Service identity, integrity, and isolation6Inter-service access management6Encryption of inter-service communication7Access management of end-user data in Google Workspace7Secure data storage9Encryption at rest9Deletion of data10Secure internet communication10Google Front End service10DoS protection11User authentication11Operational security12Safe software development12Source code protections12Keeping employee devices and credentials safe13Reducing insider risk13Threat monitoring13Intrusion detection14What s next14This content was last updated in March 2022, and represents the status quo as of the time it waswritten.
WAN traversal hop of customer VM to VM traffic. As described earlier, all control plane WAN traffic within the infrastructure is already encrypted. In the future we plan to take advantage of the hardware-accelerated network encryption discussed earlier to also encrypt inter-VM LAN traffic within the data center.
Download Google Infrastructure Security Design Overview
Information
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document: