Main areas covered
| Section | Area | Description |
|---|---|---|
| 1 | Identity and access management | Service account permissions, administrator role restrictions, and audit configuration |
| 2 | Logging and monitoring | Cloud Audit Logs, Log Sink, Log Metric Filter, and Alerting Policy |
| 3 | Networking | Avoiding the default network, minimizing VPC firewall exposure, VPC Flow Logs, and DNSSEC |
| 4 | Virtual machines | OS Login, Shielded VM, blocking project-wide SSH keys, and restricting IP forwarding |
| 5 | Storage | Cloud Storage uniform bucket-level access, public-access blocking, and customer-managed keys |
| 6 | Cloud SQL database services | SSL connection enforcement, blocking public IP access, and automated backups |
| 7 | BigQuery | Blocking public dataset access and using a customer-managed encryption key |