Google rolled out a handful of updates to its ever-growing cloud security portfolio targeted at helping enterprises and governments tackle surging cybersecurity attacks. The updates come on the back of a handful of recent acquisitions by the cloud giant in the security space.

Sunil Potti, VP and GM of Google Cloud, during a press briefing touted the launch of Google’s Assured Open Source Software (OSS) service as “probably the biggest” of the updates.

The Assured Open Source Software (OSS) service allows open source software users to tap into pre-packaged security tools. These tools scan, analyze, and fuzz-test for vulnerabilities; use metadata from Google’s Container Analysis tool; are built on Google’s Cloud Build platform that offers verifiable Supply chain Levels for Software Artifacts (SLSA) compliance; are signed by Google; and are accessible through a Google protected and secured Artifact Registry.

Potti said the Assured OSS effort should work toward providing assurance to enterprise and government users about open source security concerns. He also cited recent work in joining the Open Source Security Foundation (OpenSSF) and the Linux Foundation’s action plan to improve open source software’s security and resilience.

Easing Google Cloud Security Deployments

More broadly, Google also launched new tools designed to make it easier for an organization to deploy a robust security posture.

One of those tools is the Security Foundation product that takes advantage of what Google has already done internally. It allows customers to basically copy Google’s own internal security posture by tapping into guidance from Google’s Cloud Cybersecurity Action Team and using codified configuration from the Security Foundations Blueprint.

Potti described the product as a “complete turnkey offering across various controls – that we believe having looked at all the configs over the last few years of customers consuming TCP – the best day-zero” platform Google would recommend to users.

Google also expanded its BeyondCorp offerings with an Enterprise Essentials tier. The new tier uses threat and data protection, and monitoring and reporting capabilities accessible through a Chrome browser to provide a consistent layer of security.

Jeanette Manfra, director of risk and compliance at Google Cloud, explained that this tier “is designed to provide organizations with an easy on-ramp to a zero-trust access strategy. … We want to make security simple and transparent and make it easy for our customers to begin this journey.”

The still-offered Enterprise version will also be adding an app connector and client connector that will allow users to connect to applications running on other cloud services without needing to open firewalls or configure site-to-site VPN connections.

Google also updated its Siemplify security orchestration, automation, and response (SOAR) platform to make it easier for end users and service providers to collaborate on shared data. This builds on Google’s acquisition of Siemplify earlier this year that brought SOAR capabilities in house.