Google added new security capabilities around data encryption, network security, security analytics, and user protection at the U.K. edition of its annual Cloud Next event.
But perhaps the most important new capability is its new External Key Manager, which allows companies to store and manage encryption keys outside of Google Cloud. This service, which the cloud provider says will soon be available in beta, works with Cloud KMS, and it lets customers encrypt data in BigQuery and Compute Engine with encryption keys stored and managed in a third-party key management system deployed outside Google’s infrastructure. Google is working with five management vendors on this effort: Equinix, Fortanix, Ionic, Thales, and Unbound.
This service is different from bring-your-own-key, or BYOK, that Google and other cloud providers already offer, said Fortanix CTO and co-founder Anand Kashyap. It’s BYOKMS, with the “MS” standing for management service, he said.
“We expect other large public cloud providers to take note of this announcement, and hopefully in the next year we will see other public cloud providers open up their key management offerings and allow an external key management service to be integrated with them,” Kashyap said. “We are ready and willing to integrate SKDMS with their public clouds.”
SDKMS, or self-defending key management service, is Fortanix’s cloud-based service that provides both key management and hardware security model (HSM) capabilities via software.
Why Key Management MattersThis move to allow companies to manage and store their encryption keys outside of Google Cloud is a big deal because “it gives customers complete control of their keys,” Kashyap said.
Some enterprises want to move their data and compute to the cloud, but because of regulations and compliance issues they have to keep their keys on premises. “This level of integration allows them to do that,” he explained. “It will allow them to move more workloads to the public cloud, and Google offering this definitely gives them a competitive advantage” when it comes to attracting enterprise customers.
In tandem, Google also announced Key Access Justifications, which is a new feature that works with External Key Manager. It provides a detailed justification each time a customer’s key is requested to decrypt data, and it also includes a mechanism for a customer to explicitly approve or deny providing the key using an automated policy.
“Using External Key Manager and Key Access Justifications together you can deny Google the ability to decrypt your data for any reason,” according to a blog by Sunil Potti, VP of engineering at Google Cloud Security. “As a result, you are the ultimate arbiter of access to your data — a level of control not available from any other cloud provider.”
Google Cloud Armor Gets ToughGoogle already offered distributed denial of service (DDoS) and web attack prevention via Google Cloud Armor and its Cloud Load Balancing infrastructure. The combined services provide always-on threat detection and mitigation. And today Google added new web application firewall (WAF) to Cloud Armor.
“You can now configure Cloud Armor policies with geo-based access controls, pre-configured WAF application protection rules to mitigate OWASP Top 10 risks, and a custom rules language to create custom Layer-7 filtering policies,” Potti wrote in the blog post.
Additionally, Cloud Armor now integrates with Cloud Security Command Center and notifies customers of suspicious application traffic patterns directly in the Cloud SCC dashboard.
The cloud provider also added a new Packet Mirroring service. This service, now in beta, allows companies to collect and inspect network traffic for Compute Engine and GKE. Packet Mirroring also works with third-party tools including products from Awake Security, Check Point, Cisco, Corelight, cPacket Networks, ExtraHop Networks, Flowmon, Ixia by Keysight, Netscout, and Palo Alto Networks.
Threat Detection, PreventionAnd finally, Google rolled out new threat detection and prevention capabilities to help enterprises secure cloud resources and workloads. Event Threat Detection, now in beta, helps detect threats using logs so companies can send incidents to a security information and event management (SIEM) tool for further investigation.
Additionally, Security Health Analytics helps prevent incidents by identifying potential misconfigurations and compliance violations in a company’s Google Cloud Platform resources. It also suggests ways to fix the problems.
Comments