Protect your cloud data with Security Command Center

Google Cloud TechAbout 4 min readMay 22, 2025Watch original
THE SUMMARYAI-generated

Data Security and Compliance Posture Management: A Beyond-DSPM Offering

Key Concepts:

  • Data Security and Compliance Posture Management (DSCPM)
  • Data Loss Prevention (DLP)
  • Data Security Posture Management (DSPM)
  • Data Governance
  • Data Map
  • Data Controls (Data Access, Data Flow, Data Retention, Data Protection, AI Controls, Purpose-Based Access)
  • Implicit Boundary
  • Detective Mode
  • Preventive Mode
  • Security Command Center
  • BigQuery Security Center
  • IAM (Identity and Access Management)
  • GDPR (General Data Protection Regulation)
  • HIPAA (Health Insurance Portability and Accountability Act)
  • PCI DSS (Payment Card Industry Data Security Standard)
  • DORA (Digital Operational Resilience Act)

The Challenge: Balancing Data Risks and Rewards

Data has become a crucial asset for enterprises, driving innovation through AI, ML, and analytics. However, this comes with significant risks, including data breaches and compliance violations. The cost of failing to prevent these breaches can be substantial, potentially leading to personal liability. Managing data risk is essential across all industries and workloads, with specific requirements varying based on organization size and regulatory purview.

Examples:

  • Financial Services: Meeting regional banking regulatory requirements, such as monitoring privileged access to sensitive data within 48 hours, protecting retail customer data from accidental sharing for PCI DSS and DORA, and managing data residency and protection.
  • Healthcare: Ensuring patient data is used only for restricted purposes (e.g., research), meeting data protection and retention requirements (HIPAA mandates six-year retention), preventing sensitive data leaks in AI/ML training environments, and protecting IP (models, weights) from exfiltration.

Limitations of Current DSPM Solutions

Current Data Security Posture Management (DSPM) solutions often lack the depth and breadth of capabilities required to address the variations of requirements. While they may excel in areas like data store coverage and out-of-the-box access intelligence, they often fall short in providing comprehensive data controls to secure data and monitor those controls, leaving gaps in data posture and increasing vulnerability to risks.

Introducing Data Security and Compliance Posture Management (DSCPM)

Google Cloud introduces Data Security and Compliance Posture Management (DSCPM) as a beyond-DSPM offering within Security Command Center. This is a first-of-its-kind solution by any cloud provider, aiming to bring security and compliance to data wherever it resides (GCP or elsewhere). The vision is to provide comprehensive coverage across security, privacy, and compliance use cases.

The Data Governance Journey: Discover, Secure, and Monitor

The DSCPM approach to data governance involves three major steps:

  1. Discover: Using a "Google Maps-like" experience called Data Map to identify what data exists and where it is located.
  2. Secure: Implementing data controls as a library that exposes platform capabilities, allowing users to codify requirements as policies and apply them across the infrastructure. These controls are available as cloud controls with data frameworks.
  3. Monitor: Managing the health of deployed frameworks in near real-time and remediating any issues.

Deep Dive into the "Secure" Step: Data Controls and Policies

The "Secure" step involves:

  1. Identifying the Sensitive Data: Defining an implicit boundary around the data in scope using coarse-grained (org, folder, project) or fine-grained filters (sensitivity, location, tags).
  2. Mapping Requirements to Control Policies: Applying specific data controls in either detective or preventive mode.

Available Data Controls:

  • Data Access Governance: Restricting access to sensitive data to allowed principles.
    • Example: Allowing only the fraud detection team to access datasets with customer payment information.
  • Data Flow Governance: Restricting the flow of data to certain boundaries.
    • Example: Preventing Swiss citizen customer data from leaving Switzerland. Future support planned for logical boundaries (organization, folder, project) to prevent exfiltration.
  • Data Retention Control: Managing the historical depth of data for maximum and minimum retention periods.
    • Examples: Deleting customer data within 90 days after unsubscription (GDPR) or retaining patient data records for six years (HIPAA).
  • Data Protection Control: Managing encryption key configurations, such as key rotation period, location of keys, and segregation of duties.
    • Example: Setting a key rotation period of 90 days and specifying the location of keys.
  • AI Controls: Ensuring responsible and compliant use of data in AI/ML models.
  • Purpose-Based Access: Restricting data usage to specific, authorized purposes.

Important Note: The presenter emphasizes that only GCP can offer these controls due to the required deeper platform integration.

Monitoring and Remediation

After deploying data controls with frameworks, users can monitor the health of these frameworks in near real-time and take corrective actions as needed.

Integration with BigQuery Security Center

DSCPM is being introduced natively within BigQuery Security Center, allowing BigQuery admins to discover, secure, and monitor BigQuery assets using the same beyond-DSPM capabilities.

Integration with Third-Party Security Vendors

Google Cloud is supporting integration with third-party security vendor products, allowing users to use DSCPM as a central console to protect assets across the spectrum. Initial integrations include three vendors, with plans to add more in the future.

Conclusion

Data Security and Compliance Posture Management (DSCPM) offers a comprehensive solution for governing data for security, privacy, and compliance. By providing a beyond-DSPM approach with data controls, DSCPM enables organizations to discover, secure, and monitor their data effectively, mitigating risks and ensuring compliance with various regulations. The integration with BigQuery Security Center and third-party vendors further enhances the value and reach of this offering.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.