Data Boundary for Canada Controlled Goods Program (CGP)
This page describes the set of controls that are applied on Canada Controlled Goods Program (CGP) workloads in Assured Workloads. It provides detailed information about data residency, supported Google Cloud products and their API endpoints, and any applicable restrictions or limitations on those products. The following additional information applies to CGP:
- Data residency: The CGP control package sets data location controls to support Canada-only regions. See the Google Cloud-wide organization policy constraints section for more information.
- Customer-managed encryption keys (CMEK): You must use CMEK in CGP workloads for products or services that support it. During folder creation, Assured Workloads creates a key management project and a key ring for you to store your keys. See Supporting compliance with key management for more information.
- Support: Technical support services for CGP workloads are available with Enhanced or Premium Cloud Customer Care subscriptions. CGP workloads support cases are routed to Canadian support personnel who have completed Canada Controlled Goods Program screenings. See Getting support for more information.
- Pricing: The CGP control package is included in Assured Workloads' Premium tier, which incurs a 5% additional charge. See Assured Workloads pricing for more information.
Prerequisites
To remain compliant as a user of the CGP control package, verify that you satisfy and adhere to the following prerequisites:
- Create a CGP folder using Assured Workloads and deploy your CGP workloads only in that folder.
- Only enable and use in-scope CGP services for CGP workloads.
- Don't use Google Cloud MCP servers unless otherwise noted. CGP doesn't provide data residency controls for in-use data and in-transit data with Google Cloud MCP servers. To block unwanted Google Cloud MCP servers access, see the Control Google Cloud MCP servers use with IAM page page.
- Don't change the default organization policy constraint values unless you understand and are willing to accept the data residency risks that may occur.
- When accessing the Google Cloud console for CGP workloads,
you must use one of the following
Jurisdictional Google Cloud console
URLs:
- console.ca.cloud.google.com
- console.ca.cloud.google for federated identity users
- For all services used in a CGP folder, don't store
controlled goods data in the following user-defined or security configuration
information types:
- Error messages
- Console output
- Attribute data
- Service configuration data
- Network packet headers
- Resource identifiers
- Data labels
- Don't enter or access controlled goods data through the Google Cloud console.
- Consider adopting the general security best practices provided in the Google Cloud security best practices center.
Supported products and API endpoints
Unless otherwise noted, users can access all supported products through the Google Cloud console. Restrictions or limitations that affect the features of a supported product, including those that are enforced through organization policy constraint settings, are listed in the following table.
If a product is not listed, that product is unsupported and has not met the control requirements for CGP. Unsupported products are not recommended for use without due diligence and a thorough understanding of your responsibilities in the shared responsibility model. Before using an unsupported product, ensure that you are aware of and are willing to accept any associated risks involved, such as negative impacts to data residency or data sovereignty.
Restrictions and limitations
The following sections describe Google Cloud-wide or product-specific restrictions or limitations for features, including any organization policy constraints that are set by default on CGP folders. Other applicable organization policy constraints—even if not set by default—can provide additional defense-in-depth to further protect your organization's Google Cloud resources.
Google Cloud-wide
Affected Google Cloud-wide features
| Feature | Description |
|---|---|
| Google Cloud console | To access the Google Cloud console when using the CGP control package,
you must use one of the following URLs:
|
Google Cloud-wide organization policy constraints
The following organization policy constraints apply across Google Cloud.
| Organization policy constraint | Description |
|---|---|
gcp.resourceLocations |
Set to the following locations in the allowedValues list:
Changing this value by making it less restrictive potentially undermines data residency by allowing data to be created or stored outside of a compliant data boundary. |
gcp.restrictCmekCryptoKeyProjects |
Set to under:organizations/your-organization-name, which is your
Assured Workloads organization. You can further restrict this value by specifying a project
or folder.Limits the scope of approved folders or projects that can provide Cloud KMS keys for encrypting at-rest data using CMEK. This constraint prevents unapproved folders or projects from providing encryption keys, thus helping to guarantee data sovereignty for in-scope services' at-rest data. |
gcp.restrictNonCmekServices |
Set to a list of all in-scope
API service names, including:
Each listed service requires Customer-managed encryption keys (CMEK). CMEK encrypts at-rest data with a key managed by you, not Google's default encryption mechanisms. Changing this value by removing one or more in-scope services from the list may undermine data sovereignty, because new at-rest data will be automatically encrypted using Google's own keys instead of yours. Existing at-rest data will remain encrypted by the key you provided. |
gcp.restrictServiceUsage |
Set to allow all supported products and API endpoints. Determines which services can be used by restricting runtime access to their resources. For more information, see Restricting resource usage. |
gcp.restrictTLSVersion |
Set to deny the following TLS versions:
|
Cloud DNS
Affected Cloud DNS features
| Feature | Description |
|---|---|
| Google Cloud console | Cloud DNS features are not available in the Google Cloud console. Use the API or Google Cloud CLI instead. |
Cloud Logging
Affected Cloud Logging features
| Feature | Description |
|---|---|
| Log sinks | Filters shouldn't contain Customer Data. Log sinks include filters which are stored as configuration. Don't create filters that contain Customer Data. |
| Live tailing log entries | Filters shouldn't contain Customer Data. A live tailing session includes a filter which is stored as configuration. Tailing logs doesn't store any log entry data itself, but can query and transmit data across regions. Don't create filters that contain Customer Data. |
| Log-based alerts | This feature is disabled. You cannot create log-based alerts in the Google Cloud console. |
| Shortened URLs for Logs Explorer queries | This feature is disabled. You cannot create shortened URLs of queries in the Google Cloud console. |
| Saving queries in Logs Explorer | This feature is disabled. You cannot save any queries in the Google Cloud console. |
| SQL-based alerting policies | This feature is disabled. You cannot use the SQL-based alerting policies feature. |
Cloud Monitoring
Affected Cloud Monitoring features
| Feature | Description |
|---|---|
| Synthetic Monitor | This feature is disabled. |
| Uptime checks | This feature is disabled. |
Cloud Router
Affected Cloud Router features
| Feature | Description |
|---|---|
| Google Cloud console | Cloud Router features are not available in the Google Cloud console. Use the API or Google Cloud CLI instead. |
Cloud SQL
Affected Cloud SQL features
| Feature | Description |
|---|---|
| Exporting to CSV | Don't use the Exporting to CSV feature as it's not compliant with CGP. This feature is disabled in the Google Cloud console. |
executeSql |
Don't use the executeSql method of the Cloud SQL API as it's not compliant
with CGP. |
Compute Engine
Affected Compute Engine features
| Feature | Description |
|---|---|
| Suspending and resuming a VM instance | This feature is disabled. Suspending and resuming a VM instance requires persistent disk storage, and persistent disk storage used for storing the suspended VM state cannot currently be encrypted by using CMEK. See the gcp.restrictNonCmekServices organization policy
constraint in the section above to understand the data sovereignty and data residency
implications of enabling this feature.
|
| Local SSDs | This feature is disabled. You will be unable to create an instance with Local SSDs because they cannot be encrypted by using CMEK. See the gcp.restrictNonCmekServices organization policy
constraint in the section above to understand the data sovereignty and data residency
implications of enabling this feature.
|
| Google Cloud console | The following Compute Engine features are not available in the Google Cloud console. Use the API or Google Cloud CLI instead: |
| VM metadata security considerations | It's your responsibility not to write sensitive data to the VM metadata server. |
| Bare Metal Solution VMs | You cannot use Bare Metal Solution VMs (o2 VMs) because Bare Metal Solution VMs are not compliant with
CGP.
|
| Google Cloud VMware Engine VMs | You cannot use Google Cloud VMware Engine VMs, as Google Cloud VMware Engine VMs are not compliant
with CGP.
|
| Creating a C3 VM instance | This feature is disabled. |
| Using persistent disks or their snapshots without CMEK | You cannot use persistent disks or their snapshots unless they have been encrypted using
CMEK. |
| Sharing an SSD persistent disk in multi-writer mode | You cannot share an SSD persistent disk in multi-writer mode between VM instances. |
| Adding an instance group to a global load balancer | You cannot add an instance group to a global load balancer. This feature is disabled by the compute.disableGlobalLoadBalancing organization
policy constraint.
|
| Guest environment | It is possible for scripts, daemons, and binaries that are included with the guest
environment to access unencrypted at-rest and in-use data. Depending on your VM
configuration, updates to this software may be installed by default. See
Guest environment for specific
information about each package's contents, source code, and more. These components help you meet data sovereignty through internal security controls and processes. However, if you want additional control, you can also curate your own images or agents and optionally use the compute.trustedImageProjects organization policy
constraint.
For more information, see Building a custom image. |
| OS policies in VM Manager |
Inline scripts and binary output files within the OS policy files are not encrypted using
customer-managed encryption keys (CMEK). Don't include any sensitive information in
these files. Consider storing these scripts and output files in
Cloud Storage buckets. For more information, see
Example OS policies. If you want to restrict the creation or modification of OS policy resources that use inline scripts or binary output files, enable the constraints/osconfig.restrictInlineScriptAndOutputFileUsage organization policy
constraint.For more information, see Constraints for OS Config. |
instances.getSerialPortOutput()
|
This API is disabled. You will be unable to get serial port output from the specified
instance using this API. Change the compute.disableInstanceDataAccessApis organization policy constraint
value to False to enable this API. You can also enable and use the interactive serial
port by following the instructions in
Enabling access for a project.
|
instances.getScreenshot() |
This API is disabled. You will be unable to get a screenshot from the specified instance
using this API. Change the compute.disableInstanceDataAccessApis organization policy constraint
value to False to enable this API. You can also enable and use the interactive serial
port by following the instructions in
Enabling access for a project.
|
Compute Engine organization policy constraints
| Organization policy constraint | Description |
|---|---|
compute.enableComplianceMemoryProtection |
Set to True. Disables some internal diagnostic features to provide additional protection of memory contents when an infrastructure fault occurs. Changing this value may affect your workload's data residency or data sovereignty. |
compute.disableGlobalCloudArmorPolicy |
Set to True. Disables the creation of new global Google Cloud Armor security policies and the addition or modification of rules to existing global Google Cloud Armor security policies. This constraint doesn't restrict the removal of rules or the ability to remove or change the description and listing of global Google Cloud Armor security policies. Regional Google Cloud Armor security policies are unaffected by this constraint. All global and regional security policies that exist prior to the enforcement of this constraint remain in effect. |
compute.disableGlobalLoadBalancing |
Set to True. Disables creation of global load balancing products. Changing this value may affect your workload's data residency or data sovereignty. |
compute.disableGlobalSelfManagedSslCertificate |
Set to True. Disables creation of global self-managed SSL certificates. Changing this value may affect your workload's data residency or data sovereignty. |
compute.disableInstanceDataAccessApis
| Set to True. Globally disables the instances.getSerialPortOutput() and
instances.getScreenshot() APIs.Enabling this constraint prevents you from generating credentials on Windows Server VMs. If you need to manage a username and password on a Windows VM, do the following:
|
compute.disableNonFIPSMachineTypes
| Set to True. Disables creation of VM instance types that do not comply with FIPS requirements. |
compute.restrictNonConfidentialComputing |
(Optional) Value is not set. Set this value to provide additional defense-in-depth. For more information, see the Confidential VM documentation. |
compute.trustedImageProjects |
(Optional) Value is not set. Set this value to provide additional defense-in-depth.
Setting this value constrains image storage and disk instantiation to the specified list of projects. This value affects data sovereignty by preventing use of any unauthorized images or agents. |
Google Cloud NetApp Volumes
Affected Google Cloud NetApp Volumes features
| Feature | Description |
|---|---|
| Supported service levels | CGP supports the following service levels:
|
Pub/Sub
Pub/Sub organization policy constraints
| Organization policy constraint | Description |
|---|---|
pubsub.enforceInTransitRegions |
Set to True. Ensures that Customer Data transits only within the allowed regions specified in the message storage policy for the Pub/Sub topic. Changing this value might affect your workload's data residency or data sovereignty. |
pubsub.managed.disableSubscriptionMessageTransforms |
Set to True. Disables Pub/Sub subscriptions from being set with Single Message Transforms (SMTs). Changing this value might affect your workload's data residency or data sovereignty. |
pubsub.managed.disableTopicMessageTransforms |
Set to True. Disables Pub/Sub topics from being set with Single Message Transforms (SMTs). Changing this value may affect your workload's data residency or data sovereignty. |
Virtual Private Cloud (VPC)
Affected VPC features
| Feature | Description |
|---|---|
| Google Cloud console | VPC networking features are not available in the Google Cloud console. Use the API or Google Cloud CLI instead. |
What's next
- Learn how to create an Assured Workloads folder
- Understand Assured Workloads pricing