国際武器取引規則(ITAR)の Data Boundary
このページでは、Assured Workloads の ITAR ワークロードに適用される一連の制御について説明します。データ所在地、サポートされている Google Cloud プロダクトとその API エンドポイント、それらのプロダクトに適用される制限事項に関する詳細情報が提供されます。ITAR には、次の追加情報が適用されます。
- データ所在地: ITAR コントロール パッケージは、米国のみのリージョンをサポートするデータ ロケーション コントロールを設定します。詳細については、Google Cloud全体の組織のポリシーの制約をご覧ください。
- サポート: ITAR ワークロードのテクニカル サポート サービスは、エンハンストまたはプレミアムの Cloud カスタマーケア サブスクリプションで利用できます。ITAR ワークロードのサポートケースは、米国に拠点を置く US person に転送されます。詳細については、サポートの利用をご覧ください。
- 料金: ITAR コントロール パッケージは、Assured Workloads のプレミアム ティアに含まれており、20% の追加料金が発生します。詳細については、Assured Workloads の料金をご覧ください。
前提条件
ITAR コントロール パッケージのユーザーとしてコンプライアンスを維持するには、次の前提条件を満たし、遵守していることを確認してください。
- Assured Workloads を使用して ITAR フォルダを作成し、そのフォルダにのみ ITAR ワークロードをデプロイします。
- ITAR ワークロードには、対象の ITAR サービスのみを有効にして使用します。
- 特に記載がない限り、Google Cloud MCP サーバーは使用しないでください。ITAR は、Google Cloud MCP サーバーで使用中のデータと転送中のデータのデータ所在地制御を提供しません。不要な Google Cloud MCP サーバーへのアクセスをブロックするには、IAM による Google Cloud MCP サーバーの使用の制御をご覧ください。
- 発生する可能性のあるデータ所在地のリスクを理解し、それを受け入れる意思がある場合を除き、デフォルトの組織のポリシーの制約値を変更しないでください。
- ITAR ワークロードの Google Cloud コンソールにアクセスする場合は、次のいずれかの管轄区域の Google Cloud コンソール URL を使用する必要があります。
- console.us.cloud.google.com
- console.us.cloud.google(フェデレーション ID ユーザーの場合)
- Google Cloud サービス エンドポイントに接続する場合は、そのエンドポイントを提供するサービスのリージョン エンドポイントを使用する必要があります。さらに、以下の点にもご注意ください。
- オンプレミスまたは他のクラウド プロバイダの VM など、Google Cloud以外の VM から Google Cloud サービス エンドポイントに接続する場合は、使用可能ないずれかのプライベート アクセス オプションを使用する必要があります。ここでは、Google Cloud 以外の VM への接続をサポートし、Google Cloud 以外のトラフィックを Google Cloudにルーティングします。
- Google Cloud VM から Google Cloud サービス エンドポイントに接続する場合は、使用可能なプライベート アクセス オプションのいずれかを使用できます。
- 外部 IP アドレスで公開されている Google Cloud VM に接続する場合は、外部 IP アドレスを持つ VM から API にアクセスするをご覧ください。
- ITAR フォルダで使用されるすべてのサービスでは、次のユーザー定義またはセキュリティ構成情報タイプに技術データを保存しないでください。
- エラー メッセージ
- コンソール出力
- 属性データ
- サービス構成データ
- ネットワーク パケット ヘッダー
- リソース識別子
- データラベル
- 指定されたリージョン エンドポイントは、それらを提供するサービスにのみ使用します。詳細については、ITAR の対象となるサービスをご覧ください。
- Google Cloud セキュリティ ベスト プラクティス センターで提供されている一般的なセキュリティ ベスト プラクティスの採用を検討してください。
サポートされているプロダクトと API エンドポイント
特に明記されている場合を除き、ユーザーは Google Cloud コンソールからすべてのサポート対象プロダクトにアクセスできます。サポートされているプロダクトの機能に影響する制限事項(組織のポリシーの制約の設定によって適用される制限事項を含む)は、次の表に記載されています。
プロダクトがリストにない場合、そのプロダクトはサポートされておらず、ITAR の制御要件を満たしていません。デュー デリジェンスを実施し、責任の共有モデルにおけるお客様の責任を十分に理解していない場合は、サポート対象外のプロダクトを使用することをおすすめしません。サポートされていないプロダクトを使用する前に、データ所在地やデータ主権への悪影響など、関連するリスクを認識し、受け入れることを確認してください。
API オペレーションで顧客データとやり取りするサービスは、リージョン API エンドポイントを提供します。ITAR への準拠を維持するには、サービスのグローバル API エンドポイントの代わりにこれらのエンドポイントを使用します。API オペレーションで顧客データとやり取りしないサービスの場合、グローバル API エンドポイントを使用できます。これらのグローバル API エンドポイントを介して ITAR 規制の技術データを送信しないようにするのは、お客様の責任です。顧客データとサービスデータの詳細については、データ所在地をご覧ください。
リージョン API エンドポイントをサポートするプロダクト
サポートされているプロダクトと、そのリージョン API エンドポイントのリストは、次の表に記載されています。これらの API エンドポイントは、顧客データを処理して送信するように設計されています。これらのプロダクトを使用する際に ITAR のコンプライアンス要件をサポートするには、グローバル API エンドポイントではなく、利用可能なリージョン API エンドポイントを使用する必要があります。
| サポートされているサービス | リージョン API エンドポイント | 制限事項 |
|---|---|---|
| AlloyDB for PostgreSQL |
alloydb.us-central1.rep.googleapis.comalloydb.us-central2.rep.googleapis.comalloydb.us-east1.rep.googleapis.comalloydb.us-east4.rep.googleapis.comalloydb.us-east5.rep.googleapis.comalloydb.us-east7.rep.googleapis.comalloydb.us-south1.rep.googleapis.comalloydb.us-west1.rep.googleapis.comalloydb.us-west2.rep.googleapis.comalloydb.us-west3.rep.googleapis.comalloydb.us-west4.rep.googleapis.com |
なし |
| Apigee |
apigee.us.rep.googleapis.com |
なし |
| Artifact Analysis |
containeranalysis.us.rep.googleapis.comcontaineranalysis.us-central1.rep.googleapis.comcontaineranalysis.us-central2.rep.googleapis.comcontaineranalysis.us-east1.rep.googleapis.comcontaineranalysis.us-east4.rep.googleapis.comcontaineranalysis.us-east5.rep.googleapis.comcontaineranalysis.us-east7.rep.googleapis.comcontaineranalysis.us-south1.rep.googleapis.comcontaineranalysis.us-west1.rep.googleapis.comcontaineranalysis.us-west2.rep.googleapis.comcontaineranalysis.us-west3.rep.googleapis.comcontaineranalysis.us-west4.rep.googleapis.com |
なし |
| Artifact Registry |
artifactregistry.us.rep.googleapis.comartifactregistry.us-central1.rep.googleapis.comartifactregistry.us-central2.rep.googleapis.comartifactregistry.us-east1.rep.googleapis.comartifactregistry.us-east4.rep.googleapis.comartifactregistry.us-east5.rep.googleapis.comartifactregistry.us-east7.rep.googleapis.comartifactregistry.us-south1.rep.googleapis.comartifactregistry.us-west1.rep.googleapis.comartifactregistry.us-west2.rep.googleapis.comartifactregistry.us-west3.rep.googleapis.comartifactregistry.us-west4.rep.googleapis.comartifactregistry.us-west8.rep.googleapis.com |
なし |
| Backup and DR サービス |
backupdr.us.rep.googleapis.combackupdr.us-central1.rep.googleapis.combackupdr.us-central2.rep.googleapis.combackupdr.us-east1.rep.googleapis.combackupdr.us-east4.rep.googleapis.combackupdr.us-east5.rep.googleapis.combackupdr.us-east7.rep.googleapis.combackupdr.us-south1.rep.googleapis.combackupdr.us-west1.rep.googleapis.combackupdr.us-west2.rep.googleapis.combackupdr.us-west3.rep.googleapis.combackupdr.us-west4.rep.googleapis.combackupdr.us-west8.rep.googleapis.com |
なし |
| Backup for Google Kubernetes Engine(GKE) |
gkebackup.us-central1.rep.googleapis.comgkebackup.us-east1.rep.googleapis.comgkebackup.us-east4.rep.googleapis.comgkebackup.us-east5.rep.googleapis.comgkebackup.us-east7.rep.googleapis.comgkebackup.us-south1.rep.googleapis.comgkebackup.us-west1.rep.googleapis.comgkebackup.us-west2.rep.googleapis.comgkebackup.us-west3.rep.googleapis.comgkebackup.us-west4.rep.googleapis.comgkebackup.us-west8.rep.googleapis.com |
なし |
| BigQuery |
bigquery.us-central1.rep.googleapis.combigquery.us-central2.rep.googleapis.combigquery.us-east1.rep.googleapis.combigquery.us-east4.rep.googleapis.combigquery.us-east5.rep.googleapis.combigquery.us-east7.rep.googleapis.combigquery.us-south1.rep.googleapis.combigquery.us-west1.rep.googleapis.combigquery.us-west2.rep.googleapis.combigquery.us-west3.rep.googleapis.combigquery.us-west4.rep.googleapis.combigquery.us-west8.rep.googleapis.combigquerymigration.us-central1.rep.googleapis.combigquerymigration.us-central2.rep.googleapis.combigquerymigration.us-east1.rep.googleapis.combigquerymigration.us-east4.rep.googleapis.combigquerymigration.us-east5.rep.googleapis.combigquerymigration.us-east7.rep.googleapis.combigquerymigration.us-south1.rep.googleapis.combigquerymigration.us-west1.rep.googleapis.combigquerymigration.us-west2.rep.googleapis.combigquerymigration.us-west3.rep.googleapis.combigquerymigration.us-west4.rep.googleapis.combigquerymigration.us-west8.rep.googleapis.combigqueryreservation.us-central1.rep.googleapis.combigqueryreservation.us-central2.rep.googleapis.combigqueryreservation.us-east1.rep.googleapis.combigqueryreservation.us-east4.rep.googleapis.combigqueryreservation.us-east5.rep.googleapis.combigqueryreservation.us-east7.rep.googleapis.combigqueryreservation.us-south1.rep.googleapis.combigqueryreservation.us-west1.rep.googleapis.combigqueryreservation.us-west2.rep.googleapis.combigqueryreservation.us-west3.rep.googleapis.combigqueryreservation.us-west4.rep.googleapis.combigqueryreservation.us-west8.rep.googleapis.combigquerystorage.us-central1.rep.googleapis.combigquerystorage.us-central2.rep.googleapis.combigquerystorage.us-east1.rep.googleapis.combigquerystorage.us-east4.rep.googleapis.combigquerystorage.us-east5.rep.googleapis.combigquerystorage.us-east7.rep.googleapis.combigquerystorage.us-south1.rep.googleapis.combigquerystorage.us-west1.rep.googleapis.combigquerystorage.us-west2.rep.googleapis.combigquerystorage.us-west3.rep.googleapis.combigquerystorage.us-west4.rep.googleapis.combigquerystorage.us-west8.rep.googleapis.com |
影響を受ける機能 |
| BigQuery Data Transfer Service |
bigquerydatatransfer.us-central1.rep.googleapis.combigquerydatatransfer.us-central2.rep.googleapis.combigquerydatatransfer.us-east1.rep.googleapis.combigquerydatatransfer.us-east4.rep.googleapis.combigquerydatatransfer.us-east5.rep.googleapis.combigquerydatatransfer.us-east7.rep.googleapis.combigquerydatatransfer.us-south1.rep.googleapis.combigquerydatatransfer.us-west1.rep.googleapis.combigquerydatatransfer.us-west2.rep.googleapis.combigquerydatatransfer.us-west3.rep.googleapis.combigquerydatatransfer.us-west4.rep.googleapis.combigquerydatatransfer.us-west8.rep.googleapis.com |
なし |
| Bigtable |
bigtable.us-central1.rep.googleapis.combigtable.us-central2.rep.googleapis.combigtable.us-east1.rep.googleapis.combigtable.us-east4.rep.googleapis.combigtable.us-east5.rep.googleapis.combigtable.us-east7.rep.googleapis.combigtable.us-south1.rep.googleapis.combigtable.us-west1.rep.googleapis.combigtable.us-west2.rep.googleapis.combigtable.us-west3.rep.googleapis.combigtable.us-west4.rep.googleapis.combigtable.us-west8.rep.googleapis.com |
なし |
| Cloud Build |
cloudbuild.us-central1.rep.googleapis.comcloudbuild.us-central2.rep.googleapis.comcloudbuild.us-east1.rep.googleapis.comcloudbuild.us-east4.rep.googleapis.comcloudbuild.us-east5.rep.googleapis.comcloudbuild.us-east7.rep.googleapis.comcloudbuild.us-south1.rep.googleapis.comcloudbuild.us-west1.rep.googleapis.comcloudbuild.us-west2.rep.googleapis.comcloudbuild.us-west3.rep.googleapis.comcloudbuild.us-west4.rep.googleapis.comcloudbuild.us-west8.rep.googleapis.com |
なし |
| Cloud Deploy |
clouddeploy.us-central1.rep.googleapis.comclouddeploy.us-east1.rep.googleapis.comclouddeploy.us-east4.rep.googleapis.comclouddeploy.us-east5.rep.googleapis.comclouddeploy.us-east7.rep.googleapis.comclouddeploy.us-south1.rep.googleapis.comclouddeploy.us-west1.rep.googleapis.comclouddeploy.us-west2.rep.googleapis.comclouddeploy.us-west3.rep.googleapis.comclouddeploy.us-west4.rep.googleapis.com |
なし |
| Cloud External Key Manager(Cloud EKM) |
cloudkms.us.rep.googleapis.comcloudkms.us-central1.rep.googleapis.comcloudkms.us-central2.rep.googleapis.comcloudkms.us-east1.rep.googleapis.comcloudkms.us-east4.rep.googleapis.comcloudkms.us-east5.rep.googleapis.comcloudkms.us-east7.rep.googleapis.comcloudkms.us-south1.rep.googleapis.comcloudkms.us-west1.rep.googleapis.comcloudkms.us-west2.rep.googleapis.comcloudkms.us-west3.rep.googleapis.comcloudkms.us-west4.rep.googleapis.comcloudkms.us-west8.rep.googleapis.com |
なし |
| Cloud HSM |
cloudkms.us.rep.googleapis.comcloudkms.us-central1.rep.googleapis.comcloudkms.us-central2.rep.googleapis.comcloudkms.us-east1.rep.googleapis.comcloudkms.us-east4.rep.googleapis.comcloudkms.us-east5.rep.googleapis.comcloudkms.us-east7.rep.googleapis.comcloudkms.us-south1.rep.googleapis.comcloudkms.us-west1.rep.googleapis.comcloudkms.us-west2.rep.googleapis.comcloudkms.us-west3.rep.googleapis.comcloudkms.us-west4.rep.googleapis.comcloudkms.us-west8.rep.googleapis.com |
なし |
| Cloud Interconnect |
compute.us-central1.rep.googleapis.comcompute.us-central2.rep.googleapis.comcompute.us-east1.rep.googleapis.comcompute.us-east4.rep.googleapis.comcompute.us-east5.rep.googleapis.comcompute.us-east7.rep.googleapis.comcompute.us-south1.rep.googleapis.comcompute.us-west1.rep.googleapis.comcompute.us-west2.rep.googleapis.comcompute.us-west3.rep.googleapis.comcompute.us-west4.rep.googleapis.comcompute.us-west8.rep.googleapis.com |
影響を受ける機能 |
| Cloud Key Management Service(Cloud KMS) |
cloudkms.us.rep.googleapis.comcloudkms.us-central1.rep.googleapis.comcloudkms.us-central2.rep.googleapis.comcloudkms.us-east1.rep.googleapis.comcloudkms.us-east4.rep.googleapis.comcloudkms.us-east5.rep.googleapis.comcloudkms.us-east7.rep.googleapis.comcloudkms.us-south1.rep.googleapis.comcloudkms.us-west1.rep.googleapis.comcloudkms.us-west2.rep.googleapis.comcloudkms.us-west3.rep.googleapis.comcloudkms.us-west4.rep.googleapis.comcloudkms.us-west8.rep.googleapis.com |
なし |
| Cloud Load Balancing |
compute.us-central1.rep.googleapis.comcompute.us-central2.rep.googleapis.comcompute.us-east1.rep.googleapis.comcompute.us-east4.rep.googleapis.comcompute.us-east5.rep.googleapis.comcompute.us-east7.rep.googleapis.comcompute.us-south1.rep.googleapis.comcompute.us-west1.rep.googleapis.comcompute.us-west2.rep.googleapis.comcompute.us-west3.rep.googleapis.comcompute.us-west4.rep.googleapis.comcompute.us-west8.rep.googleapis.com |
影響を受ける機能 |
| Cloud Logging |
logging.us.rep.googleapis.comlogging.us-central1.rep.googleapis.comlogging.us-central2.rep.googleapis.comlogging.us-east1.rep.googleapis.comlogging.us-east4.rep.googleapis.comlogging.us-east5.rep.googleapis.comlogging.us-east7.rep.googleapis.comlogging.us-south1.rep.googleapis.comlogging.us-west1.rep.googleapis.comlogging.us-west2.rep.googleapis.comlogging.us-west3.rep.googleapis.comlogging.us-west4.rep.googleapis.comlogging.us-west8.rep.googleapis.com |
影響を受ける機能 |
| Cloud NAT |
compute.us-central1.rep.googleapis.comcompute.us-central2.rep.googleapis.comcompute.us-east1.rep.googleapis.comcompute.us-east4.rep.googleapis.comcompute.us-east5.rep.googleapis.comcompute.us-east7.rep.googleapis.comcompute.us-south1.rep.googleapis.comcompute.us-west1.rep.googleapis.comcompute.us-west2.rep.googleapis.comcompute.us-west3.rep.googleapis.comcompute.us-west4.rep.googleapis.comcompute.us-west8.rep.googleapis.com |
影響を受ける機能 |
| Cloud Router |
compute.us-central1.rep.googleapis.comcompute.us-central2.rep.googleapis.comcompute.us-east1.rep.googleapis.comcompute.us-east4.rep.googleapis.comcompute.us-east5.rep.googleapis.comcompute.us-east7.rep.googleapis.comcompute.us-south1.rep.googleapis.comcompute.us-west1.rep.googleapis.comcompute.us-west2.rep.googleapis.comcompute.us-west3.rep.googleapis.comcompute.us-west4.rep.googleapis.comcompute.us-west8.rep.googleapis.com |
影響を受ける機能 |
| Cloud Run |
run.us-central1.rep.googleapis.comrun.us-central2.rep.googleapis.comrun.us-east1.rep.googleapis.comrun.us-east4.rep.googleapis.comrun.us-east5.rep.googleapis.comrun.us-east7.rep.googleapis.comrun.us-south1.rep.googleapis.comrun.us-west1.rep.googleapis.comrun.us-west2.rep.googleapis.comrun.us-west3.rep.googleapis.comrun.us-west4.rep.googleapis.comrun.us-west8.rep.googleapis.com |
影響を受ける機能 |
| Cloud SQL |
sqladmin.us-central1.rep.googleapis.comsqladmin.us-central2.rep.googleapis.comsqladmin.us-east1.rep.googleapis.comsqladmin.us-east4.rep.googleapis.comsqladmin.us-east5.rep.googleapis.comsqladmin.us-east7.rep.googleapis.comsqladmin.us-south1.rep.googleapis.comsqladmin.us-west1.rep.googleapis.comsqladmin.us-west2.rep.googleapis.comsqladmin.us-west3.rep.googleapis.comsqladmin.us-west4.rep.googleapis.comsqladmin.us-west8.rep.googleapis.com |
影響を受ける機能 |
| Cloud Service Mesh |
trafficdirector.us-central1.rep.googleapis.comtrafficdirector.us-central2.rep.googleapis.comtrafficdirector.us-east1.rep.googleapis.comtrafficdirector.us-east4.rep.googleapis.comtrafficdirector.us-east5.rep.googleapis.comtrafficdirector.us-east7.rep.googleapis.comtrafficdirector.us-south1.rep.googleapis.comtrafficdirector.us-west1.rep.googleapis.comtrafficdirector.us-west2.rep.googleapis.comtrafficdirector.us-west3.rep.googleapis.comtrafficdirector.us-west4.rep.googleapis.comtrafficdirector.us-west8.rep.googleapis.com |
なし |
| Spanner |
spanner.us.rep.googleapis.comspanner.us-central1.rep.googleapis.comspanner.us-central2.rep.googleapis.comspanner.us-east1.rep.googleapis.comspanner.us-east4.rep.googleapis.comspanner.us-east5.rep.googleapis.comspanner.us-east7.rep.googleapis.comspanner.us-south1.rep.googleapis.comspanner.us-west1.rep.googleapis.comspanner.us-west2.rep.googleapis.comspanner.us-west3.rep.googleapis.comspanner.us-west4.rep.googleapis.comspanner.us-west8.rep.googleapis.com |
影響を受ける機能と組織のポリシーの制約 |
| Cloud Storage |
storage.us.rep.googleapis.comstorage.us-central1.rep.googleapis.comstorage.us-central2.rep.googleapis.comstorage.us-east1.rep.googleapis.comstorage.us-east4.rep.googleapis.comstorage.us-east5.rep.googleapis.comstorage.us-east7.rep.googleapis.comstorage.us-south1.rep.googleapis.comstorage.us-west1.rep.googleapis.comstorage.us-west2.rep.googleapis.comstorage.us-west3.rep.googleapis.comstorage.us-west4.rep.googleapis.comstorage.us-west8.rep.googleapis.com |
影響を受ける機能 |
| Cloud VPN |
compute.us-central1.rep.googleapis.comcompute.us-central2.rep.googleapis.comcompute.us-east1.rep.googleapis.comcompute.us-east4.rep.googleapis.comcompute.us-east5.rep.googleapis.comcompute.us-east7.rep.googleapis.comcompute.us-south1.rep.googleapis.comcompute.us-west1.rep.googleapis.comcompute.us-west2.rep.googleapis.comcompute.us-west3.rep.googleapis.comcompute.us-west4.rep.googleapis.comcompute.us-west8.rep.googleapis.com |
影響を受ける機能 |
| Compute Engine |
compute.us-central1.rep.googleapis.comcompute.us-central2.rep.googleapis.comcompute.us-east1.rep.googleapis.comcompute.us-east4.rep.googleapis.comcompute.us-east5.rep.googleapis.comcompute.us-east7.rep.googleapis.comcompute.us-south1.rep.googleapis.comcompute.us-west1.rep.googleapis.comcompute.us-west2.rep.googleapis.comcompute.us-west3.rep.googleapis.comcompute.us-west4.rep.googleapis.comcompute.us-west8.rep.googleapis.com |
影響を受ける機能と組織のポリシーの制約 |
| Dataflow |
dataflow.us-central1.rep.googleapis.comdataflow.us-central2.rep.googleapis.comdataflow.us-east1.rep.googleapis.comdataflow.us-east4.rep.googleapis.comdataflow.us-east5.rep.googleapis.comdataflow.us-east7.rep.googleapis.comdataflow.us-south1.rep.googleapis.comdataflow.us-west1.rep.googleapis.comdataflow.us-west2.rep.googleapis.comdataflow.us-west3.rep.googleapis.comdataflow.us-west4.rep.googleapis.comdataflow.us-west8.rep.googleapis.com |
なし |
| Eventarc |
eventarc.us.rep.googleapis.comeventarc.us-central1.rep.googleapis.comeventarc.us-central2.rep.googleapis.comeventarc.us-east1.rep.googleapis.comeventarc.us-east4.rep.googleapis.comeventarc.us-east5.rep.googleapis.comeventarc.us-east7.rep.googleapis.comeventarc.us-south1.rep.googleapis.comeventarc.us-west1.rep.googleapis.comeventarc.us-west2.rep.googleapis.comeventarc.us-west3.rep.googleapis.comeventarc.us-west4.rep.googleapis.comeventarc.us-west8.rep.googleapis.com |
なし |
| 外部パススルー ネットワーク ロードバランサ |
compute.us-central1.rep.googleapis.comcompute.us-central2.rep.googleapis.comcompute.us-east1.rep.googleapis.comcompute.us-east4.rep.googleapis.comcompute.us-east5.rep.googleapis.comcompute.us-east7.rep.googleapis.comcompute.us-south1.rep.googleapis.comcompute.us-west1.rep.googleapis.comcompute.us-west2.rep.googleapis.comcompute.us-west3.rep.googleapis.comcompute.us-west4.rep.googleapis.comcompute.us-west8.rep.googleapis.com |
なし |
| Filestore |
file.us-central1.rep.googleapis.comfile.us-central2.rep.googleapis.comfile.us-east1.rep.googleapis.comfile.us-east4.rep.googleapis.comfile.us-east5.rep.googleapis.comfile.us-east7.rep.googleapis.comfile.us-south1.rep.googleapis.comfile.us-west1.rep.googleapis.comfile.us-west2.rep.googleapis.comfile.us-west3.rep.googleapis.comfile.us-west4.rep.googleapis.comfile.us-west8.rep.googleapis.com |
なし |
| Firestore |
firestore.us.rep.googleapis.comfirestore.us-central1.rep.googleapis.comfirestore.us-east1.rep.googleapis.comfirestore.us-east4.rep.googleapis.comfirestore.us-east5.rep.googleapis.comfirestore.us-east7.rep.googleapis.comfirestore.us-south1.rep.googleapis.comfirestore.us-west1.rep.googleapis.comfirestore.us-west2.rep.googleapis.comfirestore.us-west3.rep.googleapis.comfirestore.us-west4.rep.googleapis.comfirestore.us-west8.rep.googleapis.com |
なし |
| Google Kubernetes Engine(GKE)Hub(フリート) |
gkehub.us-central1.rep.googleapis.comgkehub.us-central2.rep.googleapis.comgkehub.us-east1.rep.googleapis.comgkehub.us-east4.rep.googleapis.comgkehub.us-east5.rep.googleapis.comgkehub.us-east7.rep.googleapis.comgkehub.us-south1.rep.googleapis.comgkehub.us-west1.rep.googleapis.comgkehub.us-west2.rep.googleapis.comgkehub.us-west3.rep.googleapis.comgkehub.us-west4.rep.googleapis.comgkehub.us-west8.rep.googleapis.com |
なし |
| Vertex AI の生成 AI |
aiplatform.us.rep.googleapis.com |
組織ポリシーの制約 |
| Google Cloud Armor |
compute.us-central1.rep.googleapis.comcompute.us-central2.rep.googleapis.comcompute.us-east1.rep.googleapis.comcompute.us-east4.rep.googleapis.comcompute.us-east5.rep.googleapis.comcompute.us-east7.rep.googleapis.comcompute.us-south1.rep.googleapis.comcompute.us-west1.rep.googleapis.comcompute.us-west2.rep.googleapis.comcompute.us-west3.rep.googleapis.comcompute.us-west4.rep.googleapis.comcompute.us-west8.rep.googleapis.com |
影響を受ける機能 |
| Google Cloud Managed Service for Apache Kafka |
managedkafka.us-central1.rep.googleapis.commanagedkafka.us-east1.rep.googleapis.commanagedkafka.us-east4.rep.googleapis.commanagedkafka.us-east5.rep.googleapis.commanagedkafka.us-east7.rep.googleapis.commanagedkafka.us-south1.rep.googleapis.commanagedkafka.us-west1.rep.googleapis.commanagedkafka.us-west2.rep.googleapis.commanagedkafka.us-west3.rep.googleapis.commanagedkafka.us-west4.rep.googleapis.com |
なし |
| 内部パススルー ネットワーク ロードバランサ |
compute.us-central1.rep.googleapis.comcompute.us-central2.rep.googleapis.comcompute.us-east1.rep.googleapis.comcompute.us-east4.rep.googleapis.comcompute.us-east5.rep.googleapis.comcompute.us-east7.rep.googleapis.comcompute.us-south1.rep.googleapis.comcompute.us-west1.rep.googleapis.comcompute.us-west2.rep.googleapis.comcompute.us-west3.rep.googleapis.comcompute.us-west4.rep.googleapis.comcompute.us-west8.rep.googleapis.com |
なし |
| Key Access Justifications |
cloudkms.us.rep.googleapis.comcloudkms.us-central1.rep.googleapis.comcloudkms.us-central2.rep.googleapis.comcloudkms.us-east1.rep.googleapis.comcloudkms.us-east4.rep.googleapis.comcloudkms.us-east5.rep.googleapis.comcloudkms.us-east7.rep.googleapis.comcloudkms.us-south1.rep.googleapis.comcloudkms.us-west1.rep.googleapis.comcloudkms.us-west2.rep.googleapis.comcloudkms.us-west3.rep.googleapis.comcloudkms.us-west4.rep.googleapis.comcloudkms.us-west8.rep.googleapis.com |
なし |
| Knowledge Catalog |
dataplex.us.rep.googleapis.comdataplex.us-central1.rep.googleapis.comdataplex.us-central2.rep.googleapis.comdataplex.us-east1.rep.googleapis.comdataplex.us-east4.rep.googleapis.comdataplex.us-east5.rep.googleapis.comdataplex.us-east7.rep.googleapis.comdataplex.us-south1.rep.googleapis.comdataplex.us-west1.rep.googleapis.comdataplex.us-west2.rep.googleapis.comdataplex.us-west3.rep.googleapis.comdataplex.us-west4.rep.googleapis.comdataplex.us-west8.rep.googleapis.comdatalineage.us.rep.googleapis.comdatalineage.us-central1.rep.googleapis.comdatalineage.us-central2.rep.googleapis.comdatalineage.us-east1.rep.googleapis.comdatalineage.us-east4.rep.googleapis.comdatalineage.us-east5.rep.googleapis.comdatalineage.us-east7.rep.googleapis.comdatalineage.us-south1.rep.googleapis.comdatalineage.us-west1.rep.googleapis.comdatalineage.us-west2.rep.googleapis.comdatalineage.us-west3.rep.googleapis.comdatalineage.us-west4.rep.googleapis.com |
影響を受ける機能 |
| Managed Service for Apache Airflow |
composer.us-central1.rep.googleapis.comcomposer.us-east1.rep.googleapis.comcomposer.us-east4.rep.googleapis.comcomposer.us-east5.rep.googleapis.comcomposer.us-east7.rep.googleapis.comcomposer.us-south1.rep.googleapis.comcomposer.us-west1.rep.googleapis.comcomposer.us-west2.rep.googleapis.comcomposer.us-west3.rep.googleapis.comcomposer.us-west4.rep.googleapis.com |
なし |
| Managed Service for Apache Spark |
dataproc-control.us-central1.rep.googleapis.comdataproc-control.us-central2.rep.googleapis.comdataproc-control.us-east1.rep.googleapis.comdataproc-control.us-east4.rep.googleapis.comdataproc-control.us-east5.rep.googleapis.comdataproc-control.us-east7.rep.googleapis.comdataproc-control.us-south1.rep.googleapis.comdataproc-control.us-west1.rep.googleapis.comdataproc-control.us-west2.rep.googleapis.comdataproc-control.us-west3.rep.googleapis.comdataproc-control.us-west4.rep.googleapis.comdataproc-control.us-west8.rep.googleapis.comdataproc.us-central1.rep.googleapis.comdataproc.us-central2.rep.googleapis.comdataproc.us-east1.rep.googleapis.comdataproc.us-east4.rep.googleapis.comdataproc.us-east5.rep.googleapis.comdataproc.us-east7.rep.googleapis.comdataproc.us-south1.rep.googleapis.comdataproc.us-west1.rep.googleapis.comdataproc.us-west2.rep.googleapis.comdataproc.us-west3.rep.googleapis.comdataproc.us-west4.rep.googleapis.comdataproc.us-west8.rep.googleapis.com |
なし |
| Memorystore for Redis |
redis.us-central1.rep.googleapis.comredis.us-central2.rep.googleapis.comredis.us-east1.rep.googleapis.comredis.us-east4.rep.googleapis.comredis.us-east5.rep.googleapis.comredis.us-east7.rep.googleapis.comredis.us-south1.rep.googleapis.comredis.us-west1.rep.googleapis.comredis.us-west2.rep.googleapis.comredis.us-west3.rep.googleapis.comredis.us-west4.rep.googleapis.comredis.us-west8.rep.googleapis.com |
なし |
| Persistent Disk |
compute.us-central1.rep.googleapis.comcompute.us-central2.rep.googleapis.comcompute.us-east1.rep.googleapis.comcompute.us-east4.rep.googleapis.comcompute.us-east5.rep.googleapis.comcompute.us-east7.rep.googleapis.comcompute.us-south1.rep.googleapis.comcompute.us-west1.rep.googleapis.comcompute.us-west2.rep.googleapis.comcompute.us-west3.rep.googleapis.comcompute.us-west4.rep.googleapis.comcompute.us-west8.rep.googleapis.com |
なし |
| Pub/Sub |
pubsub.us-central1.rep.googleapis.compubsub.us-central2.rep.googleapis.compubsub.us-east1.rep.googleapis.compubsub.us-east4.rep.googleapis.compubsub.us-east5.rep.googleapis.compubsub.us-east7.rep.googleapis.compubsub.us-south1.rep.googleapis.compubsub.us-west1.rep.googleapis.compubsub.us-west2.rep.googleapis.compubsub.us-west3.rep.googleapis.compubsub.us-west4.rep.googleapis.compubsub.us-west8.rep.googleapis.com |
組織ポリシーの制約 |
| リージョン外部アプリケーション ロードバランサ |
compute.us-central1.rep.googleapis.comcompute.us-central2.rep.googleapis.comcompute.us-east1.rep.googleapis.comcompute.us-east4.rep.googleapis.comcompute.us-east5.rep.googleapis.comcompute.us-east7.rep.googleapis.comcompute.us-south1.rep.googleapis.comcompute.us-west1.rep.googleapis.comcompute.us-west2.rep.googleapis.comcompute.us-west3.rep.googleapis.comcompute.us-west4.rep.googleapis.comcompute.us-west8.rep.googleapis.com |
なし |
| リージョン外部プロキシ ネットワーク ロードバランサ |
compute.us-central1.rep.googleapis.comcompute.us-central2.rep.googleapis.comcompute.us-east1.rep.googleapis.comcompute.us-east4.rep.googleapis.comcompute.us-east5.rep.googleapis.comcompute.us-east7.rep.googleapis.comcompute.us-south1.rep.googleapis.comcompute.us-west1.rep.googleapis.comcompute.us-west2.rep.googleapis.comcompute.us-west3.rep.googleapis.comcompute.us-west4.rep.googleapis.comcompute.us-west8.rep.googleapis.com |
なし |
| リージョン内部アプリケーション ロードバランサ |
compute.us-central1.rep.googleapis.comcompute.us-central2.rep.googleapis.comcompute.us-east1.rep.googleapis.comcompute.us-east4.rep.googleapis.comcompute.us-east5.rep.googleapis.comcompute.us-east7.rep.googleapis.comcompute.us-south1.rep.googleapis.comcompute.us-west1.rep.googleapis.comcompute.us-west2.rep.googleapis.comcompute.us-west3.rep.googleapis.comcompute.us-west4.rep.googleapis.comcompute.us-west8.rep.googleapis.com |
なし |
| リージョン内部プロキシ ネットワーク ロードバランサ |
compute.us-central1.rep.googleapis.comcompute.us-central2.rep.googleapis.comcompute.us-east1.rep.googleapis.comcompute.us-east4.rep.googleapis.comcompute.us-east5.rep.googleapis.comcompute.us-east7.rep.googleapis.comcompute.us-south1.rep.googleapis.comcompute.us-west1.rep.googleapis.comcompute.us-west2.rep.googleapis.comcompute.us-west3.rep.googleapis.comcompute.us-west4.rep.googleapis.comcompute.us-west8.rep.googleapis.com |
なし |
| Secret Manager |
secretmanager.us.rep.googleapis.comsecretmanager.us-central1.rep.googleapis.comsecretmanager.us-central2.rep.googleapis.comsecretmanager.us-east1.rep.googleapis.comsecretmanager.us-east4.rep.googleapis.comsecretmanager.us-east5.rep.googleapis.comsecretmanager.us-east7.rep.googleapis.comsecretmanager.us-south1.rep.googleapis.comsecretmanager.us-west1.rep.googleapis.comsecretmanager.us-west2.rep.googleapis.comsecretmanager.us-west3.rep.googleapis.comsecretmanager.us-west4.rep.googleapis.com |
なし |
| Secure Source Manager |
securesourcemanager.us-central1.rep.googleapis.comsecuresourcemanager.us-east1.rep.googleapis.comsecuresourcemanager.us-east4.rep.googleapis.comsecuresourcemanager.us-east7.rep.googleapis.comsecuresourcemanager.us-west2.rep.googleapis.com |
なし |
| Security Command Center Premium |
securitycenter.us.rep.googleapis.com |
影響を受ける機能 |
| Sensitive Data Protection |
dlp.us.rep.googleapis.comdlp.us-central1.rep.googleapis.comdlp.us-central2.rep.googleapis.comdlp.us-east1.rep.googleapis.comdlp.us-east4.rep.googleapis.comdlp.us-east5.rep.googleapis.comdlp.us-south1.rep.googleapis.comdlp.us-west1.rep.googleapis.comdlp.us-west2.rep.googleapis.comdlp.us-west3.rep.googleapis.comdlp.us-west4.rep.googleapis.comdlp.us-west8.rep.googleapis.com |
なし |
| Service Directory |
servicedirectory.us-central1.rep.googleapis.comservicedirectory.us-central2.rep.googleapis.comservicedirectory.us-east1.rep.googleapis.comservicedirectory.us-east4.rep.googleapis.comservicedirectory.us-east5.rep.googleapis.comservicedirectory.us-east7.rep.googleapis.comservicedirectory.us-south1.rep.googleapis.comservicedirectory.us-west1.rep.googleapis.comservicedirectory.us-west2.rep.googleapis.comservicedirectory.us-west3.rep.googleapis.comservicedirectory.us-west4.rep.googleapis.comservicedirectory.us-west8.rep.googleapis.com |
なし |
| Vertex AI オンライン予測 |
aiplatform.us.rep.googleapis.com |
組織ポリシーの制約 |
| VM Manager |
osconfig.us-central1.rep.googleapis.comosconfig.us-central2.rep.googleapis.comosconfig.us-east1.rep.googleapis.comosconfig.us-east4.rep.googleapis.comosconfig.us-east5.rep.googleapis.comosconfig.us-east7.rep.googleapis.comosconfig.us-south1.rep.googleapis.comosconfig.us-west1.rep.googleapis.comosconfig.us-west2.rep.googleapis.comosconfig.us-west3.rep.googleapis.comosconfig.us-west4.rep.googleapis.comosconfig.us-west8.rep.googleapis.com |
なし |
| Virtual Private Cloud(VPC) |
compute.us-central1.rep.googleapis.comcompute.us-central2.rep.googleapis.comcompute.us-east1.rep.googleapis.comcompute.us-east4.rep.googleapis.comcompute.us-east5.rep.googleapis.comcompute.us-east7.rep.googleapis.comcompute.us-south1.rep.googleapis.comcompute.us-west1.rep.googleapis.comcompute.us-west2.rep.googleapis.comcompute.us-west3.rep.googleapis.comcompute.us-west4.rep.googleapis.comcompute.us-west8.rep.googleapis.com |
影響を受ける機能 |
グローバル API エンドポイントをサポートするプロダクト
サポートされているプロダクトとそのグローバル API エンドポイントのリストは、次の表に記載されています。これらのグローバル API エンドポイントは、構成データ、メタデータ、リソース識別子などのサービスデータを処理するように設計されており、顧客データを処理することを目的としていません。これらのグローバル API エンドポイントを介して ITAR 規制の技術データが送信されないようにする責任はお客様にあります。
| サポートされているサービス | グローバル API エンドポイント | 制限事項 |
|---|---|---|
| アクセス承認 |
accessapproval.googleapis.com |
なし |
| Access Context Manager |
accesscontextmanager.googleapis.com |
なし |
| Certificate Authority Service |
privateca.googleapis.com |
なし |
| Certificate Manager |
certificatemanager.googleapis.com |
なし |
| Cloud Billing API |
billingbudgets.googleapis.comcloudbilling.googleapis.com |
なし |
| Cloud DNS |
dns.googleapis.com |
影響を受ける機能 |
| Cloud Monitoring |
monitoring.googleapis.com |
影響を受ける機能 |
| Cloud OS Login API |
oslogin.googleapis.com |
なし |
| 重要な連絡先 |
essentialcontacts.googleapis.com |
なし |
| Firebase セキュリティ ルール |
firebaserules.googleapis.com |
なし |
| Google Kubernetes Engine(GKE)Identity Service |
anthosidentityservice.googleapis.com |
なし |
| GKE イメージ ストリーミング |
containerfilesystem.googleapis.com |
なし |
| Google Kubernetes Engine(GKE) |
container.googleapis.comcontainersecurity.googleapis.com |
影響を受ける機能と組織のポリシーの制約 |
| Identity and Access Management(IAM) |
iam.googleapis.com |
なし |
| Identity-Aware Proxy(IAP) |
iap.googleapis.com |
なし |
| 法域 Google Cloud コンソール |
Not applicable |
なし |
| Network Connectivity Center |
networkconnectivity.googleapis.com |
影響を受ける機能 |
| 組織ポリシー サービス |
orgpolicy.googleapis.com |
なし |
| Resource Manager |
cloudresourcemanager.googleapis.com |
なし |
| VPC Service Controls |
accesscontextmanager.googleapis.comaccesscontextintelligence.googleapis.com |
なし |
制限事項
以降のセクションでは、 Google Cloud全体またはプロダクト固有の制限、または機能の制限について説明します。これには、ITAR フォルダにデフォルトで設定されている組織ポリシーの制約も含まれます。デフォルトで設定されていない場合でも、その他の適用可能な組織のポリシーの制約により、組織の Google Cloud リソースをさらに保護するための多層防御を追加できます。
Google Cloud-wide
影響を受ける Google Cloud全体の機能
| 機能 | 説明 |
|---|---|
| Google Cloud コンソール | ITAR コントロール パッケージを使用するときに Google Cloud コンソールにアクセスするには、次のいずれかの URL を使用する必要があります。
|
Google Cloud全体の組織ポリシー制約
次の組織のポリシーの制約は、 Google Cloud全体に適用されます。
| 組織のポリシーの制約 | 説明 |
|---|---|
gcp.resourceLocations |
allowedValues リストの次の場所に設定します。
制限を緩くしてこの値を変更すると、準拠したデータ境界外でデータを作成または保存できるようになるため、データ所在地が損なわれる可能性があります。 |
gcp.restrictCmekCryptoKeyProjects |
Assured Workloads 組織である under:organizations/your-organization-name に設定します。プロジェクトまたはフォルダを指定することで、この値をさらに制限できます。CMEK を使用して保存データの暗号化を行うために Cloud KMS 鍵を提供できる承認済みフォルダまたはプロジェクトのスコープを制限します。この制約により、承認されていないフォルダまたはプロジェクトが暗号鍵を提供できなくなるため、対象範囲内のサービスの保管中のデータのデータ主権を保証できます。 |
gcp.restrictNonCmekServices |
対象範囲内のすべての API サービス名のリストに設定します。次に例を示します。
各サービスには、顧客管理の暗号鍵(CMEK)が必要です。CMEK は、Google のデフォルトの暗号化メカニズムではなく、ユーザーが管理している鍵で保存データを暗号化します。 リストから 1 つ以上の対象サービスを削除してこの値を変更すると、データ主権が損なわれる可能性があります。新しい保管中のデータは、ユーザーではなく Google 独自の鍵を使用して自動的に暗号化されます。既存の保存データは、指定した鍵によって暗号化されたままになります。 |
gcp.restrictServiceUsage |
すべてのサポートされているプロダクトと API エンドポイントを許可するように設定します。 リソースへのランタイム アクセスを制限することで、使用できるサービスを決定します。詳細については、リソース使用量の制限をご覧ください。 |
gcp.restrictTLSVersion |
次の TLS バージョンを拒否するように設定します。
|
BigQuery
影響を受ける BigQuery の機能
| 機能 | 説明 |
|---|---|
| 新しいフォルダで BigQuery を有効にする | BigQuery はサポートされていますが、内部構成プロセスにより、Assured Workloads フォルダ新規作成時には自動的には有効になりません。通常、このプロセスは 10 分で完了しますが、状況によってはさらに時間がかかることもあります。プロセスが完了したかどうかを確認し、BigQuery を有効にするには、次の操作を行います。
有効化プロセスが完了すると、Assured Workloads フォルダで BigQuery を使用できるようになります。 Gemini in BigQuery は Assured Workloads ではサポートされていません。 |
| 準拠している BigQuery API | 次の BigQuery API は ITAR に準拠しています。 |
| リージョン | BigQuery は、米国のマルチリージョンを除くすべての BigQuery 米国リージョンで ITAR に準拠しています。データセットが米国のマルチリージョン、米国以外のリージョン、米国以外のマルチリージョンに作成されている場合、ITAR への準拠は保証されません。BigQuery データセットを作成する際に ITAR に準拠するリージョンを指定する責任はお客様にあります。 |
| ITAR 以外のプロジェクトからの ITAR データセットに対するクエリ | BigQuery では、ITAR 以外のプロジェクトからの ITAR データセットへのクエリを防ぐことはできません。ITAR 技術データに対して読み取りまたは結合オペレーションを使用するクエリが、ITAR 準拠のフォルダにあることを確認します。 |
| 外部データソースへの接続 | Google のコンプライアンス責任は、BigQuery Connection API の機能に限定されます。BigQuery Connection API で使用されるソースプロダクトのコンプライアンスを確保するのは、お客様の責任です。 |
| 対応していない機能 | 次の BigQuery 機能はサポートされていないため、BigQuery CLI では使用しないでください。Assured Workloads に対して、これらを BigQuery で使用しないようにすることはお客様の責任です。
|
| BigQuery CLI | BigQuery CLI がサポートされています。
|
| Google Cloud SDK | テクニカル データのデータリージョン指定の保証を維持するには、Google Cloud SDK バージョン 403.0.0 以降を使用する必要があります。現在の Google Cloud SDK のバージョンを確認するには、gcloud --version を実行してから gcloud components update を実行し、最新バージョンに更新します。 |
| 管理機能 | BigQuery はサポートされていない API を無効にしますが、Assured Workloads フォルダを作成するのに十分な権限を持つ管理者は、サポートされていない API を有効にできます。この場合、Assured Workloads モニタリング ダッシュボードで、コンプライアンス違反の可能性がある旨が通知されます。 |
| データの読み込み | Google の Software as a Service(SaaS)アプリ、外部クラウド ストレージ プロバイダ、データ ウェアハウス用の BigQuery Data Transfer Service コネクタはサポートされていません。お客様は、ITAR ワークロードに対して BigQuery Data Transfer Service コネクタを使用しないようにする責任があります。 |
| サードパーティ転送 | BigQuery は、BigQuery Data Transfer Service のサードパーティ転送のサポートを検証しません。BigQuery Data Transfer Service のサードパーティ転送を使用する際のサポート確認は、お客様の責任です。 |
| 非準拠 BQML モデル | 外部でトレーニングされた BQML モデルは対象外です。 |
| クエリジョブ | クエリジョブは、Assured Workloads フォルダ内でのみ作成する必要があります。 |
| 他のプロジェクトのデータセットに対するクエリ | BigQuery では、Assured Workloads 以外のプロジェクトから Assured Workloads データセットへのクエリを防ぐことはできません。Assured Workloads データに対して読み取りや結合を行うクエリはすべて、Assured Workloads フォルダに配置する必要があります。ユーザーは、BigQuery CLI で projectname.dataset.table を使用して、クエリ結果の完全修飾されたテーブル名を指定できます。 |
| Cloud Logging | BigQuery は、一部のログデータに対して Cloud Logging を利用します。コンプライアンスを維持するには、_default ロギング バケットを無効にするか、次のコマンドを使用して _default バケットを対象範囲内のリージョンに制限する必要があります。gcloud alpha logging settings update --organization=ORGANIZATION_ID --disable-default-sink
詳細については、ログをリージョン化するをご覧ください。 |
Cloud DNS
影響を受ける Cloud DNS 機能
| 機能 | 説明 |
|---|---|
| Google Cloud コンソール | Cloud DNS の機能は Google Cloud コンソールで使用できません。代わりに API または Google Cloud CLI を使用してください。 |
Cloud Interconnect
影響を受ける Cloud Interconnect の機能
| 機能 | 説明 |
|---|---|
| Google Cloud コンソール | Cloud Interconnect の機能は Google Cloud コンソールで使用できません。代わりに API または Google Cloud CLI を使用してください。 |
| 高可用性(HA)VPN | Cloud VPN で Cloud Interconnect を使用する場合は、高可用性(HA)VPN 機能を有効にする必要があります。また、影響を受ける Cloud VPN 機能セクションに記載されている暗号化と地域化の要件にも準拠する必要があります。 |
Cloud Load Balancing
影響を受ける Cloud Load Balancing の機能
| 機能 | 説明 |
|---|---|
| Google Cloud コンソール | Cloud Load Balancing の機能は Google Cloud コンソールで使用できません。代わりに API または Google Cloud CLI を使用してください。 |
| リージョン ロードバランサ | ITAR では、リージョン ロードバランサのみを使用する必要があります。リージョン ロードバランサの構成の詳細については、次のページをご覧ください。 |
Cloud Logging
影響を受ける Cloud Logging の機能
| 機能 | 説明 |
|---|---|
| ログシンク | フィルタに顧客データを含めないでください。 ログシンクには、構成として格納されるフィルタが含まれます。顧客データを含むフィルタは作成しないでください。 |
| ライブ テーリング ログエントリ | フィルタに顧客データを含めないでください。 ライブ テーリング セッションには、構成として格納されたフィルタが含まれます。テーリングログによって、ログエントリのデータが保存されることはありませんが、リージョン間でデータをクエリして送信できます。顧客データを含むフィルタは作成しないでください。 |
| ログベースのアラート | この機能は無効になっています。 Google Cloud コンソールでログベースのアラートを作成することはできません。 |
| ログ エクスプローラ クエリの短縮 URL | この機能は無効になっています。 Google Cloud コンソールでは、クエリの短縮 URL を作成できません。 |
| ログ エクスプローラにクエリを保存する | この機能は無効になっています。 Google Cloud コンソールではクエリを保存できません。 |
| SQL ベースのアラート ポリシー | この機能は無効になっています。 SQL ベースのアラート ポリシー機能は使用できません。 |
Cloud Monitoring
影響を受ける Cloud Monitoring の機能
| 機能 | 説明 |
|---|---|
| 合成モニター | この機能は無効になっています。 |
| 稼働時間チェック | この機能は無効になっています。 |
| ダッシュボードのログパネル ウィジェット | この機能は無効になっています。 ダッシュボードにログパネルを追加することはできません。 |
| ダッシュボードの Error Reporting パネル ウィジェット | この機能は無効になっています。 ダッシュボードに Error Reporting パネルを追加することはできません。 |
ダッシュボードの EventAnnotation のフィルタ |
この機能は無効になっています。EventAnnotation のフィルタはダッシュボードで設定できません。 |
alertPolicies での SqlCondition |
この機能は無効になっています。alertPolicy に SqlCondition を追加することはできません。 |
Cloud NAT
影響を受ける Cloud NAT の機能
| 機能 | 説明 |
|---|---|
| Google Cloud コンソール | Cloud NAT の機能は Google Cloud コンソールで使用できません。代わりに API または Google Cloud CLI を使用してください。 |
Cloud Router
影響を受ける Cloud Router の機能
| 機能 | 説明 |
|---|---|
| Google Cloud コンソール | Cloud Router の機能は Google Cloud コンソールで使用できません。代わりに API または Google Cloud CLI を使用してください。 |
Cloud Run
影響を受ける Cloud Run の機能
| 機能 | 説明 |
|---|---|
| サポートされていない機能 | 次の Cloud Run 機能はサポートされていません。 |
Cloud SQL
影響を受ける Cloud SQL の機能
| 機能 | 説明 |
|---|---|
| CSV へのエクスポート | CSV へのエクスポート機能は ITAR に準拠していないため、使用しないでください。この機能は Google Cloud コンソールでは無効になっています。 |
executeSql |
Cloud SQL API の executeSql メソッドは ITAR に準拠していないため、使用しないでください。 |
Cloud Storage
影響を受ける Cloud Storage の機能
| 機能 | 説明 |
|---|---|
| Google Cloud コンソール | ITAR への準拠を維持するため、管轄区域の Google Cloud コンソールを使用する責任はお客様にあります。管轄地区のコンソールでは、Cloud Storage オブジェクトのアップロードとダウンロードがブロックされます。Cloud Storage オブジェクトをアップロードおよびダウンロードするには、このセクションの準拠した API エンドポイントの行をご覧ください。 |
| 準拠した API エンドポイント | Cloud Storage で ITAR 準拠のリージョン エンドポイントのいずれかを使用する必要があります。詳細については、Cloud Storage リージョン エンドポイントと Cloud Storage のロケーションをご覧ください。 |
| 制限事項 | ITAR に準拠するには、Cloud Storage リージョン エンドポイントを使用する必要があります。ITAR の Cloud Storage リージョン エンドポイントの詳細については、Cloud Storage リージョン エンドポイントをご覧ください。 次のオペレーションは、リージョン エンドポイントでは対象外です。ただし、これらのオペレーションでは、データ所在地に関するサービス規約で定義されている顧客データを扱いません。したがって、ITAR への準拠に違反することなく、必要に応じてこれらのオペレーションにグローバル エンドポイントを使用できます。 |
| オブジェクトのコピーと書き換え | オブジェクトのコピーと書き換えのオペレーションは、送信元バケットと宛先バケットの両方がエンドポイントで指定されたリージョンにある場合、リージョン エンドポイントでサポートされます。ただし、バケットが複数のロケーションに存在する場合は、リージョン エンドポイントを使用してバケット間でオブジェクトをコピーまたはリライトすることはできません。グローバル エンドポイントを使用してロケーション間でコピーまたはリライトすることは可能ですが、ITAR への準拠に違反する可能性があるため、おすすめしません。 |
Cloud VPN
影響を受ける Cloud VPN の機能
| 機能 | 説明 |
|---|---|
| Google Cloud コンソール | Cloud VPN の機能は Google Cloud コンソールで使用できません。代わりに API または Google Cloud CLI を使用してください。 |
| 暗号化 | 証明書の作成と IP セキュリティの構成には、FIPS 140-2 準拠の暗号のみを使用する必要があります。Cloud VPN でサポートされている暗号の詳細については、サポートされている IKE の暗号ページをご覧ください。FIPS 140-2 標準に準拠する暗号を選択する方法については、FIPS 140-2 認証取得済みページをご覧ください。 Google Cloudで既存の暗号を変更することはできません。Cloud VPN で使用するサードパーティ アプライアンスでも暗号が構成されていることを確認します。 |
| VPN エンドポイント | 対象範囲内のリージョンにある Cloud VPN エンドポイントのみを使用する必要があります。VPN ゲートウェイが対象範囲内のリージョンでのみ使用されるように構成されていることを確認します。 |
Compute Engine
影響を受ける Compute Engine の機能
| 機能 | 説明 |
|---|---|
| VM インスタンスの一時停止および再開 | この機能は無効になっています。 VM インスタンスの一時停止と再開には永続ディスク ストレージが必要です。停止状態の VM の状態を保存するために使用される永続ディスク ストレージは、現在、CMEK を使用して暗号化できません。この機能を有効にした場合のデータ主権とデータ所在地の影響については、上記の gcp.restrictNonCmekServices 組織ポリシーの制約をご覧ください。 |
| ローカル SSD | この機能は無効になっています。 ローカル SSD は CMEK を使用して暗号化できないため、ローカル SSD を使用してインスタンスを作成できません。この機能を有効にした場合のデータ主権とデータ所在地の影響については、上記の gcp.restrictNonCmekServices 組織ポリシーの制約をご覧ください。 |
| Google Cloud コンソール | 次の Compute Engine 機能は、 Google Cloud コンソールで使用できません。代わりに API または Google Cloud CLI を使用してください。 |
| VM メタデータのセキュリティに関する考慮事項 | センシティブ データを VM メタデータ サーバーに書き込まないようにすることは、お客様の責任です。 |
| Bare Metal Solution VM | Bare Metal Solution VM(o2 VM)は ITAR に準拠していないため、使用できません。 |
| Google Cloud VMware Engine VM | Google Cloud VMware Engine VM は ITAR に準拠していないため、Google Cloud VMware Engine VM を使用することはできません。 |
| C3 VM インスタンスを作成する | この機能は無効になっています。 |
| CMEK を使用せずに永続ディスクまたはそのスナップショットを使用する | 永続ディスクまたはそのスナップショットは、CMEK を使用して暗号化されていない限り使用できません。 |
| マルチライター モードでの SSD 永続ディスクの共有 | マルチライター モードの SSD 永続ディスクを VM インスタンス間で共有することはできません。 |
| グローバル ロードバランサへのインスタンス グループの追加 | インスタンス グループをグローバル ロードバランサに追加することはできません。 この機能は、 compute.disableGlobalLoadBalancing 組織ポリシー制約によって無効になっています。 |
| ゲスト環境 | ゲスト環境に含まれているスクリプト、デーモン、バイナリが、暗号化されていない保存中および使用中のデータにアクセスすることは可能です。VM の構成によっては、このソフトウェアの更新がデフォルトでインストールされることがあります。各パッケージの内容、ソースコードなどの詳細については、ゲスト環境をご覧ください。 これらのコンポーネントは、内部のセキュリティ管理とプロセスを通じてデータ主権を満たすのに役立ちます。ただし、追加の制御が必要な場合は、独自のイメージやエージェントをキュレートし、必要に応じて compute.trustedImageProjects 組織ポリシーの制約を使用することもできます。詳細については、カスタム イメージのビルドをご覧ください。 |
| VM Manager の OS ポリシー |
OS ポリシー ファイル内のインライン スクリプトとバイナリ出力ファイルは、顧客管理の暗号鍵(CMEK)を使用して暗号化されません。これらのファイルに機密情報を含めないでください。これらのスクリプトと出力ファイルを Cloud Storage バケットに保存することを検討してください。詳細については、OS ポリシーの例をご覧ください。 インライン スクリプトまたはバイナリ出力ファイルを使用する OS ポリシー リソースの作成または変更を制限する場合は、 constraints/osconfig.restrictInlineScriptAndOutputFileUsage 組織のポリシーの制約を有効にします。詳細については、OS Config の制約をご覧ください。 |
instances.getSerialPortOutput()
|
この API は無効になっています。この API を使用して、指定したインスタンスからシリアルポート出力を取得することはできません。 この API を有効にするには、 compute.disableInstanceDataAccessApis 組織のポリシー制約値を False に変更します。プロジェクトのアクセスを有効にするの手順に沿って、インタラクティブ シリアルポートを有効にして使用することもできます。 |
instances.getScreenshot() |
この API は無効になっています。この API を使用して指定したインスタンスからスクリーンショットを取得することはできません。 この API を有効にするには、 compute.disableInstanceDataAccessApis 組織のポリシー制約値を False に変更します。プロジェクトのアクセスを有効にするの手順に沿って、インタラクティブ シリアルポートを有効にして使用することもできます。 |
Compute Engine の組織のポリシーの制約
| 組織のポリシーの制約 | 説明 |
|---|---|
compute.enableComplianceMemoryProtection |
True に設定します。 インフラストラクチャ障害が発生したときにメモリ コンテンツを追加で保護するために、一部の内部診断機能を無効にします。 この値を変更すると、ワークロードのデータ所在地またはデータ主権に影響する可能性があります。 |
compute.disableGlobalCloudArmorPolicy |
True に設定します。 新しいグローバル Google Cloud Armor セキュリティ ポリシーの作成と、既存のグローバル Google Cloud Armor セキュリティ ポリシーへのルールの追加または変更を無効にします。この制約は、ルールの削除や、グローバル Google Cloud Armor セキュリティ ポリシーの説明と一覧取得の削除または変更を制限するものではありません。リージョン Google Cloud Armor セキュリティ ポリシーは、この制約の影響を受けません。この制約の適用前から存在するグローバル セキュリティ ポリシーとリージョン セキュリティ ポリシーは引き続き有効です。 |
compute.disableGlobalLoadBalancing |
True に設定します。 グローバル ロード バランシング プロダクトの作成を無効にします。 この値を変更すると、ワークロードのデータ所在地またはデータ主権に影響する可能性があります。 |
compute.disableGlobalSelfManagedSslCertificate |
True に設定します。 グローバル セルフマネージド SSL 証明書の作成を無効にします。 この値を変更すると、ワークロードのデータ所在地またはデータ主権に影響する可能性があります。 |
compute.disableInstanceDataAccessApis
| True に設定します。instances.getSerialPortOutput() API と instances.getScreenshot() API をグローバルに無効にします。この制約を有効にすると、Windows Server VM で認証情報を生成できなくなります。 Windows VM でユーザー名とパスワードを管理する必要がある場合は、次の操作を行います。
|
compute.requireOsConfig
| True に設定します。 すべての新しいプロジェクトで VM Manager(OS Config)を有効にします。新しいプロジェクトで作成されるすべての VM インスタンスで VM Manager が有効になります。 |
compute.restrictNonConfidentialComputing |
(省略可)値が設定されていません。多層防御を提供するには、この値を設定します。詳細については、Confidential VM のドキュメントをご覧ください。 |
compute.trustedImageProjects |
(省略可)値が設定されていません。多層防御を提供するには、この値を設定します。 この値を設定すると、イメージ ストレージとディスクのインスタンス化が、指定されたプロジェクトのリストに制限されます。この値は、未承認のイメージやエージェントの使用を防ぐことでデータ主権に影響を与えます。 |
Knowledge Catalog
Knowledge Catalog の機能
| 機能 | 説明 |
|---|---|
| Attribute Store | この機能は非推奨となり、無効になっています。 |
| Data Catalog | この機能は非推奨となり、無効になっています。Data Catalog でメタデータを検索したり、管理したりすることはできません。 |
| レイクとゾーン | この機能は無効になっています。レイク、ゾーン、タスクを管理できません。 |
Google Cloud Armor
影響を受ける Google Cloud Armor の機能
| 機能 | 説明 |
|---|---|
| グローバル スコープのセキュリティ ポリシー | この機能は、compute.disableGlobalCloudArmorPolicy 組織のポリシーの制約によって無効になっています。 |
Google Kubernetes Engine
影響を受ける Google Kubernetes Engine の機能
| 機能 | 説明 |
|---|---|
| クラスタ リソースの制限 | クラスタ構成で、ITAR でサポートされていないサービスのリソースが使用されていないことを確認します。たとえば、次の構成は、サポートされていないサービスの有効化または使用が必要なため、無効です。
set `binaryAuthorization.evaluationMode` to `enabled`
|
Google Kubernetes Engine の組織のポリシーの制約
| 組織のポリシーの制約 | 説明 |
|---|---|
container.restrictNoncompliantDiagnosticDataAccess |
True に設定します。 ワークロードの主権管理を維持するために必要な、カーネルの問題の集計分析を無効にします。 この値を変更すると、ワークロードのデータ所在地またはデータ主権に影響する可能性があります。 |
Network Connectivity Center
影響を受ける Network Connectivity Center の機能
| 機能 | 説明 |
|---|---|
| Google Cloud コンソール | Network Connectivity Center の機能は Google Cloud コンソールで使用できません。代わりに API または Google Cloud CLI を使用してください。 |
Pub/Sub
Pub/Sub 組織のポリシーの制約
| 組織のポリシーの制約 | 説明 |
|---|---|
pubsub.enforceInTransitRegions |
True に設定します。 お客様のデータが、Pub/Sub トピックのメッセージ ストレージ ポリシーで指定された、許可されるリージョン内でのみ転送されるようにします。 この値を変更すると、ワークロードのデータ所在地またはデータ主権に影響する可能性があります。 |
pubsub.managed.disableSubscriptionMessageTransforms |
True に設定します。 Pub/Sub サブスクリプションで単一メッセージ変換(SMT)を設定できないようにします。 この値を変更すると、ワークロードのデータ所在地またはデータ主権に影響する可能性があります。 |
pubsub.managed.disableTopicMessageTransforms |
True に設定します。 Pub/Sub トピックで 単一メッセージ変換(SMT)を設定できないようにします。 この値を変更すると、ワークロードのデータ所在地またはデータ主権に影響する可能性があります。 |
Security Command Center Premium
影響を受ける Security Command Center Premium の機能
| 機能 | 説明 |
|---|---|
| コンプライアンス マネージャー | コンプライアンス マネージャー はサポートされておらず、ITAR の制御要件を満たしていません。 |
| データ セキュリティ ポスチャー管理 | データ セキュリティ ポスチャー管理はサポートされておらず、ITAR の制御要件を満たしていません。 |
Spanner
影響を受ける Spanner の機能
| 機能 | 説明 |
|---|---|
| スプリットの境界 | Spanner は、主キーとインデックス付き列の小さなサブセットを使用して、顧客データとメタデータを含むスプリットの境界を定義します。Spanner のスプリットの境界は、連続する範囲の行が小さな部分に分割される場所を示します。 これらのスプリットの境界は、Google の担当者がテクニカル サポートとデバッグ目的でアクセスできますが、Assured Workloads における管理者権限データ管理の対象ではありません。 |
Spanner の組織のポリシーの制約
| 組織のポリシーの制約 | 説明 |
|---|---|
spanner.assuredWorkloadsAdvancedServiceControls |
True に設定します。 Spanner リソースに追加のデータ主権とサポート性の制御を適用します。 |
spanner.disableMultiRegionInstanceIfNoLocationSelected |
True に設定します。 マルチリージョン Spanner インスタンスの作成機能を無効にして、データ所在地とデータ主権を適用します。 |
Vertex AI
Vertex AI の組織のポリシーの制約
| 組織のポリシーの制約 | 説明 |
|---|---|
vertexai.allowOnlyITARCompliantAPIs |
True に設定します。 Vertex AI API で ITAR 準拠の API のみを使用できるようにします。デフォルトでは、すべての API が許可されます。 |
Virtual Private Cloud(VPC)
影響を受ける VPC 機能
| 機能 | 説明 |
|---|---|
| Google Cloud コンソール | VPC ネットワーキング機能は Google Cloud コンソールで使用できません。代わりに API または Google Cloud CLI を使用してください。 |
次のステップ
- Assured Workloads フォルダを作成する方法を学習する。
- Assured Workloads の料金について