This document provides an overview of various controls that support the security of Knowledge Catalog on Google Cloud and links to further information on how to configure the controls. Security controls such as network security options, policies, and access management can help you address your business risks and meet the privacy and regulatory requirements that apply to your business.
The security, privacy, risk, and compliance for Knowledge Catalog use a shared responsibility model. For example, because Knowledge Catalog is a fully-managed service, Google secures and manages the infrastructure that Knowledge Catalog and other Google Cloud services run on, and provides you with the capabilities that help you manage access to your services and resources. For more information about how we secure the infrastructure, see the Google infrastructure security design overview.
Provisioned services
Knowledge Catalog uses the following APIs:
To get started, see Enable Knowledge Catalog.
Authentication for Google Cloud management
Administrators and developers who create and manage Knowledge Catalog instances must authenticate to Google Cloud to verify their identity and access privileges. You must set up each user with a user account that is managed by Cloud Identity, Google Workspace, or an identity provider that you've federated with Cloud Identity or Google Workspace. For more information, see Overview of Google identity management.
After you create the user accounts, implement security best practices such as single sign-on and 2-step verification.
Authentication for Google Cloud resource access
Workforce Identity Federation lets you use your external identity provider (IdP) to authenticate your workforce users so that they can access Google Cloud resources. Use Workforce Identity Federation when users require programmatic access to your Google Cloud resources and you store your users' credentials in IdPs that support OpenID Connect (OIDC) or Security Assertion Markup Language (SAML).
Workload Identity Federation lets you use your external IdP to grant your on-premises or multi-cloud workloads access to Google Cloud resources, without using a service account key. You can use identity federation with IdPs such as Amazon Web Services (AWS), Microsoft Entra ID, GitHub, or Okta.
For more information about Knowledge Catalog support for identity federation, see Federated identity supported services.
For more information about authentication in Google Cloud, see Authentication.
Identity and Access Management
To manage Identity and Access Management (IAM) roles at scale for your administrators and developers, consider creating separate functional groups for your various user roles and applications. Grant the IAM roles or permissions that are required to manage Knowledge Catalog to your groups. When you assign roles to your groups, follow the principle of least privilege and other IAM security best practices. For more information, see Best practices for using Google Groups.
For more information about using IAM with Knowledge Catalog, see Manage access with IAM. For more information about setting up IAM, see IAM overview.
You can grant predefined and custom roles for Knowledge Catalog resources such as entry groups and entries.
Knowledge Catalog service accounts
When you enable Knowledge Catalog, Google creates service accounts for you. A service account is a special type of non-interactive Google Account that's typically used by an application or compute workload, such as a Compute Engine instance, rather than a person. Applications use service accounts to access Google APIs.
Service agents
To enable Knowledge Catalog to access your resources on your behalf, Google Cloud creates a special service account known as a service agent.
When you enable Knowledge Catalog, the following Knowledge Catalog service agents are created:
service-PROJECT_NUMBER@gcp-sa-dataplex.iam.gserviceaccount.comservice-org-ORGANIZATION_NUMBER@gcp-sa-dataplex.iam.gserviceaccount.comservice-org-ORGANIZATION_NUMBER@gcp-sa-dataplex-cmek.iam.gserviceaccount.comservice-PROJECT_NUMBER@gcp-sa-datalineage.iam.gserviceaccount.com
For more information about Knowledge Catalog service agents, see Enable customer-managed encryption keys.
Policies for Knowledge Catalog
The predefined organization policies that apply to Knowledge Catalog include the following:
- Resource Location Restriction (
constraints/gcp.resourceLocations) - Restrict which projects may supply KMS CryptoKeys for CMEK (
constraints/gcp.restrictCmekCryptoKeyProjects) - Restrict which services may create resources without CMEK (
constraints/gcp.restrictNonCmekServices) - Restrict endpoint usage (
constraints/gcp.restrictEndpointUsage) - Restrict Resource Service Usage (
constraints/gcp.restrictServiceUsage) - Restrict TLS Cipher Suites (
constraints/gcp.restrictTLSCipherSuites)
You can use custom organization policies to configure restrictions on Knowledge Catalog at a project, folder, or organization level. For more information, see Creating and managing custom constraints.
For more information about organization policies, see Manage Knowledge Catalog resources using custom constraints.
Network security
By default, Google applies default protections to data in transit for all Google Cloud services, including Knowledge Catalog instances that are running on Google Cloud. For more information about default network protections, see Encryption in transit.
If required by your organization, you can configure additional security controls to further protect traffic on the Google Cloud network and traffic between the Google Cloud network and your corporate network. Consider the following:
- Knowledge Catalog supports VPC Service Controls. VPC Service Controls let you control the movement of data in Google services and set up context-based perimeter security.
- In Google Cloud, consider using Shared VPC as your network topology. Shared VPC provides centralized network configuration management while maintaining separation of environments.
For more information about network security best practices, see Implement zero trust and Decide the network design for your Google Cloud landing zone.
Data protection and privacy
Knowledge Catalog encrypts your data that is stored in Google Cloud using default encryption. Example data includes the following:
- Entry group and entry names
- Tag and aspect definitions
- Metadata attributes, descriptions, and tags
- Business glossary terms and relationships
This data can only be accessed by Knowledge Catalog instances.
You can enable customer-managed encryption keys (CMEK) to encrypt your data at rest. With CMEK, keys are stored in Cloud Key Management Service (Cloud KMS) as software-protected keys or hardware-protected keys with Cloud HSM, but they are managed by you. To provision encryption keys automatically, you can enable Cloud KMS Autokey. When you enable Autokey, a developer can request a key from Cloud KMS, and the service agent provisions a key that matches the developer's intent. With Cloud KMS Autokey, keys are available on demand, are consistent, and follow industry-standard practices.
In addition, Knowledge Catalog supports Cloud External Key Manager (Cloud EKM), which lets you store your keys in an external key manager outside of Google Cloud. For more information, see Enable customer-managed encryption keys.
Where data is processed
Knowledge Catalog supports data residency for data that is stored on Google Cloud. Data residency lets you choose the regions that you want your data to be stored in using the Resource Location Restriction policy constraint. You can use Cloud Asset Inventory to verify the location of Knowledge Catalog resources.
If you require data residency for data in use, you can configure Assured Workloads. For more information, see Assured Workloads and data residency.
Data privacy
To help protect the privacy of your data, Knowledge Catalog conforms to the Common Privacy Principles.
Knowledge Catalog acts as a data processor for Customer Data. Google also acts as a data controller for information such as billing and account management and abuse detections. For more information, see Google Cloud Privacy Notice.
Audit logging
Knowledge Catalog writes the following types of audit logs:
Admin Activity audit logs: Includes
ADMIN WRITEoperations that write metadata or configuration information.Data Access audit logs: Includes
ADMIN READoperations that read metadata or configuration information. Also includesDATA READandDATA WRITEoperations that read or write user-provided data.
For more information, see Audit logging.
Access transparency
You can use Access Approval and Access Transparency to control access to Knowledge Catalog instances by Google personnel who support the service. Access Approval lets you approve or dismiss requests for access by Google employees. Access Transparency logs offer near real-time insight when Google Cloud administrators access the resources.
Monitoring and incident response
You can use a variety of tools to help you monitor the performance and security of Knowledge Catalog. Consider the following:
- Logs Explorer to view and analyze event logs and create custom metrics and alerts.
- Use the Cloud Monitoring dashboard to monitor the performance of Knowledge Catalog. For more information, see Monitor Knowledge Catalog.
- Deploy cloud controls and frameworks in Security Command Center to detect vulnerabilities and threats to Knowledge Catalog (such as privilege escalations). You can set up alerts and playbooks for your security operations center (SOC) analysts so that they can respond to findings.
Certifications and compliance
Meeting your regulatory requirements is a shared responsibility between you and Google.
Knowledge Catalog has received a variety of certifications, including the following:
- ISO 27001
- SOC 2
- FedRAMP
- DoD IL5
- ITAR
For more information about Google Cloud compliance with different regulatory frameworks and certifications, see the compliance resource center.
Knowledge Catalog also supports Assured Workloads (subject to the limitations of each control package), which lets you apply controls to specific folders in your Google organization that support regulatory, regional, or sovereign requirements. For more information, see Supported products by control package.
What's next
- Use Terraform to deploy Knowledge Catalog.
- Use Google Threat Intelligence to track external threats that apply to your business.
- Learn how to manage access in Knowledge Catalog.
- Learn how to configure customer-managed encryption keys in Knowledge Catalog.