Data Boundary בהתאם לתקנות International Traffic in Arms Regulations ‏ (ITAR)

בדף הזה מתואר קבוצת אמצעי הבקרה שמוחלים על עומסי עבודה של ITAR ב-Assured Workloads. הוא כולל מידע מפורט על מיקום אחסון הנתונים, על מוצרים נתמכים Google Cloud ונקודות קצה ל-API שלהם, ועל הגבלות או מגבלות שחלות על המוצרים האלה. המידע הנוסף הבא רלוונטי ל-ITAR:

  • מיקום אחסון הנתונים: חבילת אמצעי הבקרה של ITAR מגדירה אמצעי בקרה למיקום הנתונים כדי לתמוך באזורים בארה"ב בלבד. מידע נוסף זמין בקטע Google Cloud-wide organization policy constraints.
  • תמיכה: שירותי תמיכה טכנית לעומסי עבודה של ITAR זמינים עם מינויים ל-Cloud Customer Care ברמות Enhanced או Premium. בקשות תמיכה בנושא עומסי עבודה של ITAR מועברות לאנשים או ישויות שנמצאים בארה"ב. מידע נוסף זמין במאמר בנושא קבלת תמיכה.
  • תמחור: חבילת הבקרה ITAR כלולה ברמת הפרימיום של Assured Workloads, שכוללת חיוב נוסף של 20%. מידע נוסף זמין במאמר בנושא תמחור של Assured Workloads.

דרישות מוקדמות

כדי להמשיך לעמוד בדרישות כמשתמש בחבילת אמצעי הבקרה של ITAR, צריך לוודא שאתם עומדים בדרישות המוקדמות הבאות:

  • יוצרים תיקיית ITAR באמצעות Assured Workloads ומפריסים את עומסי העבודה של ITAR רק בתיקייה הזו.
  • אפשר להפעיל ולהשתמש רק בשירותי ITAR שכלולים בהיקף עבור עומסי עבודה של ITAR.
  • אלא אם צוין אחרת, אל תשתמשו בשרתי Google Cloud MCP. תקנות ITAR לא מספקות אמצעי בקרה על מיקום אחסון הנתונים בשרתי MCP של Google Cloud, כשמדובר בנתונים בשימוש ובנתונים במעבר. כדי לחסום גישה לא רצויה לשרתי Google Cloud MCP, אפשר לעיין בדף שליטה בשימוש בשרתי Google Cloud MCP באמצעות IAM.
  • אל תשנו את ערכי ברירת המחדל של האילוצים במדיניות הארגון, אלא אם אתם מבינים את הסיכונים שעלולים להתרחש בנוגע למיקום אחסון הנתונים ומקבלים אותם.
  • כשניגשים למסוף Google Cloud בשביל עומסי עבודה של ITAR, צריך להשתמש באחת מכתובות ה-URL הבאות של מסוף Google Cloud בתחום שיפוט:
  • כשמתחברים ל Google Cloud נקודות קצה של שירותים, צריך להשתמש בנקודות קצה אזוריות לשירותים שמציעים אותן. בנוסף:
    • כשמתחברים לנקודות קצה של שירותים Google Cloud ממכונות וירטואליות שאינןGoogle Cloud, כמו מכונות וירטואליות מקומיות או של ספקי ענן אחרים, צריך להשתמש באחת מאפשרויות הגישה הפרטית שזמינות ותומכות בחיבורים למכונות וירטואליות שאינןGoogle Cloud , כדי לנתב את התעבורה שאינהGoogle Cloud אל Google Cloud.
    • כשמתחברים ל Google Cloud נקודות קצה של שירותים מ Google Cloud מכונות וירטואליות, אפשר להשתמש בכל אחת מאפשרויות הגישה הפרטית שזמינות.
    • כשמתחברים למכונות וירטואליות Google Cloud שנחשפו עם כתובות IP חיצוניות, כדאי לעיין במאמר גישה לממשקי API ממכונות וירטואליות עם כתובות IP חיצוניות.
  • בכל השירותים שבהם נעשה שימוש בתיקיית ITAR, אסור לאחסן נתונים טכניים בסוגי המידע הבאים של הגדרות אבטחה או הגדרות שהוגדרו על ידי המשתמש:
    • הודעות שגיאה
    • פלט המסוף
    • נתוני מאפיינים
    • נתוני הגדרת שירות
    • כותרות של חבילות נתונים ברשת
    • מזהי משאבים
    • תוויות נתונים
  • צריך להשתמש רק בנקודות הקצה האזוריות שצוינו לשירותים שמציעים אותן. מידע נוסף זמין במאמר בנושא שירותים שכלולים בהיקף של ITAR.
  • כדאי ליישם את השיטות המומלצות הכלליות לאבטחה שמפורטות Google Cloud במרכז לשיטות אבטחה מומלצות.

מוצרים נתמכים ונקודות קצה של API

אלא אם צוין אחרת, המשתמשים יכולים לגשת לכל המוצרים הנתמכים דרך המסוף Google Cloud . בטבלה הבאה מפורטות הגבלות שמשפיעות על התכונות של מוצר נתמך, כולל הגבלות שנאכפות באמצעות הגדרות של אילוצי מדיניות הארגון.

אם מוצר לא מופיע ברשימה, סימן שהמוצר לא נתמך ולא עומד בדרישות הבקרה של ITAR. לא מומלץ להשתמש במוצרים לא נתמכים בלי לבצע בדיקת נאותות ולהבין היטב את האחריות שלכם במסגרת מודל האחריות המשותפת. לפני שמשתמשים במוצר שלא נתמך, חשוב לוודא שאתם מודעים לסיכונים הכרוכים בכך ומוכנים לקבל אותם, כמו השפעות שליליות על מיקום הנתונים או על ריבונות הנתונים.

שירותים שמתקשרים עם נתוני לקוחות בפעולות ה-API שלהם מספקים נקודות קצה אזוריות של API. כדי לשמור על תאימות ל-ITAR, צריך להשתמש בנקודות הקצה האלה במקום בנקודת הקצה הגלובלית ל-API של השירות. לשירותים שפעולות ה-API שלהם לא מיועדות לאינטראקציה עם נתוני לקוחות, יש נקודות קצה גלובליות של API. באחריותכם לוודא שלא תעבירו נתונים טכניים שמוסדרים על ידי ITAR דרך נקודות הקצה הגלובליות האלה של ה-API. מידע נוסף על נתוני לקוחות ונתוני שירות זמין במאמר מיקום אחסון הנתונים.

מוצרים נתמכים עם נקודות קצה אזוריות של API

בטבלה הבאה מפורטת רשימה של מוצרים נתמכים ונקודות הקצה האזוריות שלהם ל-API. נקודות הקצה (endpoints) של ה-API האלה נועדו לעבד ולשדר נתוני לקוחות. כדי לעמוד בדרישות התאימות ל-ITAR כשמשתמשים במוצרים האלה, צריך להשתמש בנקודת קצה אזורית זמינה של API במקום בנקודת קצה גלובלית של API.

מוצר נתמך נקודות קצה אזוריות של API הגבלות
‫AlloyDB ל-PostgreSQL
    alloydb.us-central1.rep.googleapis.com
    alloydb.us-central2.rep.googleapis.com
    alloydb.us-east1.rep.googleapis.com
    alloydb.us-east4.rep.googleapis.com
    alloydb.us-east5.rep.googleapis.com
    alloydb.us-east7.rep.googleapis.com
    alloydb.us-south1.rep.googleapis.com
    alloydb.us-west1.rep.googleapis.com
    alloydb.us-west2.rep.googleapis.com
    alloydb.us-west3.rep.googleapis.com
    alloydb.us-west4.rep.googleapis.com

ללא
Apigee
    apigee.us.rep.googleapis.com

ללא
Artifact Analysis
    containeranalysis.us.rep.googleapis.com
    containeranalysis.us-central1.rep.googleapis.com
    containeranalysis.us-central2.rep.googleapis.com
    containeranalysis.us-east1.rep.googleapis.com
    containeranalysis.us-east4.rep.googleapis.com
    containeranalysis.us-east5.rep.googleapis.com
    containeranalysis.us-east7.rep.googleapis.com
    containeranalysis.us-south1.rep.googleapis.com
    containeranalysis.us-west1.rep.googleapis.com
    containeranalysis.us-west2.rep.googleapis.com
    containeranalysis.us-west3.rep.googleapis.com
    containeranalysis.us-west4.rep.googleapis.com

ללא
Artifact Registry
    artifactregistry.us.rep.googleapis.com
    artifactregistry.us-central1.rep.googleapis.com
    artifactregistry.us-central2.rep.googleapis.com
    artifactregistry.us-east1.rep.googleapis.com
    artifactregistry.us-east4.rep.googleapis.com
    artifactregistry.us-east5.rep.googleapis.com
    artifactregistry.us-east7.rep.googleapis.com
    artifactregistry.us-south1.rep.googleapis.com
    artifactregistry.us-west1.rep.googleapis.com
    artifactregistry.us-west2.rep.googleapis.com
    artifactregistry.us-west3.rep.googleapis.com
    artifactregistry.us-west4.rep.googleapis.com
    artifactregistry.us-west8.rep.googleapis.com

ללא
שירות Backup and DR
    backupdr.us.rep.googleapis.com
    backupdr.us-central1.rep.googleapis.com
    backupdr.us-central2.rep.googleapis.com
    backupdr.us-east1.rep.googleapis.com
    backupdr.us-east4.rep.googleapis.com
    backupdr.us-east5.rep.googleapis.com
    backupdr.us-east7.rep.googleapis.com
    backupdr.us-south1.rep.googleapis.com
    backupdr.us-west1.rep.googleapis.com
    backupdr.us-west2.rep.googleapis.com
    backupdr.us-west3.rep.googleapis.com
    backupdr.us-west4.rep.googleapis.com
    backupdr.us-west8.rep.googleapis.com

ללא
גיבוי ל-Google Kubernetes Engine‏ (GKE)
    gkebackup.us-central1.rep.googleapis.com
    gkebackup.us-east1.rep.googleapis.com
    gkebackup.us-east4.rep.googleapis.com
    gkebackup.us-east5.rep.googleapis.com
    gkebackup.us-east7.rep.googleapis.com
    gkebackup.us-south1.rep.googleapis.com
    gkebackup.us-west1.rep.googleapis.com
    gkebackup.us-west2.rep.googleapis.com
    gkebackup.us-west3.rep.googleapis.com
    gkebackup.us-west4.rep.googleapis.com
    gkebackup.us-west8.rep.googleapis.com

ללא
BigQuery
    bigquery.us-central1.rep.googleapis.com
    bigquery.us-central2.rep.googleapis.com
    bigquery.us-east1.rep.googleapis.com
    bigquery.us-east4.rep.googleapis.com
    bigquery.us-east5.rep.googleapis.com
    bigquery.us-east7.rep.googleapis.com
    bigquery.us-south1.rep.googleapis.com
    bigquery.us-west1.rep.googleapis.com
    bigquery.us-west2.rep.googleapis.com
    bigquery.us-west3.rep.googleapis.com
    bigquery.us-west4.rep.googleapis.com
    bigquery.us-west8.rep.googleapis.com
    bigquerymigration.us-central1.rep.googleapis.com
    bigquerymigration.us-central2.rep.googleapis.com
    bigquerymigration.us-east1.rep.googleapis.com
    bigquerymigration.us-east4.rep.googleapis.com
    bigquerymigration.us-east5.rep.googleapis.com
    bigquerymigration.us-east7.rep.googleapis.com
    bigquerymigration.us-south1.rep.googleapis.com
    bigquerymigration.us-west1.rep.googleapis.com
    bigquerymigration.us-west2.rep.googleapis.com
    bigquerymigration.us-west3.rep.googleapis.com
    bigquerymigration.us-west4.rep.googleapis.com
    bigquerymigration.us-west8.rep.googleapis.com
    bigqueryreservation.us-central1.rep.googleapis.com
    bigqueryreservation.us-central2.rep.googleapis.com
    bigqueryreservation.us-east1.rep.googleapis.com
    bigqueryreservation.us-east4.rep.googleapis.com
    bigqueryreservation.us-east5.rep.googleapis.com
    bigqueryreservation.us-east7.rep.googleapis.com
    bigqueryreservation.us-south1.rep.googleapis.com
    bigqueryreservation.us-west1.rep.googleapis.com
    bigqueryreservation.us-west2.rep.googleapis.com
    bigqueryreservation.us-west3.rep.googleapis.com
    bigqueryreservation.us-west4.rep.googleapis.com
    bigqueryreservation.us-west8.rep.googleapis.com
    bigquerystorage.us-central1.rep.googleapis.com
    bigquerystorage.us-central2.rep.googleapis.com
    bigquerystorage.us-east1.rep.googleapis.com
    bigquerystorage.us-east4.rep.googleapis.com
    bigquerystorage.us-east5.rep.googleapis.com
    bigquerystorage.us-east7.rep.googleapis.com
    bigquerystorage.us-south1.rep.googleapis.com
    bigquerystorage.us-west1.rep.googleapis.com
    bigquerystorage.us-west2.rep.googleapis.com
    bigquerystorage.us-west3.rep.googleapis.com
    bigquerystorage.us-west4.rep.googleapis.com
    bigquerystorage.us-west8.rep.googleapis.com

תכונות מושפעות
שירות העברת נתונים ל-BigQuery
    bigquerydatatransfer.us-central1.rep.googleapis.com
    bigquerydatatransfer.us-central2.rep.googleapis.com
    bigquerydatatransfer.us-east1.rep.googleapis.com
    bigquerydatatransfer.us-east4.rep.googleapis.com
    bigquerydatatransfer.us-east5.rep.googleapis.com
    bigquerydatatransfer.us-east7.rep.googleapis.com
    bigquerydatatransfer.us-south1.rep.googleapis.com
    bigquerydatatransfer.us-west1.rep.googleapis.com
    bigquerydatatransfer.us-west2.rep.googleapis.com
    bigquerydatatransfer.us-west3.rep.googleapis.com
    bigquerydatatransfer.us-west4.rep.googleapis.com
    bigquerydatatransfer.us-west8.rep.googleapis.com

ללא
Bigtable
    bigtable.us-central1.rep.googleapis.com
    bigtable.us-central2.rep.googleapis.com
    bigtable.us-east1.rep.googleapis.com
    bigtable.us-east4.rep.googleapis.com
    bigtable.us-east5.rep.googleapis.com
    bigtable.us-east7.rep.googleapis.com
    bigtable.us-south1.rep.googleapis.com
    bigtable.us-west1.rep.googleapis.com
    bigtable.us-west2.rep.googleapis.com
    bigtable.us-west3.rep.googleapis.com
    bigtable.us-west4.rep.googleapis.com
    bigtable.us-west8.rep.googleapis.com

ללא
Cloud Build
    cloudbuild.us-central1.rep.googleapis.com
    cloudbuild.us-central2.rep.googleapis.com
    cloudbuild.us-east1.rep.googleapis.com
    cloudbuild.us-east4.rep.googleapis.com
    cloudbuild.us-east5.rep.googleapis.com
    cloudbuild.us-east7.rep.googleapis.com
    cloudbuild.us-south1.rep.googleapis.com
    cloudbuild.us-west1.rep.googleapis.com
    cloudbuild.us-west2.rep.googleapis.com
    cloudbuild.us-west3.rep.googleapis.com
    cloudbuild.us-west4.rep.googleapis.com
    cloudbuild.us-west8.rep.googleapis.com

ללא
Cloud Deploy
    clouddeploy.us-central1.rep.googleapis.com
    clouddeploy.us-east1.rep.googleapis.com
    clouddeploy.us-east4.rep.googleapis.com
    clouddeploy.us-east5.rep.googleapis.com
    clouddeploy.us-east7.rep.googleapis.com
    clouddeploy.us-south1.rep.googleapis.com
    clouddeploy.us-west1.rep.googleapis.com
    clouddeploy.us-west2.rep.googleapis.com
    clouddeploy.us-west3.rep.googleapis.com
    clouddeploy.us-west4.rep.googleapis.com

ללא
‫Cloud External Key Manager ‏ (Cloud EKM)
    cloudkms.us.rep.googleapis.com
    cloudkms.us-central1.rep.googleapis.com
    cloudkms.us-central2.rep.googleapis.com
    cloudkms.us-east1.rep.googleapis.com
    cloudkms.us-east4.rep.googleapis.com
    cloudkms.us-east5.rep.googleapis.com
    cloudkms.us-east7.rep.googleapis.com
    cloudkms.us-south1.rep.googleapis.com
    cloudkms.us-west1.rep.googleapis.com
    cloudkms.us-west2.rep.googleapis.com
    cloudkms.us-west3.rep.googleapis.com
    cloudkms.us-west4.rep.googleapis.com
    cloudkms.us-west8.rep.googleapis.com

ללא
Cloud HSM
    cloudkms.us.rep.googleapis.com
    cloudkms.us-central1.rep.googleapis.com
    cloudkms.us-central2.rep.googleapis.com
    cloudkms.us-east1.rep.googleapis.com
    cloudkms.us-east4.rep.googleapis.com
    cloudkms.us-east5.rep.googleapis.com
    cloudkms.us-east7.rep.googleapis.com
    cloudkms.us-south1.rep.googleapis.com
    cloudkms.us-west1.rep.googleapis.com
    cloudkms.us-west2.rep.googleapis.com
    cloudkms.us-west3.rep.googleapis.com
    cloudkms.us-west4.rep.googleapis.com
    cloudkms.us-west8.rep.googleapis.com

ללא
Cloud Interconnect
    compute.us-central1.rep.googleapis.com
    compute.us-central2.rep.googleapis.com
    compute.us-east1.rep.googleapis.com
    compute.us-east4.rep.googleapis.com
    compute.us-east5.rep.googleapis.com
    compute.us-east7.rep.googleapis.com
    compute.us-south1.rep.googleapis.com
    compute.us-west1.rep.googleapis.com
    compute.us-west2.rep.googleapis.com
    compute.us-west3.rep.googleapis.com
    compute.us-west4.rep.googleapis.com
    compute.us-west8.rep.googleapis.com

תכונות מושפעות
Cloud Key Management Service ‏(Cloud KMS)
    cloudkms.us.rep.googleapis.com
    cloudkms.us-central1.rep.googleapis.com
    cloudkms.us-central2.rep.googleapis.com
    cloudkms.us-east1.rep.googleapis.com
    cloudkms.us-east4.rep.googleapis.com
    cloudkms.us-east5.rep.googleapis.com
    cloudkms.us-east7.rep.googleapis.com
    cloudkms.us-south1.rep.googleapis.com
    cloudkms.us-west1.rep.googleapis.com
    cloudkms.us-west2.rep.googleapis.com
    cloudkms.us-west3.rep.googleapis.com
    cloudkms.us-west4.rep.googleapis.com
    cloudkms.us-west8.rep.googleapis.com

ללא
Cloud Load Balancing
    compute.us-central1.rep.googleapis.com
    compute.us-central2.rep.googleapis.com
    compute.us-east1.rep.googleapis.com
    compute.us-east4.rep.googleapis.com
    compute.us-east5.rep.googleapis.com
    compute.us-east7.rep.googleapis.com
    compute.us-south1.rep.googleapis.com
    compute.us-west1.rep.googleapis.com
    compute.us-west2.rep.googleapis.com
    compute.us-west3.rep.googleapis.com
    compute.us-west4.rep.googleapis.com
    compute.us-west8.rep.googleapis.com

תכונות מושפעות
Cloud Logging
    logging.us.rep.googleapis.com
    logging.us-central1.rep.googleapis.com
    logging.us-central2.rep.googleapis.com
    logging.us-east1.rep.googleapis.com
    logging.us-east4.rep.googleapis.com
    logging.us-east5.rep.googleapis.com
    logging.us-east7.rep.googleapis.com
    logging.us-south1.rep.googleapis.com
    logging.us-west1.rep.googleapis.com
    logging.us-west2.rep.googleapis.com
    logging.us-west3.rep.googleapis.com
    logging.us-west4.rep.googleapis.com
    logging.us-west8.rep.googleapis.com

תכונות מושפעות
Cloud NAT
    compute.us-central1.rep.googleapis.com
    compute.us-central2.rep.googleapis.com
    compute.us-east1.rep.googleapis.com
    compute.us-east4.rep.googleapis.com
    compute.us-east5.rep.googleapis.com
    compute.us-east7.rep.googleapis.com
    compute.us-south1.rep.googleapis.com
    compute.us-west1.rep.googleapis.com
    compute.us-west2.rep.googleapis.com
    compute.us-west3.rep.googleapis.com
    compute.us-west4.rep.googleapis.com
    compute.us-west8.rep.googleapis.com

תכונות מושפעות
Cloud Router
    compute.us-central1.rep.googleapis.com
    compute.us-central2.rep.googleapis.com
    compute.us-east1.rep.googleapis.com
    compute.us-east4.rep.googleapis.com
    compute.us-east5.rep.googleapis.com
    compute.us-east7.rep.googleapis.com
    compute.us-south1.rep.googleapis.com
    compute.us-west1.rep.googleapis.com
    compute.us-west2.rep.googleapis.com
    compute.us-west3.rep.googleapis.com
    compute.us-west4.rep.googleapis.com
    compute.us-west8.rep.googleapis.com

תכונות מושפעות
Cloud Run
    run.us-central1.rep.googleapis.com
    run.us-central2.rep.googleapis.com
    run.us-east1.rep.googleapis.com
    run.us-east4.rep.googleapis.com
    run.us-east5.rep.googleapis.com
    run.us-east7.rep.googleapis.com
    run.us-south1.rep.googleapis.com
    run.us-west1.rep.googleapis.com
    run.us-west2.rep.googleapis.com
    run.us-west3.rep.googleapis.com
    run.us-west4.rep.googleapis.com
    run.us-west8.rep.googleapis.com

תכונות מושפעות
Cloud SQL
    sqladmin.us-central1.rep.googleapis.com
    sqladmin.us-central2.rep.googleapis.com
    sqladmin.us-east1.rep.googleapis.com
    sqladmin.us-east4.rep.googleapis.com
    sqladmin.us-east5.rep.googleapis.com
    sqladmin.us-east7.rep.googleapis.com
    sqladmin.us-south1.rep.googleapis.com
    sqladmin.us-west1.rep.googleapis.com
    sqladmin.us-west2.rep.googleapis.com
    sqladmin.us-west3.rep.googleapis.com
    sqladmin.us-west4.rep.googleapis.com
    sqladmin.us-west8.rep.googleapis.com

תכונות מושפעות
Cloud Service Mesh
    trafficdirector.us-central1.rep.googleapis.com
    trafficdirector.us-central2.rep.googleapis.com
    trafficdirector.us-east1.rep.googleapis.com
    trafficdirector.us-east4.rep.googleapis.com
    trafficdirector.us-east5.rep.googleapis.com
    trafficdirector.us-east7.rep.googleapis.com
    trafficdirector.us-south1.rep.googleapis.com
    trafficdirector.us-west1.rep.googleapis.com
    trafficdirector.us-west2.rep.googleapis.com
    trafficdirector.us-west3.rep.googleapis.com
    trafficdirector.us-west4.rep.googleapis.com
    trafficdirector.us-west8.rep.googleapis.com

ללא
Spanner
    spanner.us.rep.googleapis.com
    spanner.us-central1.rep.googleapis.com
    spanner.us-central2.rep.googleapis.com
    spanner.us-east1.rep.googleapis.com
    spanner.us-east4.rep.googleapis.com
    spanner.us-east5.rep.googleapis.com
    spanner.us-east7.rep.googleapis.com
    spanner.us-south1.rep.googleapis.com
    spanner.us-west1.rep.googleapis.com
    spanner.us-west2.rep.googleapis.com
    spanner.us-west3.rep.googleapis.com
    spanner.us-west4.rep.googleapis.com
    spanner.us-west8.rep.googleapis.com

התכונות שיושפעו ומגבלות שקשורות למדיניות הארגון
Cloud Storage
    storage.us.rep.googleapis.com
    storage.us-central1.rep.googleapis.com
    storage.us-central2.rep.googleapis.com
    storage.us-east1.rep.googleapis.com
    storage.us-east4.rep.googleapis.com
    storage.us-east5.rep.googleapis.com
    storage.us-east7.rep.googleapis.com
    storage.us-south1.rep.googleapis.com
    storage.us-west1.rep.googleapis.com
    storage.us-west2.rep.googleapis.com
    storage.us-west3.rep.googleapis.com
    storage.us-west4.rep.googleapis.com
    storage.us-west8.rep.googleapis.com

תכונות מושפעות
‫Cloud VPN
    compute.us-central1.rep.googleapis.com
    compute.us-central2.rep.googleapis.com
    compute.us-east1.rep.googleapis.com
    compute.us-east4.rep.googleapis.com
    compute.us-east5.rep.googleapis.com
    compute.us-east7.rep.googleapis.com
    compute.us-south1.rep.googleapis.com
    compute.us-west1.rep.googleapis.com
    compute.us-west2.rep.googleapis.com
    compute.us-west3.rep.googleapis.com
    compute.us-west4.rep.googleapis.com
    compute.us-west8.rep.googleapis.com

תכונות מושפעות
Compute Engine
    compute.us-central1.rep.googleapis.com
    compute.us-central2.rep.googleapis.com
    compute.us-east1.rep.googleapis.com
    compute.us-east4.rep.googleapis.com
    compute.us-east5.rep.googleapis.com
    compute.us-east7.rep.googleapis.com
    compute.us-south1.rep.googleapis.com
    compute.us-west1.rep.googleapis.com
    compute.us-west2.rep.googleapis.com
    compute.us-west3.rep.googleapis.com
    compute.us-west4.rep.googleapis.com
    compute.us-west8.rep.googleapis.com

התכונות שיושפעו ומגבלות שקשורות למדיניות הארגון
Dataflow
    dataflow.us-central1.rep.googleapis.com
    dataflow.us-central2.rep.googleapis.com
    dataflow.us-east1.rep.googleapis.com
    dataflow.us-east4.rep.googleapis.com
    dataflow.us-east5.rep.googleapis.com
    dataflow.us-east7.rep.googleapis.com
    dataflow.us-south1.rep.googleapis.com
    dataflow.us-west1.rep.googleapis.com
    dataflow.us-west2.rep.googleapis.com
    dataflow.us-west3.rep.googleapis.com
    dataflow.us-west4.rep.googleapis.com
    dataflow.us-west8.rep.googleapis.com

ללא
Eventarc
    eventarc.us.rep.googleapis.com
    eventarc.us-central1.rep.googleapis.com
    eventarc.us-central2.rep.googleapis.com
    eventarc.us-east1.rep.googleapis.com
    eventarc.us-east4.rep.googleapis.com
    eventarc.us-east5.rep.googleapis.com
    eventarc.us-east7.rep.googleapis.com
    eventarc.us-south1.rep.googleapis.com
    eventarc.us-west1.rep.googleapis.com
    eventarc.us-west2.rep.googleapis.com
    eventarc.us-west3.rep.googleapis.com
    eventarc.us-west4.rep.googleapis.com
    eventarc.us-west8.rep.googleapis.com

ללא
מאזן עומסי רשת חיצוני להעברת סיגנל ללא שינוי
    compute.us-central1.rep.googleapis.com
    compute.us-central2.rep.googleapis.com
    compute.us-east1.rep.googleapis.com
    compute.us-east4.rep.googleapis.com
    compute.us-east5.rep.googleapis.com
    compute.us-east7.rep.googleapis.com
    compute.us-south1.rep.googleapis.com
    compute.us-west1.rep.googleapis.com
    compute.us-west2.rep.googleapis.com
    compute.us-west3.rep.googleapis.com
    compute.us-west4.rep.googleapis.com
    compute.us-west8.rep.googleapis.com

ללא
Filestore
    file.us-central1.rep.googleapis.com
    file.us-central2.rep.googleapis.com
    file.us-east1.rep.googleapis.com
    file.us-east4.rep.googleapis.com
    file.us-east5.rep.googleapis.com
    file.us-east7.rep.googleapis.com
    file.us-south1.rep.googleapis.com
    file.us-west1.rep.googleapis.com
    file.us-west2.rep.googleapis.com
    file.us-west3.rep.googleapis.com
    file.us-west4.rep.googleapis.com
    file.us-west8.rep.googleapis.com

ללא
Firestore
    firestore.us.rep.googleapis.com
    firestore.us-central1.rep.googleapis.com
    firestore.us-east1.rep.googleapis.com
    firestore.us-east4.rep.googleapis.com
    firestore.us-east5.rep.googleapis.com
    firestore.us-east7.rep.googleapis.com
    firestore.us-south1.rep.googleapis.com
    firestore.us-west1.rep.googleapis.com
    firestore.us-west2.rep.googleapis.com
    firestore.us-west3.rep.googleapis.com
    firestore.us-west4.rep.googleapis.com
    firestore.us-west8.rep.googleapis.com

ללא
‫Google Kubernetes Engine (GKE) Hub (fleets)
    gkehub.us-central1.rep.googleapis.com
    gkehub.us-central2.rep.googleapis.com
    gkehub.us-east1.rep.googleapis.com
    gkehub.us-east4.rep.googleapis.com
    gkehub.us-east5.rep.googleapis.com
    gkehub.us-east7.rep.googleapis.com
    gkehub.us-south1.rep.googleapis.com
    gkehub.us-west1.rep.googleapis.com
    gkehub.us-west2.rep.googleapis.com
    gkehub.us-west3.rep.googleapis.com
    gkehub.us-west4.rep.googleapis.com
    gkehub.us-west8.rep.googleapis.com

ללא
‫AI גנרטיבי ב-Vertex AI
    aiplatform.us.rep.googleapis.com

מגבלות שקשורות למדיניות הארגון
Google Cloud Armor
    compute.us-central1.rep.googleapis.com
    compute.us-central2.rep.googleapis.com
    compute.us-east1.rep.googleapis.com
    compute.us-east4.rep.googleapis.com
    compute.us-east5.rep.googleapis.com
    compute.us-east7.rep.googleapis.com
    compute.us-south1.rep.googleapis.com
    compute.us-west1.rep.googleapis.com
    compute.us-west2.rep.googleapis.com
    compute.us-west3.rep.googleapis.com
    compute.us-west4.rep.googleapis.com
    compute.us-west8.rep.googleapis.com

תכונות מושפעות
שירות מנוהל של Google Cloud ל-Apache Kafka
    managedkafka.us-central1.rep.googleapis.com
    managedkafka.us-east1.rep.googleapis.com
    managedkafka.us-east4.rep.googleapis.com
    managedkafka.us-east5.rep.googleapis.com
    managedkafka.us-east7.rep.googleapis.com
    managedkafka.us-south1.rep.googleapis.com
    managedkafka.us-west1.rep.googleapis.com
    managedkafka.us-west2.rep.googleapis.com
    managedkafka.us-west3.rep.googleapis.com
    managedkafka.us-west4.rep.googleapis.com

ללא
מאזן עומסי רשת פנימי להעברת סיגנל ללא שינוי
    compute.us-central1.rep.googleapis.com
    compute.us-central2.rep.googleapis.com
    compute.us-east1.rep.googleapis.com
    compute.us-east4.rep.googleapis.com
    compute.us-east5.rep.googleapis.com
    compute.us-east7.rep.googleapis.com
    compute.us-south1.rep.googleapis.com
    compute.us-west1.rep.googleapis.com
    compute.us-west2.rep.googleapis.com
    compute.us-west3.rep.googleapis.com
    compute.us-west4.rep.googleapis.com
    compute.us-west8.rep.googleapis.com

ללא
הצדקות גישה למפתחות
    cloudkms.us.rep.googleapis.com
    cloudkms.us-central1.rep.googleapis.com
    cloudkms.us-central2.rep.googleapis.com
    cloudkms.us-east1.rep.googleapis.com
    cloudkms.us-east4.rep.googleapis.com
    cloudkms.us-east5.rep.googleapis.com
    cloudkms.us-east7.rep.googleapis.com
    cloudkms.us-south1.rep.googleapis.com
    cloudkms.us-west1.rep.googleapis.com
    cloudkms.us-west2.rep.googleapis.com
    cloudkms.us-west3.rep.googleapis.com
    cloudkms.us-west4.rep.googleapis.com
    cloudkms.us-west8.rep.googleapis.com

ללא
Knowledge Catalog
    dataplex.us.rep.googleapis.com
    dataplex.us-central1.rep.googleapis.com
    dataplex.us-central2.rep.googleapis.com
    dataplex.us-east1.rep.googleapis.com
    dataplex.us-east4.rep.googleapis.com
    dataplex.us-east5.rep.googleapis.com
    dataplex.us-east7.rep.googleapis.com
    dataplex.us-south1.rep.googleapis.com
    dataplex.us-west1.rep.googleapis.com
    dataplex.us-west2.rep.googleapis.com
    dataplex.us-west3.rep.googleapis.com
    dataplex.us-west4.rep.googleapis.com
    dataplex.us-west8.rep.googleapis.com
    datalineage.us.rep.googleapis.com
    datalineage.us-central1.rep.googleapis.com
    datalineage.us-central2.rep.googleapis.com
    datalineage.us-east1.rep.googleapis.com
    datalineage.us-east4.rep.googleapis.com
    datalineage.us-east5.rep.googleapis.com
    datalineage.us-east7.rep.googleapis.com
    datalineage.us-south1.rep.googleapis.com
    datalineage.us-west1.rep.googleapis.com
    datalineage.us-west2.rep.googleapis.com
    datalineage.us-west3.rep.googleapis.com
    datalineage.us-west4.rep.googleapis.com

תכונות מושפעות
Managed Service for Apache Airflow
    composer.us-central1.rep.googleapis.com
    composer.us-east1.rep.googleapis.com
    composer.us-east4.rep.googleapis.com
    composer.us-east5.rep.googleapis.com
    composer.us-east7.rep.googleapis.com
    composer.us-south1.rep.googleapis.com
    composer.us-west1.rep.googleapis.com
    composer.us-west2.rep.googleapis.com
    composer.us-west3.rep.googleapis.com
    composer.us-west4.rep.googleapis.com

ללא
‫Managed Service for Apache Spark
    dataproc-control.us-central1.rep.googleapis.com
    dataproc-control.us-central2.rep.googleapis.com
    dataproc-control.us-east1.rep.googleapis.com
    dataproc-control.us-east4.rep.googleapis.com
    dataproc-control.us-east5.rep.googleapis.com
    dataproc-control.us-east7.rep.googleapis.com
    dataproc-control.us-south1.rep.googleapis.com
    dataproc-control.us-west1.rep.googleapis.com
    dataproc-control.us-west2.rep.googleapis.com
    dataproc-control.us-west3.rep.googleapis.com
    dataproc-control.us-west4.rep.googleapis.com
    dataproc-control.us-west8.rep.googleapis.com
    dataproc.us-central1.rep.googleapis.com
    dataproc.us-central2.rep.googleapis.com
    dataproc.us-east1.rep.googleapis.com
    dataproc.us-east4.rep.googleapis.com
    dataproc.us-east5.rep.googleapis.com
    dataproc.us-east7.rep.googleapis.com
    dataproc.us-south1.rep.googleapis.com
    dataproc.us-west1.rep.googleapis.com
    dataproc.us-west2.rep.googleapis.com
    dataproc.us-west3.rep.googleapis.com
    dataproc.us-west4.rep.googleapis.com
    dataproc.us-west8.rep.googleapis.com

ללא
‫Memorystore for Redis
    redis.us-central1.rep.googleapis.com
    redis.us-central2.rep.googleapis.com
    redis.us-east1.rep.googleapis.com
    redis.us-east4.rep.googleapis.com
    redis.us-east5.rep.googleapis.com
    redis.us-east7.rep.googleapis.com
    redis.us-south1.rep.googleapis.com
    redis.us-west1.rep.googleapis.com
    redis.us-west2.rep.googleapis.com
    redis.us-west3.rep.googleapis.com
    redis.us-west4.rep.googleapis.com
    redis.us-west8.rep.googleapis.com

ללא
Persistent Disk
    compute.us-central1.rep.googleapis.com
    compute.us-central2.rep.googleapis.com
    compute.us-east1.rep.googleapis.com
    compute.us-east4.rep.googleapis.com
    compute.us-east5.rep.googleapis.com
    compute.us-east7.rep.googleapis.com
    compute.us-south1.rep.googleapis.com
    compute.us-west1.rep.googleapis.com
    compute.us-west2.rep.googleapis.com
    compute.us-west3.rep.googleapis.com
    compute.us-west4.rep.googleapis.com
    compute.us-west8.rep.googleapis.com

ללא
Pub/Sub
    pubsub.us-central1.rep.googleapis.com
    pubsub.us-central2.rep.googleapis.com
    pubsub.us-east1.rep.googleapis.com
    pubsub.us-east4.rep.googleapis.com
    pubsub.us-east5.rep.googleapis.com
    pubsub.us-east7.rep.googleapis.com
    pubsub.us-south1.rep.googleapis.com
    pubsub.us-west1.rep.googleapis.com
    pubsub.us-west2.rep.googleapis.com
    pubsub.us-west3.rep.googleapis.com
    pubsub.us-west4.rep.googleapis.com
    pubsub.us-west8.rep.googleapis.com

מגבלות שקשורות למדיניות הארגון
מאזן עומסים חיצוני אזורי של אפליקציות (ALB)
    compute.us-central1.rep.googleapis.com
    compute.us-central2.rep.googleapis.com
    compute.us-east1.rep.googleapis.com
    compute.us-east4.rep.googleapis.com
    compute.us-east5.rep.googleapis.com
    compute.us-east7.rep.googleapis.com
    compute.us-south1.rep.googleapis.com
    compute.us-west1.rep.googleapis.com
    compute.us-west2.rep.googleapis.com
    compute.us-west3.rep.googleapis.com
    compute.us-west4.rep.googleapis.com
    compute.us-west8.rep.googleapis.com

ללא
מאזן עומסי רשת אזורי חיצוני בשרת proxy
    compute.us-central1.rep.googleapis.com
    compute.us-central2.rep.googleapis.com
    compute.us-east1.rep.googleapis.com
    compute.us-east4.rep.googleapis.com
    compute.us-east5.rep.googleapis.com
    compute.us-east7.rep.googleapis.com
    compute.us-south1.rep.googleapis.com
    compute.us-west1.rep.googleapis.com
    compute.us-west2.rep.googleapis.com
    compute.us-west3.rep.googleapis.com
    compute.us-west4.rep.googleapis.com
    compute.us-west8.rep.googleapis.com

ללא
מאזן עומסים פנימי אזורי של אפליקציות (ALB)
    compute.us-central1.rep.googleapis.com
    compute.us-central2.rep.googleapis.com
    compute.us-east1.rep.googleapis.com
    compute.us-east4.rep.googleapis.com
    compute.us-east5.rep.googleapis.com
    compute.us-east7.rep.googleapis.com
    compute.us-south1.rep.googleapis.com
    compute.us-west1.rep.googleapis.com
    compute.us-west2.rep.googleapis.com
    compute.us-west3.rep.googleapis.com
    compute.us-west4.rep.googleapis.com
    compute.us-west8.rep.googleapis.com

ללא
מאזן עומסי רשת פנימי אזורי בשרת proxy
    compute.us-central1.rep.googleapis.com
    compute.us-central2.rep.googleapis.com
    compute.us-east1.rep.googleapis.com
    compute.us-east4.rep.googleapis.com
    compute.us-east5.rep.googleapis.com
    compute.us-east7.rep.googleapis.com
    compute.us-south1.rep.googleapis.com
    compute.us-west1.rep.googleapis.com
    compute.us-west2.rep.googleapis.com
    compute.us-west3.rep.googleapis.com
    compute.us-west4.rep.googleapis.com
    compute.us-west8.rep.googleapis.com

ללא
Secret Manager
    secretmanager.us.rep.googleapis.com
    secretmanager.us-central1.rep.googleapis.com
    secretmanager.us-central2.rep.googleapis.com
    secretmanager.us-east1.rep.googleapis.com
    secretmanager.us-east4.rep.googleapis.com
    secretmanager.us-east5.rep.googleapis.com
    secretmanager.us-east7.rep.googleapis.com
    secretmanager.us-south1.rep.googleapis.com
    secretmanager.us-west1.rep.googleapis.com
    secretmanager.us-west2.rep.googleapis.com
    secretmanager.us-west3.rep.googleapis.com
    secretmanager.us-west4.rep.googleapis.com

ללא
Secure Source Manager
    securesourcemanager.us-central1.rep.googleapis.com
    securesourcemanager.us-east1.rep.googleapis.com
    securesourcemanager.us-east4.rep.googleapis.com
    securesourcemanager.us-east7.rep.googleapis.com
    securesourcemanager.us-west2.rep.googleapis.com

ללא
‫Security Command Center Premium
    securitycenter.us.rep.googleapis.com

תכונות מושפעות
Sensitive Data Protection
    dlp.us.rep.googleapis.com
    dlp.us-central1.rep.googleapis.com
    dlp.us-central2.rep.googleapis.com
    dlp.us-east1.rep.googleapis.com
    dlp.us-east4.rep.googleapis.com
    dlp.us-east5.rep.googleapis.com
    dlp.us-south1.rep.googleapis.com
    dlp.us-west1.rep.googleapis.com
    dlp.us-west2.rep.googleapis.com
    dlp.us-west3.rep.googleapis.com
    dlp.us-west4.rep.googleapis.com
    dlp.us-west8.rep.googleapis.com

ללא
Service Directory
    servicedirectory.us-central1.rep.googleapis.com
    servicedirectory.us-central2.rep.googleapis.com
    servicedirectory.us-east1.rep.googleapis.com
    servicedirectory.us-east4.rep.googleapis.com
    servicedirectory.us-east5.rep.googleapis.com
    servicedirectory.us-east7.rep.googleapis.com
    servicedirectory.us-south1.rep.googleapis.com
    servicedirectory.us-west1.rep.googleapis.com
    servicedirectory.us-west2.rep.googleapis.com
    servicedirectory.us-west3.rep.googleapis.com
    servicedirectory.us-west4.rep.googleapis.com
    servicedirectory.us-west8.rep.googleapis.com

ללא
חיזוי אונליין של Vertex AI
    aiplatform.us.rep.googleapis.com

מגבלות שקשורות למדיניות הארגון
VM Manager
    osconfig.us-central1.rep.googleapis.com
    osconfig.us-central2.rep.googleapis.com
    osconfig.us-east1.rep.googleapis.com
    osconfig.us-east4.rep.googleapis.com
    osconfig.us-east5.rep.googleapis.com
    osconfig.us-east7.rep.googleapis.com
    osconfig.us-south1.rep.googleapis.com
    osconfig.us-west1.rep.googleapis.com
    osconfig.us-west2.rep.googleapis.com
    osconfig.us-west3.rep.googleapis.com
    osconfig.us-west4.rep.googleapis.com
    osconfig.us-west8.rep.googleapis.com

ללא
ענן וירטואלי פרטי (VPC)
    compute.us-central1.rep.googleapis.com
    compute.us-central2.rep.googleapis.com
    compute.us-east1.rep.googleapis.com
    compute.us-east4.rep.googleapis.com
    compute.us-east5.rep.googleapis.com
    compute.us-east7.rep.googleapis.com
    compute.us-south1.rep.googleapis.com
    compute.us-west1.rep.googleapis.com
    compute.us-west2.rep.googleapis.com
    compute.us-west3.rep.googleapis.com
    compute.us-west4.rep.googleapis.com
    compute.us-west8.rep.googleapis.com

תכונות מושפעות

מוצרים נתמכים עם נקודות קצה גלובליות של API

בטבלה הבאה מופיעה רשימה של מוצרים נתמכים ונקודות הקצה הגלובליות שלהם ל-API. נקודות הקצה הגלובליות של ה-API האלה מיועדות לעיבוד נתוני שירות, כמו נתוני תצורה, מטא-נתונים או מזהי משאבים, ולא לעיבוד נתוני לקוחות. באחריותכם לוודא שלא תעבירו נתונים טכניים שמוסדרים על ידי ITAR דרך נקודות הקצה הגלובליות האלה של ה-API.

מוצר נתמך נקודות קצה גלובליות ל-API הגבלות
אישור גישה
    accessapproval.googleapis.com
ללא
Access Context Manager
    accesscontextmanager.googleapis.com
ללא
Certificate Authority Service
    privateca.googleapis.com
ללא
‫Certificate Manager
    certificatemanager.googleapis.com
ללא
‫Cloud Billing API
    billingbudgets.googleapis.com
    cloudbilling.googleapis.com
ללא
Cloud DNS
    dns.googleapis.com
תכונות מושפעות
Cloud Monitoring
    monitoring.googleapis.com
תכונות מושפעות
Cloud OS Login API
    oslogin.googleapis.com
ללא
אנשי קשר חיוניים
    essentialcontacts.googleapis.com
ללא
כללי אבטחה של Firebase
    firebaserules.googleapis.com
ללא
Google Kubernetes Engine (GKE) Identity Service
    anthosidentityservice.googleapis.com
ללא
סטרימינג של תמונות ב-GKE
    containerfilesystem.googleapis.com
ללא
Google Kubernetes Engine (GKE)‎
    container.googleapis.com
    containersecurity.googleapis.com
התכונות שיושפעו ומגבלות שקשורות למדיניות הארגון
ניהול זהויות והרשאות גישה (IAM)
    iam.googleapis.com
ללא
שרת proxy לאימות זהויות (IAP)
    iap.googleapis.com
ללא
המסוף Google Cloud המשפטי
    Not applicable
ללא
Network Connectivity Center
    networkconnectivity.googleapis.com
תכונות מושפעות
Organization Policy Service
    orgpolicy.googleapis.com
ללא
מנהל המשאבים
    cloudresourcemanager.googleapis.com
ללא
VPC Service Controls
    accesscontextmanager.googleapis.com
    accesscontextintelligence.googleapis.com
ללא

הגבלות ומגבלות

בסעיפים הבאים מתוארות הגבלות או מגבלות ברמת Google Cloudאו ברמת המוצר על תכונות, כולל אילוצים של מדיניות הארגון שמוגדרים כברירת מחדל בתיקיות ITAR. אילוצים אחרים של מדיניות הארגון שחלים על המשאבים – גם אם הם לא מוגדרים כברירת מחדל – יכולים לספק הגנה נוספת כדי להגן על המשאבים של הארגון Google Cloud .

‫Google Cloud-wide

תכונות שמושפעות Google Cloudבכל הארגון

התכונה תיאור
מסוףGoogle Cloud כדי לגשת למסוף Google Cloud כשמשתמשים בחבילת בקרת ITAR, צריך להשתמש באחת מכתובות ה-URL הבאות:

Google Cloudאילוצים של מדיניות הארגון ברמת הארגון

האילוצים הבאים של מדיניות הארגון חלים על כל Google Cloud.

אילוץ של מדיניות הארגון תיאור
gcp.resourceLocations מגדירים את המיקומים הבאים ברשימה allowedValues:
  • us
  • us-central1
  • us-central2
  • us-east1
  • us-east4
  • us-east5
  • us-south1
  • us-west1
  • us-west2
  • us-west3
  • us-west4
הערך הזה מגביל את יצירת המשאבים החדשים לערכים שנבחרו. אם מגדירים את האילוץ הזה, אי אפשר ליצור משאבים באזורים אחרים, באזורים מרובים או במיקומים מחוץ לבחירה. במאמר בנושא שירותים שנתמכים על ידי מיקומי משאבים מפורטת רשימה של משאבים שאפשר להגביל באמצעות המגבלה של מדיניות הארגון בנושא מיקומי משאבים. יכול להיות שחלק מהמשאבים לא ייכללו בהיקף ולא ניתן יהיה להגביל אותם.

שינוי הערך הזה כך שיהיה פחות מגביל עלול לפגוע במיקום אחסון הנתונים, כי הוא מאפשר ליצור או לאחסן נתונים מחוץ לגבולות הנתונים התואמים.
gcp.restrictCmekCryptoKeyProjects ההגדרה היא under:organizations/your-organization-name, שהוא הארגון שלכם ב-Assured Workloads. אפשר להגביל עוד יותר את הערך הזה על ידי ציון פרויקט או תיקייה.

מגביל את היקף התיקיות או הפרויקטים שאושרו ויכולים לספק מפתחות Cloud KMS להצפנת נתונים במנוחה באמצעות CMEK. האילוץ הזה מונע מתיקיות או מפרויקטים לא מאושרים לספק מפתחות הצפנה, וכך עוזר להבטיח ריבונות הנתונים בשירותים שכלולים בהיקף, עבור נתונים במנוחה.
gcp.restrictNonCmekServices מוגדר לרשימה של כל שמות השירותים של ה-API שנכללים בהיקף, כולל:
  • bigquery.googleapis.com
  • bigquerydatatransfer.googleapis.com
  • compute.googleapis.com
  • container.googleapis.com
  • storage.googleapis.com
יכול להיות שחלק מהתכונות יושפעו בכל אחד מהשירותים שמפורטים למעלה.

כל שירות שמופיע ברשימה דורש מפתחות הצפנה בניהול הלקוח (CMEK). הצפנת CMEK מתבצעת באמצעות מפתח שמנוהל על ידכם, ולא באמצעות מנגנוני ההצפנה שמוגדרים כברירת מחדל ב-Google.

שינוי הערך הזה על ידי הסרת שירות אחד או יותר מהרשימה עלול לפגוע בריבונות הנתונים, כי נתונים חדשים במצב מנוחה יוצפנו באופן אוטומטי באמצעות המפתחות של Google ולא באמצעות המפתחות שלכם. נתונים קיימים באחסון יישארו מוצפנים באמצעות המפתח שסיפקתם.
gcp.restrictServiceUsage ההגדרה צריכה להיות 'אפשר להשתמש בכל נקודות הקצה של מוצרי API נתמכים'.

הגבלת הגישה בזמן הריצה למשאבים של שירותים מסוימים, כדי לקבוע באילו שירותים אפשר להשתמש. מידע נוסף זמין במאמר בנושא הגבלת השימוש במשאבים.
gcp.restrictTLSVersion ההגדרה היא דחייה של גרסאות ה-TLS הבאות:
  • TLS_1_0
  • TLS_1_1
מידע נוסף זמין במאמר בנושא הגבלת גרסאות TLS.

BigQuery

תכונות BigQuery שמושפעות

התכונה תיאור
הפעלת BigQuery בתיקייה חדשה ‫BigQuery נתמך, אבל הוא לא מופעל באופן אוטומטי כשיוצרים תיקייה חדשה ב-Assured Workloads בגלל תהליך הגדרה פנימי. בדרך כלל התהליך הזה מסתיים תוך עשר דקות, אבל בנסיבות מסוימות הוא יכול להימשך הרבה יותר זמן. כדי לבדוק אם התהליך הסתיים ולהפעיל את BigQuery, מבצעים את השלבים הבאים:
  1. נכנסים לדף Assured Workloads במסוף Google Cloud .

    כניסה אל Assured Workloads

  2. בוחרים את התיקייה החדשה של Assured Workloads מהרשימה.
  3. בדף Folder Details (פרטי התיקייה), בקטע Allowed services (שירותים מורשים), לוחצים על Review Available Updates (בדיקת עדכונים זמינים).
  4. בחלונית Allowed services (שירותים מותרים), בודקים את השירותים שרוצים להוסיף למדיניות הארגון Resource Usage Restriction (הגבלת השימוש במשאבים) של התיקייה. אם שירותי BigQuery מופיעים ברשימה, לוחצים על Allow Services (התרת שירותים) כדי להוסיף אותם.

    אם שירותי BigQuery לא מופיעים ברשימה, צריך לחכות עד שהתהליך הפנימי יסתיים. אם השירותים לא מופיעים תוך 12 שעות מיצירת התיקייה, צריך לפנות אל Cloud Customer Care.

אחרי שתהליך ההפעלה יסתיים, תוכלו להשתמש ב-BigQuery בתיקייה Assured Workloads.

‫Gemini ב-BigQuery לא נתמך על ידי Assured Workloads.

ממשקי API תואמים של BigQuery ממשקי ה-API הבאים של BigQuery תואמים ל-ITAR:
אזורים ‫BigQuery תואם ל-ITAR בכל האזורים בארה"ב של BigQuery, למעט האזור הגיאוגרפי בארה"ב שכולל מספר אזורים. אי אפשר להבטיח תאימות ל-ITAR אם מערך נתונים נוצר באזור בארה"ב, באזור שלא בארה"ב או במספר אזורים שלא בארה"ב. באחריותכם לציין אזור שתואם ל-ITAR כשיוצרים מערכי נתונים ב-BigQuery.
שאילתות על קבוצות נתונים של ITAR מפרויקטים שלא עומדים בדרישות ITAR ‫BigQuery לא מונע הפעלת שאילתות על מערכי נתונים של ITAR מפרויקטים שאינם ITAR. חשוב לוודא שכל שאילתה שמשתמשת בפעולת קריאה או בפעולת צירוף של נתונים טכניים שחלים עליהם תקנות ITAR נמצאת בתיקייה שתואמת לתקנות ITAR.
חיבורים למקורות נתונים חיצוניים האחריות של Google לתאימות מוגבלת ליכולת של BigQuery Connection API. באחריותכם לוודא שהמוצרים במקור שבהם נעשה שימוש ב-BigQuery Connection API עומדים בדרישות.
תכונות שלא נתמכות התכונות הבאות של BigQuery לא נתמכות ואסור להשתמש בהן בכלי BigQuery CLI. באחריותכם לא להשתמש בהם ב-BigQuery עבור Assured Workloads.
‫BigQuery CLI יש תמיכה ב-CLI של BigQuery.

Google Cloud SDK כדי לשמור על ההתחייבויות בנוגע לאזוריות הנתונים של נתונים טכניים, צריך להשתמש בגרסה 403.0.0 ואילך של Google Cloud SDK. כדי לוודא מהי גרסת Google Cloud SDK הנוכחית, מריצים את הפקודה gcloud --version ואז את הפקודה gcloud components update כדי לעדכן לגרסה החדשה ביותר.
אמצעי בקרה לאדמינים מערכת BigQuery תשבית ממשקי API שלא נתמכים, אבל אדמינים עם הרשאות מספיקות ליצירת תיקיות של Assured Workloads יכולים להפעיל ממשק API שלא נתמך. אם זה יקרה, תקבלו הודעה על אי-תאימות פוטנציאלית דרך לוח הבקרה של Assured Workloads.
טעינת נתונים אין תמיכה במחברים של שירות העברת נתונים ל-BigQuery עבור אפליקציות של Google Software as a Service‏ (SaaS), ספקי אחסון בענן חיצוניים ומחסני נתונים. באחריותכם לא להשתמש במחברים של שירות העברת הנתונים ל-BigQuery עבור עומסי עבודה של ITAR.
העברות לצד שלישי מערכת BigQuery לא מאמתת תמיכה בהעברות של צד שלישי בשירות העברת הנתונים ל-BigQuery. באחריותכם לוודא שיש תמיכה כשמשתמשים בהעברה של צד שלישי בשירות העברת הנתונים ל-BigQuery.
מודלים של BQML שלא עומדים בדרישות מודלים של BQML שאומנו חיצונית לא נתמכים.
משימות של השאילתה צריך ליצור משימות של שאילתות רק בתיקיות Assured Workloads.
שאילתות על מערכי נתונים בפרויקטים אחרים ‫BigQuery לא מונע הפעלת שאילתות על מערכי נתונים של Assured Workloads מפרויקטים שאינם Assured Workloads. חשוב לוודא שכל שאילתה שכוללת קריאה או צירוף של נתונים מ-Assured Workloads ממוקמת בתיקיות של Assured Workloads. אפשר לציין שם טבלה מלא לתוצאת השאילתה באמצעות projectname.dataset.table ב-BigQuery CLI.
Cloud Logging חלק מנתוני היומן שלכם מועברים ל-BigQuery דרך Cloud Logging. כדי לשמור על תאימות, צריך להשבית את _defaultקטגוריות רישום ביומן או להגביל את _defaultהקטגוריות לאזורים שכלולים בהיקף באמצעות הפקודה הבאה:

gcloud alpha logging settings update --organization=ORGANIZATION_ID --disable-default-sink

מידע נוסף זמין במאמר בנושא הגדרת אזור ליומנים.

Cloud DNS

התכונות שיושפעו ב-Cloud DNS

התכונה תיאור
מסוףGoogle Cloud התכונות של Cloud DNS לא זמינות במסוף Google Cloud . במקום זאת, אפשר להשתמש בAPI או ב-Google Cloud CLI.

Cloud Interconnect

התכונות שיושפעו ב-Cloud Interconnect

התכונה תיאור
מסוףGoogle Cloud התכונות של Cloud Interconnect לא זמינות במסוף Google Cloud . במקום זאת, אפשר להשתמש בAPI או ב-Google Cloud CLI.
רשת VPN בזמינות גבוהה (HA) כשמשתמשים ב-Cloud Interconnect עם Cloud VPN, צריך להפעיל את הפונקציונליות של VPN בזמינות גבוהה (HA). בנוסף, אתם צריכים לעמוד בדרישות ההצפנה והאזוריות שמפורטות בקטע תכונות Cloud VPN שמושפעות.

Cloud Load Balancing

התכונות של Cloud Load Balancing שיושפעו

התכונה תיאור
מסוףGoogle Cloud התכונות של Cloud Load Balancing לא זמינות במסוף Google Cloud . במקום זאת, אפשר להשתמש בAPI או ב-Google Cloud CLI.
מאזני עומסים אזוריים חובה להשתמש במאזני עומסים אזוריים עם ITAR. מידע נוסף על הגדרת מאזני עומסים אזוריים זמין בדפים הבאים:

Cloud Logging

התכונות שיושפעו ב-Cloud Logging

התכונה תיאור
מאגרי יומנים המסננים לא צריכים להכיל נתוני לקוחות.

אובייקטים מסוג sink ביומן כוללים מסננים שמאוחסנים כהגדרה. אל תיצרו מסננים שמכילים נתוני לקוחות.
רישום ביומן בזמן אמת המסננים לא צריכים להכיל נתוני לקוחות.

סשן של רישום ביומן בזמן אמת כולל מסנן שמאוחסן כהגדרה. הפעלת tailing ביומנים לא שומרת נתוני רשומות ביומן, אבל יכולה להריץ שאילתות ולהעביר נתונים בין אזורים. אל תיצרו מסננים שמכילים נתוני לקוחות.
התראות מבוססות-יומן התכונה הזו מושבתת.

אי אפשר ליצור התראות שמבוססות על יומנים במסוף Google Cloud .
כתובות URL מקוצרות לשאילתות ב-Logs Explorer התכונה הזו מושבתת.

אי אפשר ליצור כתובות URL מקוצרות של שאילתות במסוף Google Cloud .
שמירת שאילתות ב-Logs Explorer התכונה הזו מושבתת.

אי אפשר לשמור שאילתות במסוף Google Cloud .
מדיניות התראות שמבוססת על SQL התכונה הזו מושבתת.

אי אפשר להשתמש בתכונה של מדיניות התראות מבוססת-SQL.

Cloud Monitoring

התכונות שיושפעו ב-Cloud Monitoring

התכונה תיאור
Synthetic Monitor התכונה הזו מושבתת.
בדיקת זמני פעילות התכונה הזו מושבתת.
ווידג'טים של חלונית היומן בלוחות בקרה התכונה הזו מושבתת.

אי אפשר להוסיף חלונית יומן ללוח בקרה.
ווידג'טים של לוחות לדיווח על שגיאות במרכזי בקרה התכונה הזו מושבתת.

אי אפשר להוסיף חלונית של דיווח על שגיאות ללוח בקרה.
סינון ב EventAnnotation במרכזי בקרה התכונה הזו מושבתת.

אי אפשר להגדיר מסנן של EventAnnotation בדשבורד.
SqlCondition ב-alertPolicies התכונה הזו מושבתת.

אי אפשר להוסיף SqlCondition אל alertPolicy.

Cloud NAT

התכונות שיושפעו ב-Cloud NAT

התכונה תיאור
מסוףGoogle Cloud התכונות של Cloud NAT לא זמינות במסוף Google Cloud . במקום זאת, אפשר להשתמש בAPI או ב-Google Cloud CLI.

Cloud Router

תכונות Cloud Router שהושפעו

התכונה תיאור
מסוףGoogle Cloud התכונות של Cloud Router לא זמינות במסוף Google Cloud . במקום זאת, אפשר להשתמש בAPI או ב-Google Cloud CLI.

Cloud Run

התכונות שיושפעו ב-Cloud Run

התכונה תיאור
תכונות שלא נתמכות התכונות הבאות של Cloud Run לא נתמכות:

Cloud SQL

התכונות שיושפעו ב-Cloud SQL

התכונה תיאור
ייצוא ל-CSV אל תשתמשו בתכונה ייצוא ל-CSV כי היא לא עומדת בדרישות של ITAR. התכונה הזו מושבתת במסוף Google Cloud .
executeSql אל תשתמשו בשיטה executeSql של Cloud SQL API כי היא לא עומדת בדרישות של ITAR.

Cloud Storage

תכונות Cloud Storage שמושפעות

התכונה תיאור
מסוףGoogle Cloud כדי לשמור על תאימות ל-ITAR, באחריותכם להשתמש במסוף השיפוט Google Cloud . במסוף של אזור שיפוט מסוים אי אפשר להעלות ולהוריד אובייקטים ב-Cloud Storage. כדי להעלות ולהוריד אובייקטים ב-Cloud Storage, אפשר לעיין בשורה נקודות קצה של API שתואמות לתקנות בקטע הזה.
נקודות קצה ל-API שעומדות בדרישות חובה להשתמש באחת מנקודות הקצה האזוריות שתואמות ל-ITAR עם Cloud Storage. מידע נוסף זמין במאמרים נקודות קצה אזוריות ב-Cloud Storage ומיקומים ב-Cloud Storage.
הגבלות כדי לעמוד בדרישות התאימות ל-ITAR, צריך להשתמש בנקודות קצה אזוריות של Cloud Storage. מידע נוסף על נקודות קצה אזוריות של Cloud Storage ל-ITAR זמין במאמר נקודות קצה אזוריות של Cloud Storage.

נקודות קצה אזוריות לא תומכות בפעולות הבאות. עם זאת, הפעולות האלה לא כוללות נתוני לקוחות כפי שמוגדר בתנאים של שירות אחסון נתונים. לכן, אפשר להשתמש בנקודות קצה גלובליות לפעולות האלה לפי הצורך, בלי להפר את התאימות ל-ITAR:
העתקה ושכתוב של אובייקטים נקודות קצה אזוריות תומכות בפעולות של העתקה ושכתוב של אובייקטים, אם קטגוריית המקור וקטגוריית היעד נמצאות באזור שצוין בנקודת הקצה. אבל אי אפשר להשתמש בנקודות קצה אזוריות כדי להעתיק או לשכתב אובייקט מקטגוריה אחת לאחרת, אם הקטגוריות נמצאות במיקומים שונים. אפשר להשתמש בנקודות קצה גלובליות כדי להעתיק או לשכתב בין מיקומים, אבל אנחנו לא ממליצים על כך כי זה עלול להוביל להפרה של התאימות לתקנות ITAR.

Cloud VPN

תכונות Cloud VPN שמושפעות

התכונה תיאור
מסוףGoogle Cloud התכונות של Cloud VPN לא זמינות במסוף Google Cloud . במקום זאת, אפשר להשתמש בAPI או ב-Google Cloud CLI.
הצפנה כשיוצרים אישורים ומגדירים את אבטחת ה-IP, צריך להשתמש רק בהצפנות שתואמות לתקן FIPS 140-2. מידע נוסף על הצפנות שנתמכות ב-Cloud VPN זמין בדף הצפנות IKE נתמכות. הנחיות לבחירת צופן שתואם לתקני FIPS 140-2 מופיעות בדף FIPS 140-2 Validated.

אי אפשר לשנות צופן קיים ב- Google Cloud. מוודאים שהגדרתם את הצופן במכשיר של צד שלישי שמשמש עם Cloud VPN.
נקודות קצה של VPN חובה להשתמש רק בנקודות קצה של Cloud VPN שנמצאות באזור שכלול בהיקף. מוודאים ששער ה-VPN מוגדר לשימוש רק באזור שכלול בהיקף.

Compute Engine

התכונות שיושפעו ב-Compute Engine

התכונה תיאור
השהיה וחידוש של מכונת VM התכונה הזו מושבתת.

השהיה והפעלה מחדש של מכונה וירטואלית דורשות אחסון בדיסק לאחסון מתמיד, ובשלב הזה אי אפשר להצפין את האחסון בדיסק לאחסון מתמיד שמשמש לאחסון המצב של המכונה הווירטואלית המושהית באמצעות CMEK. עיין באילוץ של מדיניות הארגון gcp.restrictNonCmekServices בקטע שלמעלה כדי להבין את ההשלכות של הפעלת התכונה הזו על ריבונות הנתונים ועל מיקום אחסון הנתונים.
אחסון SSD מקומי התכונה הזו מושבתת.

לא תוכלו ליצור מכונה וירטואלית עם כונני SSD מקומיים, כי אי אפשר להצפין אותם באמצעות CMEK. בקטע שלמעלה מוסבר על האילוץ של מדיניות הארגון gcp.restrictNonCmekServices, כדי להבין את ההשלכות של הפעלת התכונה הזו על ריבונות הנתונים ועל מיקום אחסון הנתונים.
מסוףGoogle Cloud

התכונות הבאות של Compute Engine לא זמינות במסוף Google Cloud . במקום זאת, אפשר להשתמש ב-API או ב-Google Cloud CLI:

שיקולי אבטחה לגבי מטא-נתונים של מכונות וירטואליות באחריותכם לא לכתוב מידע אישי רגיש לשרת המטא-נתונים של המכונה הווירטואלית.
מכונות וירטואליות של Bare Metal Solution אי אפשר להשתמש במכונות וירטואליות של Bare Metal Solution (מכונות וירטואליות מסוג o2) כי הן לא עומדות בדרישות של ITAR.

מכונות וירטואליות ב-Google Cloud VMware Engine אי אפשר להשתמש במכונות וירטואליות של Google Cloud VMware Engine, כי הן לא עומדות בדרישות של ITAR.

יצירת מופע של מכונה וירטואלית מסוג C3 התכונה הזו מושבתת.

שימוש בדיסקים מתמידים או בתמונות המצב שלהם ללא CMEK אי אפשר להשתמש בדיסקים קשיחים קבועים או בתמונות המצב שלהם אלא אם הם הוצפנו באמצעות CMEK.

שיתוף דיסק אחסון מתמיד שמבוסס על SSD במצב ריבוי כתיבה אי אפשר לשתף דיסק מתמיד שמבוסס על SSD במצב ריבוי כותבים בין מופעי מכונות וירטואליות.
הוספת קבוצת מופעים למאזן עומסים גלובלי אי אפשר להוסיף קבוצת מופעים למאזן עומסים גלובלי.

התכונה הזו מושבתת בגלל אילוץ המדיניות של compute.disableGlobalLoadBalancing הארגון.
סביבת אורח יכול להיות שסקריפטים, תהליכי רקע וקבצים בינאריים שכלולים בסביבת האורח יוכלו לגשת לנתונים לא מוצפנים במנוחה ובשימוש. יכול להיות שהעדכונים של התוכנה הזו יותקנו כברירת מחדל, בהתאם להגדרת המכונה הווירטואלית. מידע ספציפי על התוכן של כל חבילה, קוד המקור ועוד מופיע במאמר בנושא סביבת אורח.

הרכיבים האלה עוזרים לכם לעמוד בדרישות של ריבונות נתונים באמצעות אמצעי אבטחה ותהליכים פנימיים. עם זאת, אם אתם רוצים שליטה נוספת, אתם יכולים גם לאצור תמונות או סוכנים משלכם, ואם תרצו, תוכלו להשתמש באילוץ compute.trustedImageProjects של מדיניות הארגון.

מידע נוסף זמין במאמר בנושא יצירת תמונה בהתאמה אישית.
OS policies in VM Manager סקריפטים מוטבעים וקבצים בינאריים של פלט בקובצי מדיניות של מערכת ההפעלה לא מוצפנים באמצעות מפתחות הצפנה בניהול הלקוח (CMEK). אל תכללו מידע רגיש בקבצים האלה. מומלץ לאחסן את הסקריפטים ואת קובצי הפלט בקטגוריות של Cloud Storage. מידע נוסף זמין במאמר בנושא דוגמאות למדיניות של מערכת הפעלה.

אם רוצים להגביל את היצירה או השינוי של משאבי מדיניות של מערכת ההפעלה שמשתמשים בסקריפטים מוטבעים או בקובצי פלט בינאריים, צריך להפעיל את אילוץ מדיניות הארגון constraints/osconfig.restrictInlineScriptAndOutputFileUsage.

מידע נוסף זמין במאמר מגבלות של OS Config.
instances.getSerialPortOutput() ה-API הזה מושבת. לא תהיה לכם אפשרות לקבל פלט של יציאה טורית מהמופע שצוין באמצעות ה-API הזה.

כדי להפעיל את ה-API הזה, משנים את הערך של compute.disableInstanceDataAccessApis אילוץ מדיניות הארגון ל-False. אפשר גם להפעיל את היציאה הטורית האינטראקטיבית ולהשתמש בה לפי ההוראות שבקטע הפעלת גישה לפרויקט.
instances.getScreenshot() ה-API הזה מושבת. לא תהיה לך אפשרות לצלם מסך מהמופע שצוין באמצעות ה-API הזה.

כדי להפעיל את ה-API הזה, משנים את הערך של compute.disableInstanceDataAccessApis אילוץ מדיניות הארגון ל-False. אפשר גם להפעיל את היציאה הטורית האינטראקטיבית ולהשתמש בה לפי ההוראות שבקטע הפעלת גישה לפרויקט.

מגבלות של מדיניות הארגון ב-Compute Engine

אילוץ של מדיניות הארגון תיאור
compute.enableComplianceMemoryProtection מגדירים את הערך True.

ההגדרה משביתה חלק מתכונות האבחון הפנימיות כדי לספק הגנה נוספת על תכני הזיכרון במקרה של תקלה בתשתית.

שינוי הערך הזה עשוי להשפיע על מיקום אחסון הנתונים או על ריבונות הנתונים של עומס העבודה.
compute.disableGlobalCloudArmorPolicy מגדירים את הערך True.

משבית את היצירה של כללי מדיניות גלובליים לאבטחה ב-Google Cloud Armor ואת ההוספה או השינוי של כללים בכללי מדיניות גלובליים קיימים לאבטחה ב-Google Cloud Armor. המגבלה הזו לא חלה על הסרת כללים או על היכולת להסיר או לשנות את התיאור ואת כרטיס המוצר של מדיניות אבטחה גלובלית של Google Cloud Armor. האילוץ הזה לא משפיע על כללי מדיניות האבטחה האזוריים של Google Cloud Armor. כל כללי המדיניות הגלובליים והאזוריים לאבטחה שקיימים לפני האכיפה של ההגבלה הזו יישארו בתוקף.

compute.disableGlobalLoadBalancing מגדירים את הערך True.

משבית את היצירה של מוצרים גלובליים לאיזון עומסים.

שינוי הערך הזה עשוי להשפיע על מיקום אחסון הנתונים או על ריבונות הנתונים של עומס העבודה.
compute.disableGlobalSelfManagedSslCertificate מגדירים את הערך True.

משבית את היצירה של אישורי SSL בניהול עצמי ברמה הגלובלית.

שינוי הערך הזה עשוי להשפיע על מיקום אחסון הנתונים או על ריבונות הנתונים של עומס העבודה.
compute.disableInstanceDataAccessApis מגדירים את הערך True.

משבית את ממשקי ה-API של instances.getSerialPortOutput() ושל instances.getScreenshot() בכל העולם.

הפעלת האילוץ הזה מונעת יצירת פרטי כניסה במכונות וירטואליות של Windows Server.

אם אתם צריכים לנהל שם משתמש וסיסמה במכונה וירטואלית של Windows, אתם יכולים לבצע את הפעולות הבאות:
  1. הפעלת SSH במכונות וירטואליות של Windows.
  2. מריצים את הפקודה הבאה כדי לשנות את הסיסמה של מכונת ה-VM:
      gcloud compute ssh
      VM_NAME --command "net user USERNAME PASSWORD"
      
    מחליפים את מה שכתוב בשדות הבאים:
    • ‫VM_NAME: השם של המכונה הווירטואלית שאתם מגדירים לה סיסמה.
    • ‫USERNAME: שם המשתמש של המשתמש שרוצים להגדיר לו סיסמה.
    • PASSWORD: הסיסמה החדשה.
compute.requireOsConfig מגדירים את הערך True.

מפעיל את VM Manager (OS Config) בכל הפרויקטים החדשים. בכל המכונות הווירטואליות שנוצרות בפרויקטים חדשים, VM Manager מופעל.
compute.restrictNonConfidentialComputing

(אופציונלי) לא הוגדר ערך. כדאי להגדיר את הערך הזה כדי לספק הגנה נוספת. מידע נוסף זמין במאמרי העזרה בנושא מכונות וירטואליות חסויות.
compute.trustedImageProjects

(אופציונלי) לא הוגדר ערך. כדאי להגדיר את הערך הזה כדי לספק הגנה נוספת.

הגדרת הערך הזה מגבילה את אחסון התמונות ואת יצירת המופעים של הדיסקים לרשימה שצוינה של פרויקטים. הערך הזה משפיע על ריבונות הנתונים, כי הוא מונע שימוש בתמונות או בסוכנים לא מורשים.

Knowledge Catalog

תכונות של Knowledge Catalog

התכונה תיאור
Attribute Store התכונה הזו יצאה משימוש והיא מושבתת.
Data Catalog התכונה הזו יצאה משימוש והיא מושבתת. אי אפשר לחפש את המטא-נתונים או לנהל אותם בקטלוג הנתונים.
אגמים ואזורים התכונה הזו מושבתת. אין לכם אפשרות לנהל אגמים, אזורים ומשימות.

Google Cloud Armor

התכונות של Google Cloud Armor שנפגעו

התכונה תיאור
כללי מדיניות גלובליים לאבטחה התכונה הזו מושבתת בגלל ההגבלה של מדיניות הארגון compute.disableGlobalCloudArmorPolicy.

Google Kubernetes Engine

תכונות של Google Kubernetes Engine שהושפעו

התכונה תיאור
הגבלות על משאבי האשכול חשוב לוודא שהגדרת האשכול לא משתמשת במשאבים לשירותים שלא נתמכים ב-ITAR. לדוגמה, ההגדרה הבאה לא תקינה כי היא דורשת הפעלה של שירות שלא נתמך או שימוש בו:

set `binaryAuthorization.evaluationMode` to `enabled`

מגבלות של מדיניות הארגון ב-Google Kubernetes Engine

אילוץ של מדיניות הארגון תיאור
container.restrictNoncompliantDiagnosticDataAccess מגדירים את הערך True.

משבית את הניתוח המצטבר של בעיות בליבת המערכת, שנדרש כדי לשמור על שליטה ריבונית בעומס עבודה.

שינוי הערך הזה עשוי להשפיע על מיקום אחסון הנתונים או על ריבונות הנתונים של עומס העבודה.

Network Connectivity Center

התכונות שיושפעו ב-Network Connectivity Center

התכונה תיאור
מסוףGoogle Cloud התכונות של Network Connectivity Center לא זמינות במסוף Google Cloud . במקום זאת, אפשר להשתמש בAPI או ב-Google Cloud CLI.

Pub/Sub

אילוצים של מדיניות הארגון ב-Pub/Sub

אילוץ של מדיניות הארגון תיאור
pubsub.enforceInTransitRegions מגדירים את הערך True.

מוודא שנתוני הלקוח מועברים רק באזורים המותרים שצוינו במדיניות אחסון ההודעות בנושא Pub/Sub.

שינוי הערך הזה עשוי להשפיע על מיקום אחסון הנתונים או על ריבונות הנתונים של עומס העבודה.
pubsub.managed.disableSubscriptionMessageTransforms מגדירים את הערך True.

ההגדרה הזו משביתה את האפשרות להגדיר מינויים ל-Pub/Sub עם Single Message Transforms (SMTs).

שינוי הערך הזה עשוי להשפיע על מיקום אחסון הנתונים או על ריבונות הנתונים של עומס העבודה.
pubsub.managed.disableTopicMessageTransforms מגדירים את הערך True.

ההגדרה הזו משביתה את האפשרות להגדיר נושאי Pub/Sub עם Single Message Transforms (SMTs).

שינוי הערך הזה עשוי להשפיע על מיקום אחסון הנתונים או על ריבונות הנתונים של עומס העבודה.

Security Command Center Premium

תכונות מושפעות ב-Security Command Center Premium

התכונה תיאור
Compliance Manager ‫Compliance Manager לא נתמך ולא עומד בדרישות הבקרה של ITAR.
Data Security Posture Management התכונה Data Security Posture Management לא נתמכת ולא עומדת בדרישות הבקרה של ITAR.

Spanner

תכונות Spanner שהושפעו

התכונה תיאור
פיצול גבולות ‫Spanner משתמש בקבוצת משנה קטנה של מפתחות ראשיים ועמודות עם אינדקס כדי להגדיר גבולות פיצול, שעשויים לכלול נתוני לקוחות ומטא-נתונים. גבול פיצול ב-Spanner מציין את המיקום שבו טווחים רציפים של שורות מפולחים לחלקים קטנים יותר.

אנשי Google יכולים לגשת לגבולות המפוצלים האלה למטרות תמיכה טכנית וניפוי באגים, והם לא כפופים לאמצעי הבקרה של נתוני גישה אדמיניסטרטיבית ב-Assured Workloads.

מגבלות של מדיניות הארגון ב-Spanner

אילוץ של מדיניות הארגון תיאור
spanner.assuredWorkloadsAdvancedServiceControls מגדירים את הערך True.

החבילה מוסיפה אמצעי בקרה נוספים על ריבונות הנתונים ועל יכולת התמיכה במשאבי Spanner.
spanner.disableMultiRegionInstanceIfNoLocationSelected מגדירים את הערך True.

משבית את האפשרות ליצור מופעי Spanner עם מספר אזורים כדי לאכוף את מיקום הנתונים ואת ריבונות הנתונים.

Vertex AI

אילוצים של מדיניות הארגון ב-Vertex AI

אילוץ של מדיניות הארגון תיאור
vertexai.allowOnlyITARCompliantAPIs מגדירים את הערך True.

מאפשרת שימוש רק בממשקי API שתואמים ל-ITAR ב-Vertex AI APIs. כברירת מחדל, כל ממשקי ה-API מותרים.

ענן וירטואלי פרטי (VPC)

תכונות ה-VPC המושפעות

התכונה תיאור
מסוףGoogle Cloud תכונות של רשתות VPC לא זמינות במסוף Google Cloud . במקום זאת, אפשר להשתמש בAPI או ב-Google Cloud CLI.

המאמרים הבאים