# Google Cloud Security Best Practices Checklist: Complete Implementation Guide

> Implement Google Cloud security best practices with the google/skills checklist. This guide automates the Well-Architected Framework Security pillar using interactive validation and Rego-based scanning.

- Repository: [Google/skills](https://github.com/google/skills)
- Tags: best-practices
- Published: 2026-08-13

---

**The Google Cloud security best practices checklist in the `google/skills` repository provides an automated, skill-based framework that implements the Google Cloud Well-Architected Framework Security pillar through eight core principles, interactive validation workflows, and programmable Rego-based compliance scanning.**

The `google/skills` repository delivers a comprehensive, code-driven approach to cloud security posture management. This guide examines how the **Google Cloud security best practices checklist** is structured as reusable Skills and reference documents, enabling teams to systematically assess, prioritize, and remediate security gaps across their Google Cloud workloads through both AI-assisted conversations and automated Workload Manager evaluations.

## Core Security Principles in the google/skills Repository

The security checklist is anchored by eight core principles defined in [`skills/cloud/google-cloud-waf-security/SKILL.md`](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-waf-security/SKILL.md). These principles drive the assessment questions and product recommendations generated by the security skill.

The eight core principles are:

1. **Implement security by design** – Embed security controls throughout the architecture from initial planning
2. **Implement zero-trust** – Verify every access request regardless of network location
3. **Shift-left security** – Integrate security testing early in the CI/CD pipeline
4. **Pre-emptive cyber-defense** – Proactively identify and mitigate threats before exploitation
5. **Use AI securely** – Ensure AI implementations follow governance and safety standards
6. **Use AI for security** – Leverage Gemini and AI tools for threat detection and response
7. **Regulatory and privacy compliance** – Meet standards such as PCI-DSS, HIPAA, and GDPR
8. **Shared responsibility** – Understand the division of security obligations between Google and the customer

## Security Validation Checklist Structure

The validation checklist provides concrete "yes/no" questions to verify alignment with each principle. Located in the **Validation checklist** section of [`skills/cloud/google-cloud-waf-security/SKILL.md`](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-waf-security/SKILL.md), these questions cover critical areas including IAM hygiene, VPC Service Controls configuration, and Binary Authorization implementation.

The checklist operates through a five-step workflow:

1. **Start a Security Skill** – Invoke the `google-cloud-waf-security` skill via `npx skills add google/skills`
2. **Context Gathering** – The skill asks targeted **Workload Assessment Questions** (e.g., "How do you enforce least-privilege?")
3. **Gap Analysis** – Responses are mapped to the **Core Principles** and the **Validation Checklist**
4. **Recommendations** – For each gap, the skill proposes specific Google Cloud services
5. **Iterative Refinement** – Adjust recommendations to fit constraints, then re-validate

## Essential Google Cloud Security Products

According to the source code analysis, the checklist recommends specific Google Cloud products mapped to each security principle. These include:

- **Identity and Access**: IAM, Cloud Identity, and Identity-Aware Proxy (IAP) for zero-trust enforcement
- **Network Security**: Cloud Armor for DDoS protection and VPC Service Controls for data exfiltration prevention
- **Data Protection**: Cloud KMS, Confidential Computing, and Google Cloud DLP
- **Threat Detection**: Security Command Center and Chronicle for security analytics
- **Supply Chain Security**: Cloud Build and Binary Authorization for shift-left security
- **Compliance**: Assured Workloads and Organization Policy Service for regulatory alignment

## Automated Scanning with Workload Manager

The [`skills/cloud/workload-manager-basics/references/general-best-practices.md`](https://github.com/google/skills/blob/main/skills/cloud/workload-manager-basics/references/general-best-practices.md) file defines a cross-product catalog used by Workload Manager for posture checks. This catalog includes built-in security rules with severity levels and provides templates for custom Rego-based policies.

### Built-in Security Rules

The general catalog contains predefined rules covering security, reliability, and FinOps postures. These rules can be listed and evaluated through the Workload Manager API.

### Custom Rego Rules

Organizations can extend the checklist using Rego policies for organization-specific controls. For example, enforcing mandatory resource labels or disallowing external IP addresses on compute instances.

## Practical Implementation Examples

### Installing the Skills Package

To begin using the security checklist interactively, install the skills package:

```bash
npx skills add google/skills

```

### Running the Security Skill

Execute the security assessment workflow:

```bash
skill run google-cloud-waf-security

```

The agent will ask a series of questions (e.g., "How do you manage IAM roles?") and output recommendations such as:

```

✅ Implement security by design – enable Cloud Identity and IAM Recommender.
✅ Deploy Cloud Armor WAF for external traffic protection.
✅ Activate Binary Authorization in Cloud Build pipelines.

```

### Automating Workload Manager Evaluations

List built-in security rules using the gcloud CLI:

```bash
gcloud alpha workload-identity-pools rules list \
  --location=global \
  --project=$PROJECT_ID \
  --filter="category=security"

```

Create an automated evaluation using the general security catalog:

```bash
gcloud alpha workload-identity-pools evaluations create \
  --location=global \
  --project=$PROJECT_ID \
  --rule-set=general-security \
  --schedule="0 6 * * *"

```

### Deploying Custom Rego Rules

Define a custom rule requiring an `owner` label on all resources:

```rego
package security

deny[msg] {
  asset := input.asset
  not asset.labels.owner
  msg := sprintf("Resource %s missing required 'owner' label", [asset.name])
}

```

Upload the rule to Cloud Storage and reference it in an evaluation:

```bash
gcloud alpha workload-identity-pools evaluations create \
  --location=global \
  --project=$PROJECT_ID \
  --custom_rules_bucket=gs://my-custom-rules \
  --schedule="0 3 * * *"

```

## Key Source Files and References

The following files in the `google/skills` repository constitute the complete security checklist implementation:

| Path | Purpose |
|------|---------|
| [`skills/cloud/google-cloud-waf-security/SKILL.md`](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-waf-security/SKILL.md) | Core security-pillar skill definition, principles, checklist, and product mapping |
| [`skills/cloud/workload-manager-basics/references/general-best-practices.md`](https://github.com/google/skills/blob/main/skills/cloud/workload-manager-basics/references/general-best-practices.md) | Cross-product catalog of security rules, severity guidance, and custom-rule templates |
| [`skills/cloud/workload-manager-basics/SKILL.md`](https://github.com/google/skills/blob/main/skills/cloud/workload-manager-basics/SKILL.md) | Wrapper skill orchestrating Workload Manager scans |
| [`skills/cloud/google-cloud-waf-security/references/iam-security.md`](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-waf-security/references/iam-security.md) | Detailed IAM and identity-security guidelines |
| [`skills/cloud/google-cloud-waf-security/references/network-security.md`](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-waf-security/references/network-security.md) | Network-security controls including VPC Service Controls and Cloud Armor |
| [`skills/cloud/google-cloud-waf-security/references/data-security.md`](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-waf-security/references/data-security.md) | Data encryption and protection mechanisms |

## Summary

- The **Google Cloud security best practices checklist** is implemented as a reusable Skill in the `google/skills` repository, structured around the Google Cloud Well-Architected Framework Security pillar.
- Eight **core principles** guide the assessment, including zero-trust architecture, shift-left security, and AI-enhanced defense.
- The **Validation Checklist** provides concrete yes/no questions to verify alignment with each principle.
- **Workload Manager** integration enables automated compliance scanning through built-in rules and custom **Rego policies**.
- Interactive assessment is available via the `google-cloud-waf-security` skill, while programmatic access uses gcloud CLI commands for rule evaluation and scheduling.

## Frequently Asked Questions

### How does the Google Cloud security best practices checklist differ from standard compliance frameworks?

The checklist in `google/skills` combines the Google Cloud Well-Architected Framework with interactive AI-driven assessment tools and automated Workload Manager scanning. Unlike static PDF checklists, this implementation provides concrete product recommendations and can execute automated Rego-based policy validation against live infrastructure.

### Can I automate the security checklist evaluation without manual interaction?

Yes. While the `skill run google-cloud-waf-security` command provides an interactive experience, you can fully automate evaluations using the Workload Manager API. Create scheduled evaluations using `gcloud alpha workload-identity-pools evaluations create` with the `--schedule` flag to run posture checks daily or weekly, integrating results into your existing security information and event management (SIEM) workflows.

### What types of custom security controls can I implement with Rego rules?

The [`general-best-practices.md`](https://github.com/google/skills/blob/main/general-best-practices.md) catalog supports custom Rego policies for organization-specific requirements. Common implementations include enforcing mandatory resource labels (such as `owner` or `cost-center`), restricting VM instances from using external IP addresses, requiring specific encryption keys for Cloud Storage buckets, and validating that Cloud SQL instances have private IP connectivity enabled.

### How does the checklist address the shared responsibility model?

The validation questions in [`skills/cloud/google-cloud-waf-security/SKILL.md`](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-waf-security/SKILL.md) explicitly map controls to customer responsibilities versus Google-managed services. For example, the checklist verifies customer-side IAM configurations and data encryption key management while acknowledging Google's responsibility for physical infrastructure security, helping teams understand exactly which security tasks they must implement versus which are handled by the platform.