Supported compliance standards

Supported in:

This page lists the certifications, regulatory compliance frameworks, data residency boundaries, and security controls supported by Google SecOps.

Data residency and boundaries (DRZ)

Google SecOps provides Advanced Data Residency (DRZ) and sovereign data boundaries to ensure your data is stored and processed within specific geographic locations:

  • Regional data residency: For information about standard operating regions and data residency commitments, see Google SecOps Service Locations.
  • Sovereign and regional data boundaries: Most country-specific and regulatory data boundaries—such as Australia, Canada, EU, Israel, Japan, KSA, US, and healthcare data boundaries—are managed through Assured Workloads. For a complete list of supported control packages, see Assured Workloads supported products and filter by Google Security Operations SIEM (Chronicle SIEM) or the chronicle.googleapis.com API endpoint.

US public sector and government compliance

For US public sector and defense workloads, Google SecOps supports federal authorization boundaries and Department of Defense requirements:

  • Federal Risk and Authorization Management Program (FedRAMP): High and Moderate impact levels.
  • Department of Defense (DoD) Cloud Computing Security Requirements Guide: Impact Levels 2 (IL2), 4 (IL4), and 5 (IL5).

For authorization boundary status and regional availability across these programs, see FedRAMP and DoD compliance scope.

Industry and healthcare regulations

Google SecOps satisfies key regulatory standards for handling protected health information and payment card data:

  • Health Insurance Portability and Accountability Act (HIPAA): For customer responsibilities and covered products, see HIPAA compliance on Google Cloud.
  • Payment Card Industry Data Security Standard (PCI DSS): For details on PCI DSS compliance in Google Cloud, see PCI DSS compliance.

Security and data protection controls

For encryption key management and network security perimeters, Google SecOps provides dedicated configuration guides:

  • Customer-Managed Encryption Keys (CMEK): Encrypt data at rest using encryption keys that you manage in Cloud Key Management Service. For supported regions and setup instructions, see Configure CMEK.
  • VPC Service Controls (VPC-SC): Set up security perimeters around Google Cloud resources to prevent data exfiltration. For supported features and setup instructions, see Configure VPC Service Controls.

Need more help? Get answers from Community members and Google SecOps professionals.