The following guidelines for the minimum viable security platform align with the organization security pillar.
Intermediate level guidelines
After you implemented the basic guidelines, implement the following organization guidelines.
| Item | Restrict authorized principals |
|---|---|
| Description | Ensure only identities from your organization are allowed in your Google Cloud environment. Use the Domain restricted sharing ( These constraints help prevent employees from granting access to external accounts outside of your organization's control that don't follow your security policies for multifactor authentication (MFA) or password management. This control is critical for preventing unauthorized access, ensuring that only trusted, managed corporate identities can be used. |
| Related information | |
| Item ID | MVSP-CO-1.21 |
| Mapping |
Related NIST-800-53 controls:
Related CRI profile controls:
Compliance Manager control: |
Advanced level guidelines
After you implemented the intermediate guidelines, implement the following organization guidelines.
| Item | Restrict resource locations |
|---|---|
| Description | The Resource Location Restriction ( This constraint lets your organization enforce that your resources and data are only created and saved in specific, approved geographic regions. |
| Related information | |
| Item ID | MVSP-CO-1.22 |
| Mapping |
Related NIST-800-53 controls:
Related CRI profile controls:
|
| Item | Restrict resource service usage |
|---|---|
| Description | The This constraint lets your organization create an allowlist of approved services, which helps prevent employees from using unvetted services. |
| Related information | |
| Item ID | MVSP-CO-1.23 |
| Mapping |
Related NIST-800-53 controls:
Related CRI profile controls:
Compliance Manager control: |