It's also important to understand that security is more than just firewall rules or encryption. Google needs to adhere to global regulations and third-party certifications. Examples of the regulations that GCP adheres to can be found on their web page at https://cloud.google.com/security/compliance/#/. It is recommended that you review this page to familiarize yourself with the various standards that should be met. Some of these will be well known, for example, regulations from the financial industry such as PCI DSS or ISO 27017 address who is responsible for interactions between cloud vendors and customers.
In this section, we will look at PCI compliance and the shared responsibility model.