Third-party risk assessments
A third-party risk assessment or vendor risk assessment is often a requirement for many regulated customers who want assurance from Google Cloud about specific controls. An example of this would be a financial institution such as a bank that wants to host workloads on Google Cloud and needs Google Cloud to complete a vendor questionnaire. Google Cloud provides self-assessment questionnaires. These are complimentary documents that cover Google Cloud’s security controls and can help customers assess the security of their service. These self-assessments are available via Google Compliance Manager, which can be accessed here: https://packt.link/B15d7.
Some of the available assessments are as follows:
- Google Cloud’s Cloud Security Alliance (CSA) STAR self-assessment is available here: https://packt.link/rnqoe.
- The Standardized Information Gathering (SIG) core questionnaire can be accessed by customers to perform an initial assessment...