SOC 2

服务和组织控制 (SOC) 2 报告是根据美国注册会计师协会 (AICPA) 审计准则委员会 SSAE 18 制定的报告,旨在评估服务组织在安全性、可用性、处理完整性、机密性或隐私性方面与信托服务标准相关的控制措施。

想要查看 Google Cloud 和 Google Workspace SOC 2 报告?客户可以在方便时通过合规报告管理器索取这些报告。

Google Cloud 和 SOC 2 合规性

访问 Google Cloud 的 SOC 2 报告

Google Cloud 会定期接受第三方审核,审核与本标准相关的产品、系统和基础设施。SOC 2 报告由客观第三方生成,旨在证明 Google Cloud 就其为保护客户数据而采取的控制措施所做的一系列声明。审核公司的评估工作包括在审核期内对控制措施的设计和实施有效性进行全面测试。

客户可以使用 SOC 2 报告来评估在此期间与所评估的 Google Cloud 和 Google Workspace 系统交互产生的风险。

Google Cloud 的 SOC 2 时间表

Google Cloud Core 和 Google Workspace SOC 2 报告

Google Cloud Core 和 Google Workspace SOC 2 Type II 报告每季度发布一次,可通过合规报告管理器下载。这些报告的审核期和发布日期如下:

  • 第一季度
  • 审核期:XX 年 2 月 1 日 - X1 年 1 月 31 日
  • 预计发布日期:3 月下旬
  • 第二季度
  • 审核期:XX 年 5 月 1 日 - X1 年 4 月 30 日
  • 预计发布日期:6 月下旬
  • 第三季度
  • 审核期:XX 年 8 月 1 日 - X1 年 7 月 31 日
  • 预计发布日期:9 月下旬
  • 第四季度
  • 审核期:XX 年 11 月 1 日 - X1 年 10 月 31 日
  • 预计发布日期:12 月下旬

其他 Google Cloud SOC 2 报告

我们会针对一小部分 Google Cloud 产品分别发布 SOC 2 Type II 报告,包括 Actifio Heritage、Apigee Edge、AppSheet、裸金属解决方案、Bare Metal HSM、BigQuery Omni、Google Cloud NetApp Volumes、Google Cloud VMware Engine、Google Distributed Cloud connected、StratoZone 和 Mandiant。这些报告每年或每半年发布一次,客户可以联系销售人员支持团队来获取这些报告。

过渡函

过渡函是由服务提供商(本例中为 Google Cloud)的管理层出具的证明,旨在“弥合”SOC 报告结束日期与客户报告期结束日期之间的时间差。过渡函旨在总结在最新的 SOC 报告期结束日期之后,在内部控制环境中发现的重大变化或问题。 过渡函仅适用于 SOC 1 和 SOC 2 报告。

Google Cloud 每月都会创建过渡函,其中每个过渡函都旨在涵盖自最近一次 SOC 报告以来的时段。例如,Google Cloud 在 1 月初发出了过渡函,涵盖 11 月 1 日至 12 月 31 日的回溯期,延长了之前发布的 SOC 报告的涵盖期,其中包含报告期结束日期 10 月 31 日。

可在合规报告管理器上查看 Google Cloud Core 和 Google Workspace SOC 2 报告的 SOC 过渡函(报告期结束日期为 3 月 31 日、6 月 30 日、9 月 30 日和 12 月 31 日),且可直接下载。如果需要提供涵盖不同报告期结束日期或产品范围的过渡函,请与销售人员支持团队联系。

常见问题解答

Google Cloud 的独立审核机构为 Ernst &Young LLP 和 Coalfire。

SOC 2 Type I 报告涵盖了服务组织在特定时间点的控制措施设计。SOC 2 Type II 报告涵盖了服务组织控制措施在一段时间内的设计和实施有效性。例如,SOC 2 Type I 可以评估服务组织截至当天的控制措施,而 SOC 2 Type II 评估服务组织在过去六个月内采取的控制措施。Google Cloud 仅发布 SOC 2 Type II 报告。

范围内的服务

以下是符合 SOC 2 标准的 Google Cloud 服务。

我们简化了部分服务的名称,但也以括号形式列出了其旧名称。


人工智能 (AI) 和机器学习 (ML)

Agent Assist

Gemini Enterprise Agent Platform 上的智能体对话(原 Vertex AI Conversation)

Gemini Enterprise Agent Platform 上的 Agent Search(原 Vertex AI Search)

AI Platform Deep Learning Container

反洗钱 AI

AutoML Tables

Cloud Natural Language API

Cloud Speaker ID

Cloud Translation

Cloud Vision

Contact Center as a Service (CCaaS)

Conversational Agents(原 Dialogflow

CX Agent Studio

CX Insights(原 Conversational Insights

Database Center

Document AI

Document AI Warehouse

订餐 AI 智能体

Gemini Code Assist

Gemini Enterprise(含 Agentspace)

Gemini Enterprise Agent Platform Colab Enterprise (Vertex AI Colab Enterprise)

Gemini Enterprise Agent Platform(原 Vertex AI Platform)

Gemini Enterprise Agent Platform Workbench 实例(原 Vertex AI Workbench 实例)

Gemini Enterprise for Customer Experience(原对话式 AI 和 Contact Center AI)

适用于 Google Cloud 的 Gemini

Gemini in BigQuery

Gemini Enterprise Agent Platform 上的生成式 AI(原 Vertex AI 上的生成式 AI)

NotebookLM for enterprise

Gemini Enterprise Agent Platform 上的 Ray(原 Vertex 上的 Ray)

Recommendations AI

Retail Search

Speech-to-Text

Talent Solution

Text-to-Speech

Video Intelligence API


应用编程接口 (API) 管理

Advanced API Security

API Gateway

Apigee

Application Integration

Cloud Endpoints

Integration Connectors


计算

App Engine

Batch

Compute Engine

Managed Lustre

Workload Manager


数据分析

BigQuery

BigQuery Omni

Cloud Data Fusion

Data Catalog

数据洞察(原 Looker Studio)

Dataflow

Dataform

Dataproc Metastore

Google Cloud Managed Service for Apache Kafka

Knowledge Catalog(原 Dataplex)

Looker (Google Cloud Core)

Managed Service for Apache Airflow(原 Cloud Composer)

Managed Service for Apache Spark(原 Dataproc)

Pub/Sub


数据库

AlloyDB

Bigtable

Cloud Spanner

Cloud SQL

Datastore

Firestore

Memorystore


开发者工具

Artifact Analysis

Artifact Registry

Cloud Build

Cloud Source Repositories

Cloud Workstations

Developer Connect

Firebase Test Lab

Google Cloud Deploy

Google Cloud SDK

Infrastructure Manager

Secure Source Manager


医疗保健和生命科学

Cloud Healthcare API(原 Cloud Healthcare)

Healthcare Data Engine (HDE)


混合云和多云端

Config Connector

Config Controller

Connect

GKE Config Sync(原 Config Sync)

GKE 身份认证服务

Google Kubernetes Engine

Hub

Knative serving

Policy Controller

Service Mesh


管理工具

App Hub

Cloud 控制台应用

Cloud 控制台平台

Cloud Deployment Manager

Cloud Shell

Recommender

Service Infrastructure


媒体和游戏

媒体 CDN

Transcoder API

Video Stitcher API


迁移

BigQuery Data Transfer Service

Database Migration Service

Migrate to Virtual Machines

Migration Center

Storage Transfer Service


网络

Cloud CDN

Cloud DNS

Cloud Interconnect

Cloud Intrusion Detection System (Cloud IDS)

Cloud Load Balancing

Cloud NAT(网络地址转换)

Cloud Next Generation Firewall (Cloud NGFW)

Cloud Router

Cloud Service Mesh

Cloud VPN

Firebase App Hosting

Google Cloud Armor

Network Connectivity Center

Network Intelligence Center

Network Security Integration

Network Service Tiers

Secure Web Proxy (Cloud SWP)

Service Directory

Spectrum Access System

Traffic Director

Virtual Private Cloud (VPC)


操作

Backup and DR Service

Cloud Logging 

Cloud Monitoring 

Cloud Profiler

Cloud Trace

Personalized Service Health


安全和身份

Access Approval

Access Context Manager

Access Transparency

Assured Workloads

Audit Manager

Binary Authorization

Certificate Authority Service

Certificate Manager

Chrome 企业进阶版

Cloud Asset Inventory

Cloud Domains

Cloud External Key Manager (Cloud EKM)

Cloud Functions for Firebase

Cloud HSM(硬件安全模块)

Cloud Key Management Service (KMS)

Cloud 配额

Cloud Run

Cloud Run Functions(原 Cloud Functions)

Cloud Scheduler

Cloud Tasks

网络保险中心(原 RIsk Manager)

DataStream

Eventarc

Firebase App Check

Firebase Authentication

Google Security Operations (SIEM)

Google Security Operations (SOAR)

Google Threat Intelligence

Google Security Operations 的 GTI

Identity & Access Management (IAM)

Identity Platform

Identity-Aware Proxy (IAP)

Key Access Justifications (KAJ)

Microsoft Active Directory (AD) 托管服务

Model Armor

Organization Policy Service(原 Cloud 组织政策)

Privileged Access Manager

reCAPTCHA Enterprise

Resource Manager(原 Resource Manager API)

SecLM

Secret Manager

Security Command Center

Sensitive Data Protection(包括 Cloud Data Loss Prevention)

无服务器计算

VirusTotal

VPC Service Controls

Web Risk API

Workflows


存储

Backup for GKE

Cloud Storage

Cloud Storage for Firebase

Filestore

Google Cloud NetApp Volumes (GCNV)

Parallelstore

Persistent Disk


Firebase

Firebase A/B Testing

Firebase AI Logic

Firebase App Distribution

Firebase Cloud Messaging

Firebase 控制台

Firebase Crashlytics

Firebase Data Connect

Firebase Dynamic Links

Firebase Hosting

Firebase In-App Messaging

Firebase Machine Learning (ML)

Firebase Performance Monitoring

Firebase Realtime Database

Firebase Registry

Firebase Remote Config

Firebase Rules

Gemini in Firebase


其他

Cloud Billing

Earth Engine

Google Cloud Marketplace

Google Cloud Skills Boost

Google Cloud VMware Engine (GCVE)

SaaS 运行时

Tables

相关产品和服务

Access Transparency

当 Google Cloud 管理员访问您的内容时,Access Transparency 可近乎实时地为您提供记录其操作的日志。

了解详情

Cloud Key Management Service

使用与本地部署时相同的方式为云服务管理加密密钥,以保护您存储在 Google Cloud 中的 Secret 和其他敏感数据。

了解详情

Google Cloud Armor

利用 Google 的全球基础架构和安全系统,大规模防御针对基础架构和应用的 DDoS 攻击。

了解详情

Security Command Center

让您可以在一个地方集中预防和检测虚拟机、网络、应用和存储空间中的安全威胁,并采取相应措施以避免造成损害或损失。

了解详情

Sensitive Data Protection(包括 Cloud Data Loss Prevention)

让您能够快速、规模化地对姓名、信用卡号、Google Cloud 凭据等敏感数据元素进行分类和隐去。

了解详情

VPC Service Controls

通过定义 Google Cloud 资源(例如 Cloud Storage 存储桶、Bigtable 实例和 BigQuery 数据集)的安全边界,确保敏感数据的私密性。

了解详情

更进一步

获享 $300 赠金以及 20 多种提供“始终免费”用量的产品,开始在 Google Cloud 上构建项目。

Security