VMware Cloud Well-Architected Framework for Google Cloud VMware Engine: Shared Responsibility Model
VMware Cloud Shared Responsibility
A shared responsibility model is common among the different VMware Cloud Infrastructure Service providers, which defines distinct roles and responsibilities between the VMware Cloud Infrastructure Services provider and an organization consuming the service.
Disclaimer: The intent of this document is to provide guidance and best practices for VMware Cloud Infrastructure Service providers regarding the shared responsibilities of the service.
Google Cloud VMware Engine
Google Cloud VMware Engine implements a shared responsibility model that defines distinct roles and responsibilities of the parties involved in the offering: the Customer and Google.
Responsibilities
Customer Responsibility: Security in the Cloud
Customers are responsible for the deployment and ongoing configuration of their SDDC, virtual machines, and data that reside therein. In addition to determining the network, firewall, and VPN configuration, customers are responsible for managing virtual machines (including guest security and encryption) and using Google Cloud Platform IAM Roles and Permissions along with vCenter Roles and Permissions to apply the appropriate controls for users.
Google Responsibility: Related to Google Cloud VMware Engine: Security of the Cloud
Google is responsible for securing the software that makes up the Google Cloud VMware Engine service. This software infrastructure is composed of the compute, storage, and networking software comprising the private cloud, and the software that interfaces with these infrastructure services. Google is also responsible for the physical facilities, physical security, infrastructure, and underlying hardware for the entire service.
Google Responsibility related to Google Infrastructure: Security of the Infrastructure
Shared Responsibility Matrix
The following is not an exhausted list of responsibilities but encompass the most frequent tasks and definitions. For further information, please contact Google.
Entity |
Responsibility/Activity |
Customer |
|
Google – Google Cloud VMware Engine |
|
Google – Google Cloud VMware Engine Infrastructure |
|
In the next section, learn about the different considerations for managing infrastructure and application services.