馃攳
Google Data Center Security: 6 Layers Deep - YouTube
Channel: Google Cloud Tech
[0]
[upbeat music]
[7]
Wong: Hi, I'm Stephanie Wong,
and I work for Google Cloud.
[10]
While I could talk all day
about cloud security,
[13]
physical security
at a Google data center
[15]
is still pretty new to me,
[16]
so today I'm on a mission
to learn all about it
[19]
by taking an inside look
at the systems in place
[22]
that protect customer data
[23]
at a typical Google data center.
Let's go.
[25]
[upbeat music]
[28]
Now, I've been told there are six layers
of security here.
[31]
Security layer one refers
to the property boundaries,
[34]
and that includes signage and fencing.
[37]
But things really start
to get interesting
[38]
when it comes to layer two,
also known as the secure perimeter,
[42]
and that includes the main entrance gate
which I am pulling up to right now.
[46]
[upbeat music]
[49]
Hey, how's it going?
person: Good morning.
[51]
[upbeat music]
[58]
Wong: So layer two has
a lot of security features
[61]
ranging from smart fencing
to overlapping cameras
[64]
to 24/7 guard patrols and more.
[67]
I'm on my way to meet some experts
[69]
who are going to show me
how it all works.
[73]
Hi, Joe.
[73]
Kava: Hi, Stephanie, how are you?
[75]
Wong: So I just passed the main gate
and I saw guards and cameras,
[78]
but what are some things
that I didn't see?
[80]
Kava: Yeah there's actually
a lot of technology
[82]
and operations
going on behind the scene.
[84]
So from the time that you're on site,
[86]
we know that you're here,
[87]
and we're able to do
correlation analysis
[90]
of where you've been.
[91]
We have guards in vehicles,
we have some guards on foot.
[94]
There's also the vehicle crash barrier.
[97]
That's designed to stop
a fully loaded truck
[99]
from crashing
through the front entrance.
[102]
Wong: Ricky, Tarik, can you tell me more
about what's unique about the fencing?
[105]
Gordon: This particular fence
is an anti-climb fence.
[108]
It's also equipped with fiber.
The technology tells us
[112]
if someone's near the fence
or touches the fence.
[115]
Billingsley: So we use thermal cameras
and standard cameras.
[117]
So we're able to see
video footage at night
[120]
just as clearly as we can
during the day.
[123]
[light electronic music]
[127]
Wong: Welcome to layer three,
building access.
[130]
But just so you know,
I am still nowhere near
[132]
the data center floor.
[134]
That's a few more layers deep.
Let's head inside.
[137]
O'Brien: Stephanie.
Wong: Hello.
[138]
O'Brien: So you've gotten through
the gate, you've come in,
[140]
you've come in to our secure lobby.
[141]
You have your card,
and we know that that's you,
[144]
but if someone happened to lose
their card,
[146]
what we want to make sure is
that it's actually Stephanie
[149]
who has shown up.
[150]
scanner: Please center your eye.
[152]
O'Brien: And with iris scan,
we can authenticate
[154]
that it's actually you
along with your ID.
[157]
Wong: Okay, I think it's good.
[161]
One thing that's a little
hard to get used to
[163]
when you visit a data center is,
[165]
for secure areas, only one person
[167]
is allowed to badge
through a door at a time.
[171]
[light electronic music]
[182]
Layer four includes
the security operations center,
[185]
or SOC, a hive of activity that
is monitoring the data center
[189]
24/7, 365 days a year.
[192]
[light electronic music]
[194]
So it sounds like we've been
keeping them very busy today.
[197]
Davis: Yes, yes you have.
[199]
So the doors, the cameras,
the badge readers,
[202]
the iris scan--
everything is connected here.
[204]
This is the brains
of the security system.
[207]
So if there's anything out
of the ordinary happening,
[210]
they have to be able to pick that up.
[212]
[upbeat music]
[220]
Wong: Interesting fact about layer five,
[221]
the data center floor:
[223]
less than 1% of Googlers
ever get to set foot in here.
[227]
So right now, I'm feeling kinda special.
[228]
[upbeat music]
[238]
Kava: This is truly
a as-needed only access area,
[242]
meaning that only the technicians
[244]
and engineers that have to be there
[246]
to maintain, upgrade,
or repair the equipment
[249]
are ever allowed there.
[252]
Wong: And do Googlers or anyone
have access to the data?
[255]
Kava: We have access to the devices,
but the data at rest
[258]
is encrypted,
and our customers can issue
[261]
and keep their own encryption keys,
[263]
and we do this because
protecting the privacy
[266]
and the security of our users' data
is our highest priority.
[271]
Wong: The mysterious layer six,
where disks
[274]
are erased and destroyed
and the fewest number of people
[277]
are allowed to enter.
[279]
Drives that need to be retired
from the data center floor
[281]
come into this room
through a secure two-way locker system
[285]
which means that only technicians
assigned to this room
[288]
can pull them
from that locker to either erase
[290]
or destroy them.
[292]
Henley: All right,
welcome to the crusher room.
[294]
Wong: Wow.
[295]
Henley: So at this point,
we have scanned the hard drive,
[297]
and the software has told us
that we need to destroy it.
[300]
Wong: Can we see it in action?
[301]
Henley: Back up.
Wong: All right.
[302]
I'll stay back here.
[both laugh]
[305]
[mechanical whirring]
[307]
That disk is definitely destroyed.
[309]
Henley: Yes it is.
[311]
[upbeat music]
[315]
Wong: If you didn't think
these six layers of security
[317]
were enough,
Google Cloud actually has
[320]
two security testing programs in place.
[322]
One hires companies to try to break in
[324]
to data center sites from the outside,
[327]
and the other tasks Googlers
with trying to break
[329]
security protocols from the inside.
[333]
And getting out of a data center
is arguably even harder
[337]
than getting in, as everybody
has to go through full metal detection
[341]
each time they leave
the data center floor.
[343]
[upbeat music]
[346]
person: Thank you, ma'am,
for your cooperation.
[347]
Wong: Thank you.
[349]
Google Cloud supports compliance
[351]
with over 40 global standards,
regulations, and certifications,
[355]
and the commitment to constantly test,
optimize, and improve systems
[359]
makes it a leader
in data center security.
[362]
Now, how do I get out of here?
[364]
[upbeat music]
Most Recent Videos:
You can go back to the homepage right here: Homepage





