Tetap teratur dengan koleksi
Simpan dan kategorikan konten berdasarkan preferensi Anda.
Akses dengan hak istimewa di Google Cloud
SistemGoogle Cloud dibuat dengan fokus untuk melindungi konten Anda
menggunakan kontrol dan pemantauan. Konten Anda yang disimpan di Google Cloud
merupakan milik Anda sepenuhnya. Terkadang, personel Google mungkin perlu mengakses
konten Anda, tetapi akses ini tidak pernah dilakukan tanpa justifikasi
bisnis yang valid.
Alasan personel Google meminta akses ke Data Pelanggan
Alasan paling umum mengapa personel Google meminta akses ke
Data Pelanggan adalah untuk menyelesaikan tiket dukungan pelanggan.
Jika Anda membuat permintaan dukungan pelanggan, personel Google mungkin
diperlukan untuk meminta akses ke data Anda. Transparansi Akses ada untuk memberikan visibilitas kepada pelanggan terkait akses ini. Google menyediakan berbagai kontrol
untuk mendukung kerahasiaan data Anda, terlepas dari apakah Transparansi Akses
diaktifkan di organisasi. Untuk informasi selengkapnya tentang kontrol ini, lihat
Ringkasan desain keamanan infrastruktur Google.
Apa yang dimaksud dengan akses dengan hak istimewa
Akses personel Google ke data Anda untuk memenuhi kewajiban penyediaan
layanan yang dikontrak disebut akses dengan hak istimewa. Akses ke data Anda
di Google Cloud biasanya karena alasan berikut:
Anda mengakses data Anda sendiri.
Layanan yang Anda gunakan mengakses data atas nama Anda.
Jika diminta untuk memberikan layanan yang dikontrak, personel Google yang bertindak sebagai
administrator dengan hak istimewa dapat mengakses data Anda.
Prinsip dasar pengelolaan akses dengan hak istimewa
Strategi pengelolaan akses dengan hak istimewaGoogle Cloudsecara ketat membatasi hal-hal yang dapat dilihat dan dilakukan oleh satu anggota staf Google dengan data Anda.Filosofi akses dengan hak istimewa Google Clouddidasarkan pada prinsip-prinsip berikut:
Hak istimewa terendah: Akses ke Data Pelanggan ditolak secara default untuk semua
personel Google. Jika diberikan, akses bersifat sementara dan tidak lebih besar dari
yang benar-benar diperlukan untuk menyediakan layanan yang dikontrak.
Membatasi akses tunggal ke data: Mengakses Data Pelanggan secara terpisah tanpa
adanya individu lain yang terlibat sangat sulit bagi setiap
personel Google.
Semua akses harus dibenarkan: Secara default, personel Google tidak memiliki akses ke Data Pelanggan. Petugas Google hanya dapat mengakses data Anda dengan
justifikasi bisnis yang valid dan aktif. Personel Google tidak dapat mengakses
Data Pelanggan untuk justifikasi yang ditutup atau jika personel Google
bukan kolaborator yang ditautkan secara langsung. Untuk daftar justifikasi
bisnis yang valid, lihat Kode alasan justifikasi.
Pemantauan dan pemberitahuan: Proses pemantauan dan respons ada untuk mengidentifikasi,
melakukan triase, dan memperbaiki pelanggaran terhadap prinsip-prinsip ini.
ProdukGoogle Cloud secara rutin menjalani audit dan sertifikasi pihak ketiga yang independen untuk memverifikasi bahwa praktik perlindungan datanya sesuai dengan kontrol dan komitmennya. Untuk informasi selengkapnya tentang cara Google Cloud produk
memberikan transparansi dan kontrol kepada pelanggan atas konten mereka, lihat
laporan resmi tentang Mempercayakan data Anda dengan Google Cloud.
Untuk mempelajari prinsip inti yang menjadi dasar kontrol yang mencegah akses administratif yang tidak sah, lihat Ringkasan kontrol akses administratif.
Untuk melihat daftar justifikasi bisnis yang dapat diminta oleh personel Google
untuk mengakses data pelanggan, lihat
Kode alasan justifikasi.
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-08-18 UTC."],[[["\u003cp\u003eGoogle personnel may require temporary access to customer content, but only with a valid business justification, such as resolving a customer support ticket.\u003c/p\u003e\n"],["\u003cp\u003ePrivileged access refers to Google personnel accessing customer data to fulfill a contracted service, which is strictly limited and managed.\u003c/p\u003e\n"],["\u003cp\u003eGoogle Cloud's privileged access management is based on principles such as least privilege, limiting singular access, requiring justification for all access, and employing monitoring and alerting.\u003c/p\u003e\n"],["\u003cp\u003eAccess to customer data is denied by default for Google personnel, and any granted access is temporary and no greater than what is absolutely necessary.\u003c/p\u003e\n"],["\u003cp\u003eGoogle Cloud undergoes third-party audits to ensure data protection practices align with their controls and commitments.\u003c/p\u003e\n"]]],[],null,["# Privileged access at Google Cloud\n=================================\n\nGoogle Cloud systems are built with a focus on protecting your content\nusing controls and monitoring. Your content stored on Google Cloud\ncompletely belongs to you. Occasionally, Google personnel might need to access\nyour content but these accesses are never without a valid business\njustification.\n\nWhy Google personnel request access to Customer Data\n----------------------------------------------------\n\nThe most common reason why Google personnel request access to\n[Customer Data](/terms/service-terms) is to resolve a customer support ticket.\nIf you create a customer support request, then a Google personnel might be\nrequired to request access to your data. Access Transparency exists to provide\ncustomers visibility into these accesses. Google provides various controls\nto support the private of your data, regardless of whether Access Transparency is\nenabled on an organization. For more information about these controls, see\n[Google infrastructure security design overview](/docs/security/infrastructure/design).\n\nWhat is privileged access\n-------------------------\n\nGoogle personnel's access to your data to fulfill an obligation of providing\na contracted service is called *privileged access*. Access to your data\nin Google Cloud is usually because of the following reasons:\n\n- You are accessing your own data.\n- A service you are using is accessing data on your behalf.\n\nWhen requested to provide a contracted service, Google personnel acting as a\nprivileged administrator can access your data.\n\nFoundational principles of privileged access management\n-------------------------------------------------------\n\nGoogle Cloud's privileged access management strategy strictly limits what a\nsingle Google staff member can view and do with your data. Google Cloud's\nprivileged access philosophy is based on the following principles:\n\n- **Least privilege**: Access to Customer Data is denied by default for all\n Google personnel. When access is granted, it is temporary and no greater than\n what is absolutely necessary to provide the contracted service.\n\n- **Limit singular access to data**: Singularly accessing Customer Data without\n another individual involved is extremely difficult for any and every\n Google personnel.\n\n- **All access must be justified** : By default, Google personnel don't have\n access to Customer Data. Google personnel can access your data only with an\n **active** , valid business justification. Google personnel can't access\n Customer Data for justifications that are closed or where the Google person is\n not a directly linked collaborator. For the list of valid business\n justifications, see [Justification reason codes](/assured-workloads/access-transparency/docs/reading-logs#justification-reason-codes).\n\n- **Monitor and alerting**: Monitoring and response processes exist to identify,\n triage, and remediate violations of these principles.\n\nFor more information about Google Cloud's privileged access philosophy, see\n[Privileged access in\nGoogle Cloud](/docs/security/privileged-access-management).\n\nGoogle Cloud products regularly undergo independent, third-party audits and\ncertifications to verify that their data protection practices match their\ncontrols and commitments. For more information about how Google Cloud products\nprovide customers with transparency and control over their content, see the\nwhitepaper on [Trusting your data with Google Cloud](https://services.google.com/fh/files/misc/072022_google_cloud_trust_whitepaper.pdf).\n\nWhat's next\n-----------\n\n- To know more about Google Cloud's commitment toward protecting the privacy\n of Customer Data, see\n [Google Cloud and common privacy principles](/privacy/common-privacy-principles).\n\n- To learn about the core principles upon which controls that prevent\n unauthorized administrative access are based, see\n [Overview of administrative access controls](/assured-workloads/cloud-provider-access-management/docs/administrative-access).\n\n- To see the list of business justifications for which Google personnel can\n request to access customer data, see\n [Justification reason codes](/assured-workloads/access-transparency/docs/reading-logs#justification-reason-codes)."]]