Shared Responsibility Model for IBM Power for Google Cloud

IBM Power for Google Cloud is an Infrastructure-as-a-Service offering provided by Converge on the Google Cloud Marketplace. It provides compute, storage and network services on demand with a capacity based pricing model and provides high performance, low latency connectivity to Google Cloud services. The Cloud service requires the customer to operate their own Google Cloud Organization and connect to IBM Power for Google Cloud using Google Private Services Access.

IBM Power for Google Cloud segments the service management (control plane) and the data access (data plane) across different endpoints so that neither can impact the other to provide a secure architecture. The IBM Power for Google Cloud control plane consists of the Web Console, pcloud CLI, and API, all managed by Converge. The data plane uses the Google Cloud private services access (PSA) framework to connect the dedicated IBM Power for Google Cloud Instance to a customer Google Organization.

Each IBM Power for Google Cloud customer is allocated a dedicated Service Producer VPC Network and Service Producer Project managed by Converge. Strong tenant isolation is maintained into the IBM Power for Google Cloud infrastructure with isolated L2 and L3 network domains per customer and a multi-tenant compute hypervisor and storage architecture.

Encryption

IBM Power for Google Cloud block storage Volumes are encrypted at rest using AES-256 by default. Data is striped across a distributed array of disks for performance and durability. Encryption keys are managed by IBM Power for Google Cloud and rotated automatically. Customers who would like to manage their own encryption keys must configure operating system or application based encryption in addition to the storage encryption provided by IBM Power for Google Cloud.

The IBM Power for Google Cloud (IP4G) network fabric provides private network connectivity between Virtual Machines in IBM Power for Google Cloud and Google Cloud. All IP4G network traffic traverses physical connections in a Google Cloud Regional Extension datacenter. Network traffic from IBM Power for Google Cloud to Google Cloud traverses a private Google Cloud connection between a Google Cloud Regional Extension data center and Google Cloud. We expect customers to enable secure communication protocols for applications to encrypt data in transit between IP4G and Google Cloud and internal networks in IP4G. All data transferred during Live Partition Mobility is encrypted in transit for IBM Power for Google Cloud.

Datacenter Access

Customers and end-users do not have physical access to the datacenters or hardware where IBM Power for Google Cloud is hosted. All physical access control, visitor management, badge authorization, and on-site maintenance activities are exclusively managed by Converge and its facility partners.

The controls governing physical datacenter security, environmental protection, and hardware operations are audited as part of the platform’s compliance with SOC 2 Type II and the Payment Card Industry Data Security Standard (PCI DSS). Customers can leverage the IBM Power for Google Cloud SOC 2 Type II report and the PCI DSS Attestation of Compliance (AOC) to satisfy compliance requirements and exclude physical datacenter controls from their direct audit scope.

Shared Responsibility

IBM Power for Google Cloud provides an API, CLI, and Web Console that allows the customer to create, delete and modify the compute, storage and networking of their IBM Power for Google Cloud Instance. The customer must authorize users to access these interfaces and it is the responsibility of the customer to ensure the appropriate Google Cloud Identities are permitted to the customer Cloud Instance.

The customer is responsible for configuring their Google Cloud organization to connect to the service.

As with any Infrastructure as a Service offering, the bulk of security responsibilities are placed on the customer to provision resources in a way that meets their regulatory and compliance requirements. Converge is responsible for the underlying infrastructure and physical security.

Responsibility Matrix

ResponsibilityCustomerIP4GDescription
UsageUsage associated with IBM Power for Google Cloud Subscription.
Access PolicyControl of IAM roles and policies that grant access to IBM Power for Google Cloud or applications on deployed virtual machines.
IdentityAuthentication to IBM Power for Google Cloud using Google Cloud Identity.
Network TrafficConfiguration of security controls for network access to virtual machine instances.
Operating SystemOperational responsibilities for operating system, data, and content.
DeploymentDeployment of IBM Power for Google Cloud virtual machines, volumes, networks and resources using the API, CLI, or UI.
PlatformAvailability and security of the IBM Power for Google Cloud API, CLI, and Web Console.
Audit Logslogging for IBM Power for Google Cloud platform events.
Physical StoragePhysical storage configuration, security, encryption and availability.
Physical ComputePhysical compute and hypervisor configuration, security and availability.
Physical NetworkPhysical network configuration, security, and availability.
Physical DatacenterDatacenter power, cooling, and security.