이 페이지의 일부 또는 모든 정보는 Trusted Cloud by S3NS에 적용되지 않을 수 있습니다. 자세한 내용은
Google Cloud와의 차이점 을 참조하세요.
보안된 시작 영역 역할 및 권한
참고: 이 표의 일부 또는 전체 역할과 권한은 Trusted Cloud에 적용되지 않습니다.
이 페이지에는 보안 시작 영역의 IAM 역할과 권한이 나와 있습니다. 모든 역할과 권한을 검색하려면 역할 및 권한 색인 을 참조하세요.
보안 시작 영역 역할
Role
Permissions
(roles/securedlandingzone.bqdwOrgRemediator
)
Access to modify (remediate) resources in SLZ BQDW Blueprint at Organization.
accesscontextmanager.servicePerimeters.get
accesscontextmanager.servicePerimeters.list
accesscontextmanager.servicePerimeters.update
(roles/securedlandingzone.bqdwProjectRemediator
)
Access to modify (remediate) resources in SLZ BQDW Blueprint at Project.
bigquery.datasets.get
bigquery.datasets.getIamPolicy
bigquery.datasets.setIamPolicy
bigquery.datasets.update
cloudkms.cryptoKeys.get
cloudkms.cryptoKeys.getIamPolicy
cloudkms.cryptoKeys.list
cloudkms.cryptoKeys.setIamPolicy
cloudkms.cryptoKeys.update
cloudkms.keyRings.getIamPolicy
cloudkms.keyRings.setIamPolicy
pubsub.topics.get
pubsub.topics.getIamPolicy
pubsub.topics.list
pubsub.topics.setIamPolicy
pubsub.topics.update
resourcemanager.projects.update
serviceusage.services.use
storage.buckets.get
storage.buckets.getIamPolicy
storage.buckets.list
storage.buckets.setIamPolicy
storage.buckets.update
Overwatch Activator
Beta
(roles/securedlandingzone.overwatchActivator
)
This role can activate or suspend Overwatches
resourcemanager.projects.get
resourcemanager.projects.list
securedlandingzone.overwatches.activate
securedlandingzone.overwatches.suspend
Overwatch Admin
Beta
(roles/securedlandingzone.overwatchAdmin
)
Full access to Overwatches
resourcemanager.projects.get
resourcemanager.projects.list
securedlandingzone.*
securedlandingzone.operations.get
securedlandingzone.overwatches.activate
securedlandingzone.overwatches.create
securedlandingzone.overwatches.delete
securedlandingzone.overwatches.get
securedlandingzone.overwatches.list
securedlandingzone.overwatches.suspend
securedlandingzone.overwatches.update
Overwatch Viewer
Beta
(roles/securedlandingzone.overwatchViewer
)
This role can view all properties of Overwatches
resourcemanager.projects.get
resourcemanager.projects.list
securedlandingzone.operations.get
securedlandingzone.overwatches.get
securedlandingzone.overwatches.list
Secured Landing Zone Service Agent
(roles/securedlandingzone.serviceAgent
)
Grants Secured Landing Zone service account permissions to manage resources in the customer project
Warning: Do not grant service agent roles to any principals except
service agents .
cloudasset.assets.exportOrgPolicy
cloudasset.assets.exportResource
cloudasset.feeds.create
cloudasset.feeds.delete
cloudasset.feeds.update
logging.logEntries.list
pubsub.subscriptions.consume
pubsub.subscriptions.create
pubsub.subscriptions.delete
pubsub.topics.attachSubscription
pubsub.topics.create
pubsub.topics.delete
pubsub.topics.detachSubscription
pubsub.topics.getIamPolicy
pubsub.topics.setIamPolicy
resourcemanager.projects.get
securitycenter.assetsecuritymarks.update
securitycenter.findings.list
securitycenter.findings.update
securitycenter.sources.list
securitycenter.sources.update
serviceusage.services.use
보안 시작 영역 권한
권한
역할에 포함됨
securedlandingzone. operations. get
소유자 (roles/ owner
)
편집자 (roles/ editor
)
뷰어 (roles/ viewer
)
오버워치 관리자 (roles/ securedlandingzone.overwatchAdmin
)
오버워치 뷰어 (roles/ securedlandingzone.overwatchViewer
)
securedlandingzone. overwatches. activate
소유자 (roles/ owner
)
편집자 (roles/ editor
)
오버워치 활성자 (roles/ securedlandingzone.overwatchActivator
)
오버워치 관리자 (roles/ securedlandingzone.overwatchAdmin
)
securedlandingzone. overwatches. create
소유자 (roles/ owner
)
편집자 (roles/ editor
)
오버워치 관리자 (roles/ securedlandingzone.overwatchAdmin
)
securedlandingzone. overwatches. delete
소유자 (roles/ owner
)
편집자 (roles/ editor
)
오버워치 관리자 (roles/ securedlandingzone.overwatchAdmin
)
securedlandingzone. overwatches. get
소유자 (roles/ owner
)
편집자 (roles/ editor
)
뷰어 (roles/ viewer
)
오버워치 관리자 (roles/ securedlandingzone.overwatchAdmin
)
오버워치 뷰어 (roles/ securedlandingzone.overwatchViewer
)
securedlandingzone. overwatches. list
소유자 (roles/ owner
)
편집자 (roles/ editor
)
뷰어 (roles/ viewer
)
보안 관리자 (roles/ iam.securityAdmin
)
보안 검토자 (roles/ iam.securityReviewer
)
오버워치 관리자 (roles/ securedlandingzone.overwatchAdmin
)
오버워치 뷰어 (roles/ securedlandingzone.overwatchViewer
)
securedlandingzone. overwatches. suspend
소유자 (roles/ owner
)
편집자 (roles/ editor
)
오버워치 활성자 (roles/ securedlandingzone.overwatchActivator
)
오버워치 관리자 (roles/ securedlandingzone.overwatchAdmin
)
securedlandingzone. overwatches. update
소유자 (roles/ owner
)
편집자 (roles/ editor
)
오버워치 관리자 (roles/ securedlandingzone.overwatchAdmin
)
달리 명시되지 않는 한 이 페이지의 콘텐츠에는 Creative Commons Attribution 4.0 라이선스 에 따라 라이선스가 부여되며, 코드 샘플에는 Apache 2.0 라이선스 에 따라 라이선스가 부여됩니다. 자세한 내용은 Google Developers 사이트 정책 을 참조하세요. 자바는 Oracle 및/또는 Oracle 계열사의 등록 상표입니다.
최종 업데이트: 2025-08-25(UTC)
[[["이해하기 쉬움","easyToUnderstand","thumb-up"],["문제가 해결됨","solvedMyProblem","thumb-up"],["기타","otherUp","thumb-up"]],[["필요한 정보가 없음","missingTheInformationINeed","thumb-down"],["너무 복잡함/단계 수가 너무 많음","tooComplicatedTooManySteps","thumb-down"],["오래됨","outOfDate","thumb-down"],["번역 문제","translationIssue","thumb-down"],["샘플/코드 문제","samplesCodeIssue","thumb-down"],["기타","otherDown","thumb-down"]],["최종 업데이트: 2025-08-25(UTC)"],[],[],null,[]]