GOOGLE PLATFORM MONITORING OVERVIEW

© JointAction Group Pty Ltd 2023
Google Platform Monitoring Overview Rev 1  
August 2023

Introduction

The Etiscope Application is developed on Google Cloud Services (Firebase). Google manages the updates to Cloud Services security and applications in accordance with their policies. 

The effect of changes may unwittingly affect the Etiscope Application development. 

However, the final build of the App is released with the Apple App Store and therefore this DOES NOT affect users, only development of the application and storage of assessment data. 

JointAction Group’s development and Frontline team will monitor changes from Google and implement a process to maintain active product development. 


Objective 

To ensure changes brought about by Google Cloud Services do not adversely affect the operation of the Etiscope Application developed in Jira and running on the Google Services platform within Google Cloud Services. 

Scope 

This Monitoring Process covers: 

  • Applications in Google Cloud Services 

  • Data in transit to and from Google Cloud services 

  • Data being processed by Cloud Functions 


Monitoring Components 

Subscription to Google Cloud Services Security Bulletins 
FrontLine Support and security officers subscribe to and monitor Google Cloud Services Security Bulletins for any patches or updates that may affect the application site. They shall report any potential or suspicious changes to the development team within 24 hours. 

Subscription to Cloud Services Release notes 
FrontLine Support and security officers subscribe to and monitor Google Release Notes for any patches or updates that may affect the application site and run platform. They shall report any potential or suspicious changes to the development team within 24 hours. 

Backup and Redundancy 
The application is backed up regularly in geographically distributed Google Cloud Storage buckets to ensure high availability and disaster recovery. 

Monitoring and Auditing 
We utilize Google Cloud Monitoring and Google Cloud Audit Logs to constantly monitor data access and system events. Alerts are set up to notify the admin team of any suspicious activity. 


Incident Response 

In the event of an update or change that is suspected or shown to affect the performance of the E􀆟scope Applica􀆟on, the Development team will roll back to legacy servers within the Google Cloud Services system while updates and changes to the applica􀆟on occur and complete the testing regime. 


Monitoring and Review 

This monitoring process is subject to regular reviews, including compliance audits. Any changes or updates will be documented and communicated to all stakeholders. 

Conclusion 

Our monitoring process is a comprehensive solution aimed at safeguarding our organisation's application development within Google Cloud Services. With the proper implementation of access controls, encryption, and monitoring tools, we aim to prevent loss and unauthorised access. 

This document is a living resource and will be updated as necessary to reflect changes in technology, compliance requirements, or threat landscapes.