compliance & risk management?

Overview

“In the cloud, a zero-trust approach can actually accelerate innovation”

Compliance and risk management is all about balancing ambition versus control. Ambition in this case translates to innovation. Teams need freedom to innovate, but laws, regulations and managing risks requires a measure of control. Freedom and control are at opposite ends of the spectrum. How do we strike a balance??

The risk appetite of the organisation must be weighed against the objective it’s trying to achieve. All within legal boundaries of course. From there, risks are managed through a control framework. Standards and regulations require controls on all levels: from geographical location and data centre management, to the use of protocol-versions, authentication and secrets management and encryption methods. Everything counts. The risks must be mapped out and mitigating measures put in place. The controls are necessary to ensure that things are done properly. It is imperative that the CISO continuously monitors whether the organisation is compliant and in control of the risks. ?

Cloud is complex in this regard because of the shared responsibility model. The CCoE will help by working closely with the CISO, ensuring tools and methods to mitigate the impact of security incidents are in place and applied. For instance, recommended security measures are included in blueprints and automated deployments of services. SaaS applications demand that providers prove what measures are in place.?

By adopting a zero-trust architecture risk assessment processes for solutions can be simplified, which will accelerate innovation significantly. ?

The CCoE gives recommendations on the use of cloud native or third-party tooling to generate security assessments and reports. Reports and assessments are used to initiate corrective actions in cooperation with the DevOps teams and SecOps.?

Strive for continuous compliance!

Activities checklist

Initial:

  • Determining applicable legislation, regulations and standards?
  • Determining the appropriate control frameworks?
  • Selecting policy compliance tooling?
  • Configuring security & compliance controls as provided by the CSP?
  • Developing with the CCOE a zero-trust architecture?
  • Describe requirements for SaaS providers

Recurring:

  • Formulating necessary measures, both technical and process-based?
  • Tailoring the risk process to the level the zero-trust architecture has been implemented?
  • Keeping track of relevant legislative changes and evaluating their impact?
    Keeping track of relevant changes in standards and evaluating their impact?
  • Assisting teams with assessing and solving security and  compliance reports (thereby continually increasing compliance scores)

RASCI

cloud consultantsupportingtransformation consultant
cloud architectconsultingcloud partnersconsulting
cloud security specialistresponsibleDevOps teaminformed
cloud developerinformedbusiness stakeholderinformed
cloud engineerarchitecture
cloud analystsecurityaccountable
product owner CCoEfinance
managementprocurement
Scroll to Top