The security in “Bring Your Enterprise on Cloud” topic is a very hug job. But it’s implementation is not impossible. This topic is based on the related links.
The conceptual check list for security is as follows
Enterprise Infrastructure Security
- Network security
- Data encryption
- Key and secret management
- Identity & Access Management
- Duty segregation
- Least Privileges
- Zero trust
- Defense in depth
- Platform policies
- Vulnerability check/management
- Compliance Monitoring
Enterprise Application Security
- Database
- Storage
- Container image registry
- Container service
- Kubernetes service
- Serverless functions
- App Service
- Queue services
- Event services
- Cache services
- Load balancers
- CDN services
- VMs
- VM Disks
Approach
These are the topics, which must be considered in “Bring Your Enterprise on Cloud” topic. In the following links I’ll provide an exact check list based on cloud provider.
To make the job easier it’s better to go through the conceptual check list in a layered way as demonstrated in the sample below. This can help to do the job Agile.
Layer 1: We explain how should be e.g. the network.
Layer 2: We explain how we can have e.g. a resilient network (we decide which platform service or a 3th party service or tool can to realize it)
Layer 3: We explain how we can have e.g. a high available network (we decide which platform service or a 3th party service or tool can to realize it)
Layer 4: We can add layers if we need more
Network
Resilient
High Available
Key/ Secret management
Resilient
High Available
Identity & Access Management
Resilient
High Available
I think the following items have to be considered in the enterprise infratructure security: security principels, Ransomeware on cloud, patch management, Technical states, pentesting, Security of information and events
LikeLike