SlideShare uma empresa Scribd logo
1 de 32
<Title>
Cloud Governance w/ the
CAF governance model
Governing Cloud
Adoption
Plan
Rationalize Digital Estate
Prioritize and create action plan
Define and implement org and
skills Readiness
Ready
Implement Azure
readiness guidelines
Create Azure landing zone
Implement best practices
Define Strategy
Understand Motivations
Business outcomes
Business justification
Migrate
• Migration consideration
• Migration Guide
• Expanded Scope
• Best Practices
Innovate
• Innovation considerations
• Innovation Guide
• Expanded Scope
• Best Practices
Adopt
Govern
Cost management • Identity Baseline
Security Baseline • Resource Consistency
Deployment Acceleration
Manage
Org Management
Change Management
Ops Management
Microsoft Cloud Adoption Framework for Azure
http://aka.ms/cloudadoptionframework
http://aka.ms/caf/gov/access
The major drivers for
IT governance
Keep risk at acceptable levels
Maintain availability to systems
and services
Consistently apply policy and
audit compliance
Protect customer data
Business Returns
IT must rapidly produce measurable
business returns to stay relevant
Transformation
Evolving how businesses operate and
interact with the market
Modernization
Improving customer and employee
experiences
Business Transformation enabled by Cloud
Technologies
Key Business Drivers
Growth
Scaling products and services to meet
ever growing business needs
Control &
Stability
Speed &
Results
Assess current state and future state to
establish a vision for applying the framework
Benchmark2
Establish a Minimally Viable Product (MVP) to
serve as a foundation for governance
MVP3
How Do I Get Started?
Frame the conversation to mitigate tangible
business risks through consistent governance
Framework1
Mature with each release to align Cloud
Adoption and existing IT functions
Evolve4
Framing a Collaborative
Governance Conversation
Assess current state and future state to
establish a vision for applying the framework
Assess2
Establish a Minimally Viable Product (MVP) to
serve as a foundation for governance
MVP3
Frame the conversation to mitigate tangible
business risks through consistent governance
Framework1
Mature with each release to align Cloud
Adoption and existing IT functions
Evolve4
CAF Governance Model
Governance End State that fosters trust and builds confidence
Incremental Governance Execution
DON’T build the Governance End State
Making Governance Actionable with Native Tools
• Azure Blueprints
• Azure Policy
• Azure Cost
Management
• Azure Advisor
• Azure Portal
• Azure EA Content
Pack
• Azure Blueprints
• Azure Policy
• Azure Security Center
• Azure Sentinel
• Subscription Design
• Encryption
• Hybrid Identity
• Azure Networking
• Azure Automation
• Azure Blueprints
• Azure Policy
• Azure Monitor
• Azure Advisor
• Resource Manager
Templates
• Resource Graph
• Management Groups
• Azure Blueprints
• RBAC
• Azure AD
• Azure AD B2B
• Azure AD B2C
• Directory Federation
• Directory Replication
• Azure Blueprint
• Azure Policy
• Resource Grouping
& Tagging
• Resource Manager
Templates
• Azure Advisor
• Azure DevOps
• Azure Site Recovery
• Azure Backup
• Azure Automation
Azure Monitor
Integrating 3rd Party Tools
Cost Management 3rd
parties
• HashiCorp Terraform
Security baseline 3rd
parties
• Splunk
• HashiCorp Vault
Discovery,
onboarding, and
recovery 3rd parties
• ServiceNow
• HashiCorp Terraform
3rd party identity
providers
• HashiCorp Vault
Deployment 3rd
parties
• Nagios
• HashiCorp Terraform
• devops tools like
Chef, Puppet, Zabix
Monitoring 3rd parties
• OpsCompass
Release
Predict, don’t guess
We could make educated guesses about future, milestone risks. We can accurately predict those risks per release.
Release Release Release Release Milestone
Release composition
Each release represents a continuum of activities from
planning to completion. Releases often span multiple
iterations of effort or sprints.
During planning, the team should be able articulate a fairly
accurate description of the assets involved, workload
criticality, data classification, deployment approach, and
budget. These may change in the release, but are close
enough for a safe governance prediction.
Release
Governance Evolution
The Cloud Governance Team then asks deeper questions to establish a governance release plan.
Governance Integration
During release planning, the Cloud Governance Team seeks
to understand the release plan, so they can better
integration.
The following high level questions can help:
• When will this release be completed?
• What risks are introduced by this plan?
• What needs to change to mitigate the new risks?
Release
Plan
Will application criticality in this release impact
policies regarding IT Operations or Cloud
Operations?
Will data classifications in this release impact
policies regarding IT Security?
Will the suggested deployment impact pricing,
planned spend, or cloud budget?
Will the application requirements impact identity
policies or implementation?
Will any of these answers impact configuration
management implementations or require the
implementation of new corporate policies?
Assessing Next Steps
Assess current state and future state to
establish a vision for applying the framework
Benchmark2
Establish a Minimally Viable Product (MVP) to
serve as a foundation for governance
MVP3
How Do I Get Started?
Frame the conversation to mitigate tangible
business risks through consistent governance
Framework1
Mature with each release to align Cloud
Adoption and existing IT functions
Evolve4
Understand the
business vision driving
cloud adoption
Priorities and Current
State
Evaluating
current state
Security management
appears to be an
important area of focus
for this customer.
Building a governance MVP
Assess current state and future state to
establish a vision for applying the framework
Benchmark2
Establish a Minimally Viable Product (MVP) to
serve as a foundation for governance
MVP3
How Do I Get Started?
Frame the conversation to mitigate tangible
business risks through consistent governance
Framework1
Mature with each release to align Cloud
Adoption and existing IT functions
Evolve4
What and Why of Governance MVP
The basic foundation of all governance practices
2. Subscriptions: To group similar
resources into logical collections
3. Resource Groups: To further group
applications or workloads into deployment
and operations units
1. Management Groups:
To reflect security,
operations and
business/accounting
hierarchies
Sound Governance starts with resource organization strategies.
CRUD
Azure Resource Manager
Query
Starting point for Governance MVP
2. Policy-based Control: Real-time
enforcement, compliance assessment and
remediation at scale
3. Resource Visibility: Query, explore &
analyze cloud resources at scale
1. Environment Factory:
Deploy and update cloud
environments in a
repeatable manner using
composable artifacts
Role-based
Access
Policy
Definitions
Resource
Manager
Templates
Management Groups
Subscriptions
Resource Groups
Building the right MVP
Building the right MVP
• Create the Subscription and Management Group, adhering to the naming standards and hierarchy decisions.
• Create an Azure Blueprint name “Governance MVP”. Azure Resource Management templates and Azure Policy will
be created and added to the Blueprint as assets.
• Enforce RBAC requirement for the subscription in the Blueprint
• Create an Azure Resource Manager Template for a VPN Gateway (To be used as needed)
• Create an Azure Policy to apply or enforce the following:
• Resource Tagging should require values for Business Function, Data Classification, Criticality, SLA, Environment,
and Application.
• Resource Grouping per Application Archetype should align to the application tag
• Software Defined Network if the environment lists the Environment tag as DMZ (Demilitarized Zone), ensure
the proper VPN is configured
• Identity validate role assignments for each resource group and resource
• Nether logging, reporting, nor encryption require a policy at this time
Microsoft is here to help
Evolve Cloud Governance
Assess current state and future state to
establish a vision for applying the framework
Benchmark2
Establish a Minimally Viable Product (MVP) to
serve as a foundation for governance
MVP3
How Do I Get Started?
Frame the conversation to mitigate tangible
business risks through consistent governance
Framework1
Mature with each release to align Cloud
Adoption and existing IT functions
Evolve4
Take Action
Assessment Link
CAF Governance Journeys
and MVP Design
Thank you

Mais conteúdo relacionado

Mais procurados

AWS Cloud Center Excellence Quick Start Prescriptive Guidance
AWS Cloud Center Excellence Quick Start Prescriptive GuidanceAWS Cloud Center Excellence Quick Start Prescriptive Guidance
AWS Cloud Center Excellence Quick Start Prescriptive Guidance
Tom Laszewski
 

Mais procurados (20)

CAF presentation 09 16-2020
CAF presentation 09 16-2020CAF presentation 09 16-2020
CAF presentation 09 16-2020
 
Well Architected Framework - Data
Well Architected Framework - Data Well Architected Framework - Data
Well Architected Framework - Data
 
Building Your Cloud Strategy
Building Your Cloud StrategyBuilding Your Cloud Strategy
Building Your Cloud Strategy
 
cloud-migrations.pptx
cloud-migrations.pptxcloud-migrations.pptx
cloud-migrations.pptx
 
Azure Governance
Azure GovernanceAzure Governance
Azure Governance
 
Azure cloud migration simplified
Azure cloud migration simplifiedAzure cloud migration simplified
Azure cloud migration simplified
 
Azure governance v4.0
Azure governance v4.0Azure governance v4.0
Azure governance v4.0
 
Where to Begin? Application Portfolio Migration
Where to Begin? Application Portfolio MigrationWhere to Begin? Application Portfolio Migration
Where to Begin? Application Portfolio Migration
 
Boot camp - Migration to AWS
Boot camp - Migration to AWSBoot camp - Migration to AWS
Boot camp - Migration to AWS
 
Setting up a Cloud Center of Excellence (CCoE) for Enterprise Customers
Setting up a Cloud Center of Excellence (CCoE) for Enterprise CustomersSetting up a Cloud Center of Excellence (CCoE) for Enterprise Customers
Setting up a Cloud Center of Excellence (CCoE) for Enterprise Customers
 
Large-Scale AWS Migrations with CSC
Large-Scale AWS Migrations with CSCLarge-Scale AWS Migrations with CSC
Large-Scale AWS Migrations with CSC
 
Cloud Adoption in the Enterprise
Cloud Adoption in the EnterpriseCloud Adoption in the Enterprise
Cloud Adoption in the Enterprise
 
Azure Migrate
Azure MigrateAzure Migrate
Azure Migrate
 
Capgemini Cloud Assessment - A Pathway to Enterprise Cloud Migration
Capgemini Cloud Assessment - A Pathway to Enterprise Cloud MigrationCapgemini Cloud Assessment - A Pathway to Enterprise Cloud Migration
Capgemini Cloud Assessment - A Pathway to Enterprise Cloud Migration
 
Cloud Migration Workshop
Cloud Migration WorkshopCloud Migration Workshop
Cloud Migration Workshop
 
Cloud governance - theory and tools
Cloud governance - theory and toolsCloud governance - theory and tools
Cloud governance - theory and tools
 
Stephane Lapointe: Governance in Azure, keep control of your environments
Stephane Lapointe: Governance in Azure, keep control of your environmentsStephane Lapointe: Governance in Azure, keep control of your environments
Stephane Lapointe: Governance in Azure, keep control of your environments
 
[Azure Governance] Lesson 1 : Azure Naming Convention
[Azure Governance] Lesson 1 : Azure Naming Convention[Azure Governance] Lesson 1 : Azure Naming Convention
[Azure Governance] Lesson 1 : Azure Naming Convention
 
AWS Cloud Adoption Framework
AWS Cloud Adoption Framework AWS Cloud Adoption Framework
AWS Cloud Adoption Framework
 
AWS Cloud Center Excellence Quick Start Prescriptive Guidance
AWS Cloud Center Excellence Quick Start Prescriptive GuidanceAWS Cloud Center Excellence Quick Start Prescriptive Guidance
AWS Cloud Center Excellence Quick Start Prescriptive Guidance
 

Semelhante a Microsoft Cloud Adoption Framework for Azure: Governance Conversation

Cloud Adoption Framework Overview Deck (PPT 1).pptx
Cloud Adoption Framework Overview Deck (PPT 1).pptxCloud Adoption Framework Overview Deck (PPT 1).pptx
Cloud Adoption Framework Overview Deck (PPT 1).pptx
ValVege
 
ICS-Azure Migrations & Application Modernization_V2.pptx
ICS-Azure Migrations & Application Modernization_V2.pptxICS-Azure Migrations & Application Modernization_V2.pptx
ICS-Azure Migrations & Application Modernization_V2.pptx
mustafa435048
 

Semelhante a Microsoft Cloud Adoption Framework for Azure: Governance Conversation (20)

Microsoft Cloud Adoption Framework
Microsoft Cloud Adoption FrameworkMicrosoft Cloud Adoption Framework
Microsoft Cloud Adoption Framework
 
Azure Governance for Enterprise
Azure Governance for EnterpriseAzure Governance for Enterprise
Azure Governance for Enterprise
 
Cloud Adoption Framework - Walking Deck (L100).pptx
Cloud Adoption Framework - Walking Deck (L100).pptxCloud Adoption Framework - Walking Deck (L100).pptx
Cloud Adoption Framework - Walking Deck (L100).pptx
 
Implementing governance in the cloud era
Implementing governance in the cloud eraImplementing governance in the cloud era
Implementing governance in the cloud era
 
Accenture 2014 AWS re:Invent Enterprise Migration Breakout Session
Accenture 2014 AWS re:Invent Enterprise Migration Breakout SessionAccenture 2014 AWS re:Invent Enterprise Migration Breakout Session
Accenture 2014 AWS re:Invent Enterprise Migration Breakout Session
 
(ENT206) Migrating Thousands of Workloads to AWS at Enterprise Scale | AWS re...
(ENT206) Migrating Thousands of Workloads to AWS at Enterprise Scale | AWS re...(ENT206) Migrating Thousands of Workloads to AWS at Enterprise Scale | AWS re...
(ENT206) Migrating Thousands of Workloads to AWS at Enterprise Scale | AWS re...
 
Migrating Thousands of Workloads to AWS at Enterprise Scale – Chris Wegmann, ...
Migrating Thousands of Workloads to AWS at Enterprise Scale – Chris Wegmann, ...Migrating Thousands of Workloads to AWS at Enterprise Scale – Chris Wegmann, ...
Migrating Thousands of Workloads to AWS at Enterprise Scale – Chris Wegmann, ...
 
Governance Strategies for Cloud Transformation | AWS Public Sector Summit 2016
Governance Strategies for Cloud Transformation | AWS Public Sector Summit 2016Governance Strategies for Cloud Transformation | AWS Public Sector Summit 2016
Governance Strategies for Cloud Transformation | AWS Public Sector Summit 2016
 
Automated Security & Continuous Compliance on Microsoft Azure
Automated Security & Continuous Compliance on Microsoft AzureAutomated Security & Continuous Compliance on Microsoft Azure
Automated Security & Continuous Compliance on Microsoft Azure
 
Microsoft Azure Assessment Service (MAAS) & Modernize - Datasheet
Microsoft Azure Assessment Service (MAAS) & Modernize - DatasheetMicrosoft Azure Assessment Service (MAAS) & Modernize - Datasheet
Microsoft Azure Assessment Service (MAAS) & Modernize - Datasheet
 
Cloud Governance & DevOps: Must-have Tools on Your Journey to Azure Cloud
Cloud Governance & DevOps: Must-have Tools on Your Journey to Azure CloudCloud Governance & DevOps: Must-have Tools on Your Journey to Azure Cloud
Cloud Governance & DevOps: Must-have Tools on Your Journey to Azure Cloud
 
Cloud Adoption Framework Overview Deck (PPT 1).pptx
Cloud Adoption Framework Overview Deck (PPT 1).pptxCloud Adoption Framework Overview Deck (PPT 1).pptx
Cloud Adoption Framework Overview Deck (PPT 1).pptx
 
ICS-Azure Migrations & Application Modernization_V2.pptx
ICS-Azure Migrations & Application Modernization_V2.pptxICS-Azure Migrations & Application Modernization_V2.pptx
ICS-Azure Migrations & Application Modernization_V2.pptx
 
Perform a Cloud Readiness Assessment for Your Own Company
Perform a Cloud Readiness Assessment for Your Own CompanyPerform a Cloud Readiness Assessment for Your Own Company
Perform a Cloud Readiness Assessment for Your Own Company
 
Migrating thousands of workloads to AWS at enterprise scale
Migrating thousands of workloads to AWS at enterprise scaleMigrating thousands of workloads to AWS at enterprise scale
Migrating thousands of workloads to AWS at enterprise scale
 
Adopting Multi-Cloud Services with Confidence
Adopting Multi-Cloud Services with ConfidenceAdopting Multi-Cloud Services with Confidence
Adopting Multi-Cloud Services with Confidence
 
AWS re:Invent 2016: Large-scale AWS Migrations (ENT204)
AWS re:Invent 2016: Large-scale AWS Migrations (ENT204)AWS re:Invent 2016: Large-scale AWS Migrations (ENT204)
AWS re:Invent 2016: Large-scale AWS Migrations (ENT204)
 
Cloud Computing for the Enterprise
Cloud Computing for the EnterpriseCloud Computing for the Enterprise
Cloud Computing for the Enterprise
 
Develop an Enterprise-wide Cloud Adoption Strategy – Chris Merrigan
Develop an Enterprise-wide Cloud Adoption Strategy – Chris MerriganDevelop an Enterprise-wide Cloud Adoption Strategy – Chris Merrigan
Develop an Enterprise-wide Cloud Adoption Strategy – Chris Merrigan
 
Application Migrations
Application MigrationsApplication Migrations
Application Migrations
 

Mais de Nicholas Vossburg

Mais de Nicholas Vossburg (17)

SAP on Azure Technical Pitch Deck
SAP on Azure Technical Pitch DeckSAP on Azure Technical Pitch Deck
SAP on Azure Technical Pitch Deck
 
NoSQL Migration Technical Pitch Deck
NoSQL Migration Technical Pitch DeckNoSQL Migration Technical Pitch Deck
NoSQL Migration Technical Pitch Deck
 
NoSQL Migration to Azure Cosmos DB Pitch Deck
NoSQL Migration to Azure Cosmos DB Pitch DeckNoSQL Migration to Azure Cosmos DB Pitch Deck
NoSQL Migration to Azure Cosmos DB Pitch Deck
 
Cosmos DB Tech Pitch
Cosmos DB Tech PitchCosmos DB Tech Pitch
Cosmos DB Tech Pitch
 
Azure Cosmos DB Pricing 101 Infographic
Azure Cosmos DB Pricing 101 InfographicAzure Cosmos DB Pricing 101 Infographic
Azure Cosmos DB Pricing 101 Infographic
 
Azure Comsos DB Use Cases
Azure Comsos DB Use CasesAzure Comsos DB Use Cases
Azure Comsos DB Use Cases
 
Linux on Azure Pitch Deck
Linux on Azure Pitch DeckLinux on Azure Pitch Deck
Linux on Azure Pitch Deck
 
High Performance Computing Pitch Deck
High Performance Computing Pitch DeckHigh Performance Computing Pitch Deck
High Performance Computing Pitch Deck
 
Machine Learning Pitch Deck
Machine Learning Pitch DeckMachine Learning Pitch Deck
Machine Learning Pitch Deck
 
Deep Learning Technical Pitch Deck
Deep Learning Technical Pitch DeckDeep Learning Technical Pitch Deck
Deep Learning Technical Pitch Deck
 
Knowledge Mining with Azure Search Technical Deck
Knowledge Mining with Azure Search Technical DeckKnowledge Mining with Azure Search Technical Deck
Knowledge Mining with Azure Search Technical Deck
 
Internet of Things Pitch Deck
Internet of Things Pitch DeckInternet of Things Pitch Deck
Internet of Things Pitch Deck
 
Cloud Scale Analytics Pitch Deck
Cloud Scale Analytics Pitch DeckCloud Scale Analytics Pitch Deck
Cloud Scale Analytics Pitch Deck
 
Azure Database Services for MySQL PostgreSQL and MariaDB
Azure Database Services for MySQL PostgreSQL and MariaDBAzure Database Services for MySQL PostgreSQL and MariaDB
Azure Database Services for MySQL PostgreSQL and MariaDB
 
Azure Cosmos DB L100 Pitch Deck
Azure Cosmos DB L100 Pitch DeckAzure Cosmos DB L100 Pitch Deck
Azure Cosmos DB L100 Pitch Deck
 
Azure Migration Program Overview
Azure Migration Program OverviewAzure Migration Program Overview
Azure Migration Program Overview
 
Windows Server 2008 End of Support Pitch Deck
Windows Server 2008 End of Support Pitch DeckWindows Server 2008 End of Support Pitch Deck
Windows Server 2008 End of Support Pitch Deck
 

Último

Último (20)

Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 

Microsoft Cloud Adoption Framework for Azure: Governance Conversation

  • 1. <Title> Cloud Governance w/ the CAF governance model
  • 3. Plan Rationalize Digital Estate Prioritize and create action plan Define and implement org and skills Readiness Ready Implement Azure readiness guidelines Create Azure landing zone Implement best practices Define Strategy Understand Motivations Business outcomes Business justification Migrate • Migration consideration • Migration Guide • Expanded Scope • Best Practices Innovate • Innovation considerations • Innovation Guide • Expanded Scope • Best Practices Adopt Govern Cost management • Identity Baseline Security Baseline • Resource Consistency Deployment Acceleration Manage Org Management Change Management Ops Management Microsoft Cloud Adoption Framework for Azure http://aka.ms/cloudadoptionframework http://aka.ms/caf/gov/access
  • 4. The major drivers for IT governance Keep risk at acceptable levels Maintain availability to systems and services Consistently apply policy and audit compliance Protect customer data
  • 5. Business Returns IT must rapidly produce measurable business returns to stay relevant Transformation Evolving how businesses operate and interact with the market Modernization Improving customer and employee experiences Business Transformation enabled by Cloud Technologies Key Business Drivers Growth Scaling products and services to meet ever growing business needs
  • 7. Assess current state and future state to establish a vision for applying the framework Benchmark2 Establish a Minimally Viable Product (MVP) to serve as a foundation for governance MVP3 How Do I Get Started? Frame the conversation to mitigate tangible business risks through consistent governance Framework1 Mature with each release to align Cloud Adoption and existing IT functions Evolve4
  • 9. Assess current state and future state to establish a vision for applying the framework Assess2 Establish a Minimally Viable Product (MVP) to serve as a foundation for governance MVP3 Frame the conversation to mitigate tangible business risks through consistent governance Framework1 Mature with each release to align Cloud Adoption and existing IT functions Evolve4
  • 10. CAF Governance Model Governance End State that fosters trust and builds confidence
  • 11. Incremental Governance Execution DON’T build the Governance End State
  • 12. Making Governance Actionable with Native Tools • Azure Blueprints • Azure Policy • Azure Cost Management • Azure Advisor • Azure Portal • Azure EA Content Pack • Azure Blueprints • Azure Policy • Azure Security Center • Azure Sentinel • Subscription Design • Encryption • Hybrid Identity • Azure Networking • Azure Automation • Azure Blueprints • Azure Policy • Azure Monitor • Azure Advisor • Resource Manager Templates • Resource Graph • Management Groups • Azure Blueprints • RBAC • Azure AD • Azure AD B2B • Azure AD B2C • Directory Federation • Directory Replication • Azure Blueprint • Azure Policy • Resource Grouping & Tagging • Resource Manager Templates • Azure Advisor • Azure DevOps • Azure Site Recovery • Azure Backup • Azure Automation Azure Monitor
  • 13. Integrating 3rd Party Tools Cost Management 3rd parties • HashiCorp Terraform Security baseline 3rd parties • Splunk • HashiCorp Vault Discovery, onboarding, and recovery 3rd parties • ServiceNow • HashiCorp Terraform 3rd party identity providers • HashiCorp Vault Deployment 3rd parties • Nagios • HashiCorp Terraform • devops tools like Chef, Puppet, Zabix Monitoring 3rd parties • OpsCompass
  • 14. Release Predict, don’t guess We could make educated guesses about future, milestone risks. We can accurately predict those risks per release. Release Release Release Release Milestone Release composition Each release represents a continuum of activities from planning to completion. Releases often span multiple iterations of effort or sprints. During planning, the team should be able articulate a fairly accurate description of the assets involved, workload criticality, data classification, deployment approach, and budget. These may change in the release, but are close enough for a safe governance prediction. Release
  • 15. Governance Evolution The Cloud Governance Team then asks deeper questions to establish a governance release plan. Governance Integration During release planning, the Cloud Governance Team seeks to understand the release plan, so they can better integration. The following high level questions can help: • When will this release be completed? • What risks are introduced by this plan? • What needs to change to mitigate the new risks? Release Plan Will application criticality in this release impact policies regarding IT Operations or Cloud Operations? Will data classifications in this release impact policies regarding IT Security? Will the suggested deployment impact pricing, planned spend, or cloud budget? Will the application requirements impact identity policies or implementation? Will any of these answers impact configuration management implementations or require the implementation of new corporate policies?
  • 17. Assess current state and future state to establish a vision for applying the framework Benchmark2 Establish a Minimally Viable Product (MVP) to serve as a foundation for governance MVP3 How Do I Get Started? Frame the conversation to mitigate tangible business risks through consistent governance Framework1 Mature with each release to align Cloud Adoption and existing IT functions Evolve4
  • 18. Understand the business vision driving cloud adoption
  • 20. Evaluating current state Security management appears to be an important area of focus for this customer.
  • 22. Assess current state and future state to establish a vision for applying the framework Benchmark2 Establish a Minimally Viable Product (MVP) to serve as a foundation for governance MVP3 How Do I Get Started? Frame the conversation to mitigate tangible business risks through consistent governance Framework1 Mature with each release to align Cloud Adoption and existing IT functions Evolve4
  • 23. What and Why of Governance MVP
  • 24. The basic foundation of all governance practices 2. Subscriptions: To group similar resources into logical collections 3. Resource Groups: To further group applications or workloads into deployment and operations units 1. Management Groups: To reflect security, operations and business/accounting hierarchies Sound Governance starts with resource organization strategies.
  • 25. CRUD Azure Resource Manager Query Starting point for Governance MVP 2. Policy-based Control: Real-time enforcement, compliance assessment and remediation at scale 3. Resource Visibility: Query, explore & analyze cloud resources at scale 1. Environment Factory: Deploy and update cloud environments in a repeatable manner using composable artifacts Role-based Access Policy Definitions Resource Manager Templates Management Groups Subscriptions Resource Groups
  • 27. Building the right MVP • Create the Subscription and Management Group, adhering to the naming standards and hierarchy decisions. • Create an Azure Blueprint name “Governance MVP”. Azure Resource Management templates and Azure Policy will be created and added to the Blueprint as assets. • Enforce RBAC requirement for the subscription in the Blueprint • Create an Azure Resource Manager Template for a VPN Gateway (To be used as needed) • Create an Azure Policy to apply or enforce the following: • Resource Tagging should require values for Business Function, Data Classification, Criticality, SLA, Environment, and Application. • Resource Grouping per Application Archetype should align to the application tag • Software Defined Network if the environment lists the Environment tag as DMZ (Demilitarized Zone), ensure the proper VPN is configured • Identity validate role assignments for each resource group and resource • Nether logging, reporting, nor encryption require a policy at this time
  • 28. Microsoft is here to help Evolve Cloud Governance
  • 29. Assess current state and future state to establish a vision for applying the framework Benchmark2 Establish a Minimally Viable Product (MVP) to serve as a foundation for governance MVP3 How Do I Get Started? Frame the conversation to mitigate tangible business risks through consistent governance Framework1 Mature with each release to align Cloud Adoption and existing IT functions Evolve4
  • 31. Assessment Link CAF Governance Journeys and MVP Design

Notas do Editor

  1. Governance is about meeting strategic objectives (performance) while meeting legal and regulatory, contractual and other obligatory requirements often supported by policies (conformance). The goal is to achieve both in a balanced way.
  2. Started with notion that the value of cloud services (speed, agility, innovation, cost, security) is often negatively impacted by existing/legacy enterprise IT processes and practices (Legacy doesn’t work)
  3. Talk track: The CAF model to governance is a way of approaching governance that allows us to decompose complex and emotional topics into smaller units of actionable change. In the sections on Defining Corporate Policy, we change the topic from alignment to current IT governance requirements to a realistic look at tangible risks created by cloud adoption. Those risks can generate policy & compliance statements and recurring processes, which augment existing IT Governance Policy. Actioning on those policy statements, is done in one of five buckets of activity that span the governance conversations. In each of the five disciplines, the Cloud Governance Team leverages the Configuration Management capabilities of the Azure Govern and Azure Manage tools to help IT Governance, IT Security, Identity, and Networking teams apply requirements consistently across all Azure adoption. In this session, we will focus on the tools that establish a foundation for governance in Azure, which can be used to accelerate all five disciplines. These tools will aid in ensuring that the requirements of each discipline is consistently applied, audited, & enforced.
  4. What third parties can be used to accomplish similar goals?
  5. Talk track: The CAF model to governance is a way of approaching governance that allows us to decompose complex and emotional topics into smaller units of actionable change. In the sections on Defining Corporate Policy, we change the topic from alignment to current IT governance requirements to a realistic look at tangible risks created by cloud adoption. Those risks can generate policy & compliance statements and recurring processes, which augment existing IT Governance Policy. Actioning on those policy statements, is done in one of five buckets of activity that span the governance conversations. In each of the five disciplines, the Cloud Governance Team leverages the Configuration Management capabilities of the Azure Govern and Azure Manage tools to help IT Governance, IT Security, Identity, and Networking teams apply requirements consistently across all Azure adoption. In this session, we will focus on the tools that establish a foundation for governance in Azure, which can be used to accelerate all five disciplines. These tools will aid in ensuring that the requirements of each discipline is consistently applied, audited, & enforced.
  6. CSA, FTA, PSS, SSP or Partner can help modify the initial design based on Decision Guidance in CAF. Review and adjust this pattern to fit before presenting to the customer.