SlideShare a Scribd company logo
<Title>
Cloud Governance w/ the
CAF governance model
Governing Cloud
Adoption
Plan
Rationalize Digital Estate
Prioritize and create action plan
Define and implement org and
skills Readiness
Ready
Implement Azure
readiness guidelines
Create Azure landing zone
Implement best practices
Define Strategy
Understand Motivations
Business outcomes
Business justification
Migrate
• Migration consideration
• Migration Guide
• Expanded Scope
• Best Practices
Innovate
• Innovation considerations
• Innovation Guide
• Expanded Scope
• Best Practices
Adopt
Govern
Cost management • Identity Baseline
Security Baseline • Resource Consistency
Deployment Acceleration
Manage
Org Management
Change Management
Ops Management
Microsoft Cloud Adoption Framework for Azure
http://aka.ms/cloudadoptionframework
http://aka.ms/caf/gov/access
The major drivers for
IT governance
Keep risk at acceptable levels
Maintain availability to systems
and services
Consistently apply policy and
audit compliance
Protect customer data
Business Returns
IT must rapidly produce measurable
business returns to stay relevant
Transformation
Evolving how businesses operate and
interact with the market
Modernization
Improving customer and employee
experiences
Business Transformation enabled by Cloud
Technologies
Key Business Drivers
Growth
Scaling products and services to meet
ever growing business needs
Control &
Stability
Speed &
Results
Assess current state and future state to
establish a vision for applying the framework
Benchmark2
Establish a Minimally Viable Product (MVP) to
serve as a foundation for governance
MVP3
How Do I Get Started?
Frame the conversation to mitigate tangible
business risks through consistent governance
Framework1
Mature with each release to align Cloud
Adoption and existing IT functions
Evolve4
Framing a Collaborative
Governance Conversation
Assess current state and future state to
establish a vision for applying the framework
Assess2
Establish a Minimally Viable Product (MVP) to
serve as a foundation for governance
MVP3
Frame the conversation to mitigate tangible
business risks through consistent governance
Framework1
Mature with each release to align Cloud
Adoption and existing IT functions
Evolve4
CAF Governance Model
Governance End State that fosters trust and builds confidence
Incremental Governance Execution
DON’T build the Governance End State
Making Governance Actionable with Native Tools
• Azure Blueprints
• Azure Policy
• Azure Cost
Management
• Azure Advisor
• Azure Portal
• Azure EA Content
Pack
• Azure Blueprints
• Azure Policy
• Azure Security Center
• Azure Sentinel
• Subscription Design
• Encryption
• Hybrid Identity
• Azure Networking
• Azure Automation
• Azure Blueprints
• Azure Policy
• Azure Monitor
• Azure Advisor
• Resource Manager
Templates
• Resource Graph
• Management Groups
• Azure Blueprints
• RBAC
• Azure AD
• Azure AD B2B
• Azure AD B2C
• Directory Federation
• Directory Replication
• Azure Blueprint
• Azure Policy
• Resource Grouping
& Tagging
• Resource Manager
Templates
• Azure Advisor
• Azure DevOps
• Azure Site Recovery
• Azure Backup
• Azure Automation
Azure Monitor
Integrating 3rd Party Tools
Cost Management 3rd
parties
• HashiCorp Terraform
Security baseline 3rd
parties
• Splunk
• HashiCorp Vault
Discovery,
onboarding, and
recovery 3rd parties
• ServiceNow
• HashiCorp Terraform
3rd party identity
providers
• HashiCorp Vault
Deployment 3rd
parties
• Nagios
• HashiCorp Terraform
• devops tools like
Chef, Puppet, Zabix
Monitoring 3rd parties
• OpsCompass
Release
Predict, don’t guess
We could make educated guesses about future, milestone risks. We can accurately predict those risks per release.
Release Release Release Release Milestone
Release composition
Each release represents a continuum of activities from
planning to completion. Releases often span multiple
iterations of effort or sprints.
During planning, the team should be able articulate a fairly
accurate description of the assets involved, workload
criticality, data classification, deployment approach, and
budget. These may change in the release, but are close
enough for a safe governance prediction.
Release
Governance Evolution
The Cloud Governance Team then asks deeper questions to establish a governance release plan.
Governance Integration
During release planning, the Cloud Governance Team seeks
to understand the release plan, so they can better
integration.
The following high level questions can help:
• When will this release be completed?
• What risks are introduced by this plan?
• What needs to change to mitigate the new risks?
Release
Plan
Will application criticality in this release impact
policies regarding IT Operations or Cloud
Operations?
Will data classifications in this release impact
policies regarding IT Security?
Will the suggested deployment impact pricing,
planned spend, or cloud budget?
Will the application requirements impact identity
policies or implementation?
Will any of these answers impact configuration
management implementations or require the
implementation of new corporate policies?
Assessing Next Steps
Assess current state and future state to
establish a vision for applying the framework
Benchmark2
Establish a Minimally Viable Product (MVP) to
serve as a foundation for governance
MVP3
How Do I Get Started?
Frame the conversation to mitigate tangible
business risks through consistent governance
Framework1
Mature with each release to align Cloud
Adoption and existing IT functions
Evolve4
Understand the
business vision driving
cloud adoption
Priorities and Current
State
Evaluating
current state
Security management
appears to be an
important area of focus
for this customer.
Building a governance MVP
Assess current state and future state to
establish a vision for applying the framework
Benchmark2
Establish a Minimally Viable Product (MVP) to
serve as a foundation for governance
MVP3
How Do I Get Started?
Frame the conversation to mitigate tangible
business risks through consistent governance
Framework1
Mature with each release to align Cloud
Adoption and existing IT functions
Evolve4
What and Why of Governance MVP
The basic foundation of all governance practices
2. Subscriptions: To group similar
resources into logical collections
3. Resource Groups: To further group
applications or workloads into deployment
and operations units
1. Management Groups:
To reflect security,
operations and
business/accounting
hierarchies
Sound Governance starts with resource organization strategies.
CRUD
Azure Resource Manager
Query
Starting point for Governance MVP
2. Policy-based Control: Real-time
enforcement, compliance assessment and
remediation at scale
3. Resource Visibility: Query, explore &
analyze cloud resources at scale
1. Environment Factory:
Deploy and update cloud
environments in a
repeatable manner using
composable artifacts
Role-based
Access
Policy
Definitions
Resource
Manager
Templates
Management Groups
Subscriptions
Resource Groups
Building the right MVP
Building the right MVP
• Create the Subscription and Management Group, adhering to the naming standards and hierarchy decisions.
• Create an Azure Blueprint name “Governance MVP”. Azure Resource Management templates and Azure Policy will
be created and added to the Blueprint as assets.
• Enforce RBAC requirement for the subscription in the Blueprint
• Create an Azure Resource Manager Template for a VPN Gateway (To be used as needed)
• Create an Azure Policy to apply or enforce the following:
• Resource Tagging should require values for Business Function, Data Classification, Criticality, SLA, Environment,
and Application.
• Resource Grouping per Application Archetype should align to the application tag
• Software Defined Network if the environment lists the Environment tag as DMZ (Demilitarized Zone), ensure
the proper VPN is configured
• Identity validate role assignments for each resource group and resource
• Nether logging, reporting, nor encryption require a policy at this time
Microsoft is here to help
Evolve Cloud Governance
Assess current state and future state to
establish a vision for applying the framework
Benchmark2
Establish a Minimally Viable Product (MVP) to
serve as a foundation for governance
MVP3
How Do I Get Started?
Frame the conversation to mitigate tangible
business risks through consistent governance
Framework1
Mature with each release to align Cloud
Adoption and existing IT functions
Evolve4
Take Action
Assessment Link
CAF Governance Journeys
and MVP Design
Thank you

More Related Content

PDF
Microsoft Cloud Adoption Framework
ssuserdb85d71
 
PPTX
Microsoft Cloud Adoption Framework for Azure: Thru Partner Governance Workshop
Nicholas Vossburg
 
PPTX
Cloud Adoption Framework - Walking Deck (L100).pptx
Sherman37
 
PPTX
Azure governance
girish goudar
 
PPTX
CAF presentation 09 16-2020
Michael Nichols
 
PDF
CAF intro Hosters modern
ssuserdb85d71
 
PDF
Azure governance v4.0
Marcos Oikawa
 
PDF
TechnicalTerraformLandingZones121120229238.pdf
MIlton788007
 
Microsoft Cloud Adoption Framework
ssuserdb85d71
 
Microsoft Cloud Adoption Framework for Azure: Thru Partner Governance Workshop
Nicholas Vossburg
 
Cloud Adoption Framework - Walking Deck (L100).pptx
Sherman37
 
Azure governance
girish goudar
 
CAF presentation 09 16-2020
Michael Nichols
 
CAF intro Hosters modern
ssuserdb85d71
 
Azure governance v4.0
Marcos Oikawa
 
TechnicalTerraformLandingZones121120229238.pdf
MIlton788007
 

What's hot (20)

PPTX
Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar
Timothy McAliley
 
PDF
[Azure Governance] Lesson 4 : Azure Policy
☁ Hicham KADIRI ☁
 
PDF
Azure cloud migration simplified
Girlo
 
PPTX
Cloud Adoption Framework - Overview_partner.pptx
abhishek22611
 
PPTX
Azure Governance
Benjamin Hüpeden
 
PPTX
Govern your Azure environment through Azure Policy
Microsoft Tech Community
 
PDF
Cloud Migration Cookbook: A Guide To Moving Your Apps To The Cloud
New Relic
 
PPTX
Azure Cloud Governance
Jonathan Wade
 
PPTX
Stephane Lapointe: Governance in Azure, keep control of your environments
MSDEVMTL
 
PPTX
Azure Migrate
Mustafa
 
PDF
Cloud Migration Strategy - IT Transformation with Cloud
Blazeclan Technologies Private Limited
 
PDF
introduction to Azure Sentinel
Robert Crane
 
PPTX
AWS Well-Architected Framework
Henrique Mecking
 
PPTX
Cloud Migration Strategy Framework
PT Datacomm Diangraha
 
PPTX
Introduction to the Microsoft Azure Cloud.pptx
EverestMedinilla2
 
PDF
Cloud migration strategies
SogetiLabs
 
PPTX
Azure migration
Arnon Rotem-Gal-Oz
 
PPTX
Azure Security Center- Zero to Hero
Kasun Rajapakse
 
PPTX
Capgemini Cloud Assessment - A Pathway to Enterprise Cloud Migration
Floyd DCosta
 
PDF
Multi-Cloud Strategy for Unrestricted Possibilities
Harsh V Sehgal
 
Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar
Timothy McAliley
 
[Azure Governance] Lesson 4 : Azure Policy
☁ Hicham KADIRI ☁
 
Azure cloud migration simplified
Girlo
 
Cloud Adoption Framework - Overview_partner.pptx
abhishek22611
 
Azure Governance
Benjamin Hüpeden
 
Govern your Azure environment through Azure Policy
Microsoft Tech Community
 
Cloud Migration Cookbook: A Guide To Moving Your Apps To The Cloud
New Relic
 
Azure Cloud Governance
Jonathan Wade
 
Stephane Lapointe: Governance in Azure, keep control of your environments
MSDEVMTL
 
Azure Migrate
Mustafa
 
Cloud Migration Strategy - IT Transformation with Cloud
Blazeclan Technologies Private Limited
 
introduction to Azure Sentinel
Robert Crane
 
AWS Well-Architected Framework
Henrique Mecking
 
Cloud Migration Strategy Framework
PT Datacomm Diangraha
 
Introduction to the Microsoft Azure Cloud.pptx
EverestMedinilla2
 
Cloud migration strategies
SogetiLabs
 
Azure migration
Arnon Rotem-Gal-Oz
 
Azure Security Center- Zero to Hero
Kasun Rajapakse
 
Capgemini Cloud Assessment - A Pathway to Enterprise Cloud Migration
Floyd DCosta
 
Multi-Cloud Strategy for Unrestricted Possibilities
Harsh V Sehgal
 
Ad

Similar to Microsoft Cloud Adoption Framework for Azure: Governance Conversation (20)

PPTX
Implementing governance in the cloud era
Synergetics Learning and Cloud Consulting
 
PDF
Cloud Governance & DevOps: Must-have Tools on Your Journey to Azure Cloud
Predica Group
 
PDF
Building an Enterprise-Grade Azure Governance Model
Karl Ots
 
PDF
Techorama Belgium 2019 - Building an Azure Governance model for the Enterprise
Karl Ots
 
PPTX
Cloud Adoption Framework Secure Overview
AanSulistiyo
 
DOCX
Govern methodology for the cloud.docx
dropbox10
 
PDF
Cloud governance - theory and tools
Antti Arnell
 
PPTX
Cloud Adoption Framework Overview Deck (PPT 1).pptx
ValVege
 
PPTX
TechEvent Cloud Governance
Trivadis
 
PDF
Govern Your Cloud: The Foundation for Success
Alert Logic
 
PPTX
Azure Governance for Enterprise
Mohit Chhabra
 
PDF
Building a Secure and Compliant Azure Virtual Data Center
Patrick Sklodowski
 
PPTX
Module3ksjdfbsdkfkasjdfbjkendfksdmnfckajs.pptx
trainingdecorpo
 
PDF
Automated Security & Continuous Compliance on Microsoft Azure
2nd Watch
 
PPTX
ITCamp 2019 - Mihai Tataran - Governing your Cloud Resources
ITCamp
 
PDF
Adopting Multi-Cloud Services with Confidence
Kevin Hakanson
 
PDF
Security & Compliance in the Cloud [2019]
Tudor Damian
 
PDF
Cloud governance framework - the essentials
Predica Group
 
PPTX
Azure Security Compass v1.1 - Presentation.pptx
ZaheerEbrahim5
 
PPTX
Running Regulated Workloads on Azure PaaS services (DogFoodCon 2018)
Jeremy Gray
 
Implementing governance in the cloud era
Synergetics Learning and Cloud Consulting
 
Cloud Governance & DevOps: Must-have Tools on Your Journey to Azure Cloud
Predica Group
 
Building an Enterprise-Grade Azure Governance Model
Karl Ots
 
Techorama Belgium 2019 - Building an Azure Governance model for the Enterprise
Karl Ots
 
Cloud Adoption Framework Secure Overview
AanSulistiyo
 
Govern methodology for the cloud.docx
dropbox10
 
Cloud governance - theory and tools
Antti Arnell
 
Cloud Adoption Framework Overview Deck (PPT 1).pptx
ValVege
 
TechEvent Cloud Governance
Trivadis
 
Govern Your Cloud: The Foundation for Success
Alert Logic
 
Azure Governance for Enterprise
Mohit Chhabra
 
Building a Secure and Compliant Azure Virtual Data Center
Patrick Sklodowski
 
Module3ksjdfbsdkfkasjdfbjkendfksdmnfckajs.pptx
trainingdecorpo
 
Automated Security & Continuous Compliance on Microsoft Azure
2nd Watch
 
ITCamp 2019 - Mihai Tataran - Governing your Cloud Resources
ITCamp
 
Adopting Multi-Cloud Services with Confidence
Kevin Hakanson
 
Security & Compliance in the Cloud [2019]
Tudor Damian
 
Cloud governance framework - the essentials
Predica Group
 
Azure Security Compass v1.1 - Presentation.pptx
ZaheerEbrahim5
 
Running Regulated Workloads on Azure PaaS services (DogFoodCon 2018)
Jeremy Gray
 
Ad

More from Nicholas Vossburg (18)

PPTX
SAP on Azure Technical Pitch Deck
Nicholas Vossburg
 
PPTX
NoSQL Migration Technical Pitch Deck
Nicholas Vossburg
 
PPTX
NoSQL Migration to Azure Cosmos DB Pitch Deck
Nicholas Vossburg
 
PPTX
Cosmos DB Tech Pitch
Nicholas Vossburg
 
PPTX
Azure Cosmos DB Pricing 101 Infographic
Nicholas Vossburg
 
PPTX
Azure Comsos DB Use Cases
Nicholas Vossburg
 
PPTX
Linux on Azure Pitch Deck
Nicholas Vossburg
 
PPTX
High Performance Computing Pitch Deck
Nicholas Vossburg
 
PPTX
Machine Learning Pitch Deck
Nicholas Vossburg
 
PPTX
Deep Learning Technical Pitch Deck
Nicholas Vossburg
 
PPTX
Knowledge Mining with Azure Search Technical Deck
Nicholas Vossburg
 
PPTX
Internet of Things Pitch Deck
Nicholas Vossburg
 
PPTX
Cloud Scale Analytics Pitch Deck
Nicholas Vossburg
 
PPTX
Azure Database Services for MySQL PostgreSQL and MariaDB
Nicholas Vossburg
 
PPTX
Azure Cosmos DB L100 Pitch Deck
Nicholas Vossburg
 
PPTX
Azure Migration Program Overview
Nicholas Vossburg
 
PPTX
Azure Migration Program Pitch Deck
Nicholas Vossburg
 
PPTX
Windows Server 2008 End of Support Pitch Deck
Nicholas Vossburg
 
SAP on Azure Technical Pitch Deck
Nicholas Vossburg
 
NoSQL Migration Technical Pitch Deck
Nicholas Vossburg
 
NoSQL Migration to Azure Cosmos DB Pitch Deck
Nicholas Vossburg
 
Cosmos DB Tech Pitch
Nicholas Vossburg
 
Azure Cosmos DB Pricing 101 Infographic
Nicholas Vossburg
 
Azure Comsos DB Use Cases
Nicholas Vossburg
 
Linux on Azure Pitch Deck
Nicholas Vossburg
 
High Performance Computing Pitch Deck
Nicholas Vossburg
 
Machine Learning Pitch Deck
Nicholas Vossburg
 
Deep Learning Technical Pitch Deck
Nicholas Vossburg
 
Knowledge Mining with Azure Search Technical Deck
Nicholas Vossburg
 
Internet of Things Pitch Deck
Nicholas Vossburg
 
Cloud Scale Analytics Pitch Deck
Nicholas Vossburg
 
Azure Database Services for MySQL PostgreSQL and MariaDB
Nicholas Vossburg
 
Azure Cosmos DB L100 Pitch Deck
Nicholas Vossburg
 
Azure Migration Program Overview
Nicholas Vossburg
 
Azure Migration Program Pitch Deck
Nicholas Vossburg
 
Windows Server 2008 End of Support Pitch Deck
Nicholas Vossburg
 

Recently uploaded (20)

PDF
Accelerating Oracle Database 23ai Troubleshooting with Oracle AHF Fleet Insig...
Sandesh Rao
 
PPTX
Simple and concise overview about Quantum computing..pptx
mughal641
 
PDF
Tea4chat - another LLM Project by Kerem Atam
a0m0rajab1
 
PDF
Doc9.....................................
SofiaCollazos
 
PDF
Research-Fundamentals-and-Topic-Development.pdf
ayesha butalia
 
PDF
Orbitly Pitch Deck|A Mission-Driven Platform for Side Project Collaboration (...
zz41354899
 
PDF
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
PPTX
The-Ethical-Hackers-Imperative-Safeguarding-the-Digital-Frontier.pptx
sujalchauhan1305
 
PPTX
Introduction to Flutter by Ayush Desai.pptx
ayushdesai204
 
PDF
NewMind AI Weekly Chronicles - July'25 - Week IV
NewMind AI
 
PDF
Presentation about Hardware and Software in Computer
snehamodhawadiya
 
PDF
Brief History of Internet - Early Days of Internet
sutharharshit158
 
PPTX
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
PPTX
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
PDF
A Strategic Analysis of the MVNO Wave in Emerging Markets.pdf
IPLOOK Networks
 
PDF
OFFOFFBOX™ – A New Era for African Film | Startup Presentation
ambaicciwalkerbrian
 
PDF
SparkLabs Primer on Artificial Intelligence 2025
SparkLabs Group
 
PDF
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
PDF
Trying to figure out MCP by actually building an app from scratch with open s...
Julien SIMON
 
PDF
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 
Accelerating Oracle Database 23ai Troubleshooting with Oracle AHF Fleet Insig...
Sandesh Rao
 
Simple and concise overview about Quantum computing..pptx
mughal641
 
Tea4chat - another LLM Project by Kerem Atam
a0m0rajab1
 
Doc9.....................................
SofiaCollazos
 
Research-Fundamentals-and-Topic-Development.pdf
ayesha butalia
 
Orbitly Pitch Deck|A Mission-Driven Platform for Side Project Collaboration (...
zz41354899
 
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
The-Ethical-Hackers-Imperative-Safeguarding-the-Digital-Frontier.pptx
sujalchauhan1305
 
Introduction to Flutter by Ayush Desai.pptx
ayushdesai204
 
NewMind AI Weekly Chronicles - July'25 - Week IV
NewMind AI
 
Presentation about Hardware and Software in Computer
snehamodhawadiya
 
Brief History of Internet - Early Days of Internet
sutharharshit158
 
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
A Strategic Analysis of the MVNO Wave in Emerging Markets.pdf
IPLOOK Networks
 
OFFOFFBOX™ – A New Era for African Film | Startup Presentation
ambaicciwalkerbrian
 
SparkLabs Primer on Artificial Intelligence 2025
SparkLabs Group
 
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
Trying to figure out MCP by actually building an app from scratch with open s...
Julien SIMON
 
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 

Microsoft Cloud Adoption Framework for Azure: Governance Conversation

  • 1. <Title> Cloud Governance w/ the CAF governance model
  • 3. Plan Rationalize Digital Estate Prioritize and create action plan Define and implement org and skills Readiness Ready Implement Azure readiness guidelines Create Azure landing zone Implement best practices Define Strategy Understand Motivations Business outcomes Business justification Migrate • Migration consideration • Migration Guide • Expanded Scope • Best Practices Innovate • Innovation considerations • Innovation Guide • Expanded Scope • Best Practices Adopt Govern Cost management • Identity Baseline Security Baseline • Resource Consistency Deployment Acceleration Manage Org Management Change Management Ops Management Microsoft Cloud Adoption Framework for Azure http://aka.ms/cloudadoptionframework http://aka.ms/caf/gov/access
  • 4. The major drivers for IT governance Keep risk at acceptable levels Maintain availability to systems and services Consistently apply policy and audit compliance Protect customer data
  • 5. Business Returns IT must rapidly produce measurable business returns to stay relevant Transformation Evolving how businesses operate and interact with the market Modernization Improving customer and employee experiences Business Transformation enabled by Cloud Technologies Key Business Drivers Growth Scaling products and services to meet ever growing business needs
  • 7. Assess current state and future state to establish a vision for applying the framework Benchmark2 Establish a Minimally Viable Product (MVP) to serve as a foundation for governance MVP3 How Do I Get Started? Frame the conversation to mitigate tangible business risks through consistent governance Framework1 Mature with each release to align Cloud Adoption and existing IT functions Evolve4
  • 9. Assess current state and future state to establish a vision for applying the framework Assess2 Establish a Minimally Viable Product (MVP) to serve as a foundation for governance MVP3 Frame the conversation to mitigate tangible business risks through consistent governance Framework1 Mature with each release to align Cloud Adoption and existing IT functions Evolve4
  • 10. CAF Governance Model Governance End State that fosters trust and builds confidence
  • 11. Incremental Governance Execution DON’T build the Governance End State
  • 12. Making Governance Actionable with Native Tools • Azure Blueprints • Azure Policy • Azure Cost Management • Azure Advisor • Azure Portal • Azure EA Content Pack • Azure Blueprints • Azure Policy • Azure Security Center • Azure Sentinel • Subscription Design • Encryption • Hybrid Identity • Azure Networking • Azure Automation • Azure Blueprints • Azure Policy • Azure Monitor • Azure Advisor • Resource Manager Templates • Resource Graph • Management Groups • Azure Blueprints • RBAC • Azure AD • Azure AD B2B • Azure AD B2C • Directory Federation • Directory Replication • Azure Blueprint • Azure Policy • Resource Grouping & Tagging • Resource Manager Templates • Azure Advisor • Azure DevOps • Azure Site Recovery • Azure Backup • Azure Automation Azure Monitor
  • 13. Integrating 3rd Party Tools Cost Management 3rd parties • HashiCorp Terraform Security baseline 3rd parties • Splunk • HashiCorp Vault Discovery, onboarding, and recovery 3rd parties • ServiceNow • HashiCorp Terraform 3rd party identity providers • HashiCorp Vault Deployment 3rd parties • Nagios • HashiCorp Terraform • devops tools like Chef, Puppet, Zabix Monitoring 3rd parties • OpsCompass
  • 14. Release Predict, don’t guess We could make educated guesses about future, milestone risks. We can accurately predict those risks per release. Release Release Release Release Milestone Release composition Each release represents a continuum of activities from planning to completion. Releases often span multiple iterations of effort or sprints. During planning, the team should be able articulate a fairly accurate description of the assets involved, workload criticality, data classification, deployment approach, and budget. These may change in the release, but are close enough for a safe governance prediction. Release
  • 15. Governance Evolution The Cloud Governance Team then asks deeper questions to establish a governance release plan. Governance Integration During release planning, the Cloud Governance Team seeks to understand the release plan, so they can better integration. The following high level questions can help: • When will this release be completed? • What risks are introduced by this plan? • What needs to change to mitigate the new risks? Release Plan Will application criticality in this release impact policies regarding IT Operations or Cloud Operations? Will data classifications in this release impact policies regarding IT Security? Will the suggested deployment impact pricing, planned spend, or cloud budget? Will the application requirements impact identity policies or implementation? Will any of these answers impact configuration management implementations or require the implementation of new corporate policies?
  • 17. Assess current state and future state to establish a vision for applying the framework Benchmark2 Establish a Minimally Viable Product (MVP) to serve as a foundation for governance MVP3 How Do I Get Started? Frame the conversation to mitigate tangible business risks through consistent governance Framework1 Mature with each release to align Cloud Adoption and existing IT functions Evolve4
  • 18. Understand the business vision driving cloud adoption
  • 20. Evaluating current state Security management appears to be an important area of focus for this customer.
  • 22. Assess current state and future state to establish a vision for applying the framework Benchmark2 Establish a Minimally Viable Product (MVP) to serve as a foundation for governance MVP3 How Do I Get Started? Frame the conversation to mitigate tangible business risks through consistent governance Framework1 Mature with each release to align Cloud Adoption and existing IT functions Evolve4
  • 23. What and Why of Governance MVP
  • 24. The basic foundation of all governance practices 2. Subscriptions: To group similar resources into logical collections 3. Resource Groups: To further group applications or workloads into deployment and operations units 1. Management Groups: To reflect security, operations and business/accounting hierarchies Sound Governance starts with resource organization strategies.
  • 25. CRUD Azure Resource Manager Query Starting point for Governance MVP 2. Policy-based Control: Real-time enforcement, compliance assessment and remediation at scale 3. Resource Visibility: Query, explore & analyze cloud resources at scale 1. Environment Factory: Deploy and update cloud environments in a repeatable manner using composable artifacts Role-based Access Policy Definitions Resource Manager Templates Management Groups Subscriptions Resource Groups
  • 27. Building the right MVP • Create the Subscription and Management Group, adhering to the naming standards and hierarchy decisions. • Create an Azure Blueprint name “Governance MVP”. Azure Resource Management templates and Azure Policy will be created and added to the Blueprint as assets. • Enforce RBAC requirement for the subscription in the Blueprint • Create an Azure Resource Manager Template for a VPN Gateway (To be used as needed) • Create an Azure Policy to apply or enforce the following: • Resource Tagging should require values for Business Function, Data Classification, Criticality, SLA, Environment, and Application. • Resource Grouping per Application Archetype should align to the application tag • Software Defined Network if the environment lists the Environment tag as DMZ (Demilitarized Zone), ensure the proper VPN is configured • Identity validate role assignments for each resource group and resource • Nether logging, reporting, nor encryption require a policy at this time
  • 28. Microsoft is here to help Evolve Cloud Governance
  • 29. Assess current state and future state to establish a vision for applying the framework Benchmark2 Establish a Minimally Viable Product (MVP) to serve as a foundation for governance MVP3 How Do I Get Started? Frame the conversation to mitigate tangible business risks through consistent governance Framework1 Mature with each release to align Cloud Adoption and existing IT functions Evolve4
  • 31. Assessment Link CAF Governance Journeys and MVP Design

Editor's Notes

  • #7: Governance is about meeting strategic objectives (performance) while meeting legal and regulatory, contractual and other obligatory requirements often supported by policies (conformance). The goal is to achieve both in a balanced way.
  • #9: Started with notion that the value of cloud services (speed, agility, innovation, cost, security) is often negatively impacted by existing/legacy enterprise IT processes and practices (Legacy doesn’t work)
  • #14: Talk track: The CAF model to governance is a way of approaching governance that allows us to decompose complex and emotional topics into smaller units of actionable change. In the sections on Defining Corporate Policy, we change the topic from alignment to current IT governance requirements to a realistic look at tangible risks created by cloud adoption. Those risks can generate policy & compliance statements and recurring processes, which augment existing IT Governance Policy. Actioning on those policy statements, is done in one of five buckets of activity that span the governance conversations. In each of the five disciplines, the Cloud Governance Team leverages the Configuration Management capabilities of the Azure Govern and Azure Manage tools to help IT Governance, IT Security, Identity, and Networking teams apply requirements consistently across all Azure adoption. In this session, we will focus on the tools that establish a foundation for governance in Azure, which can be used to accelerate all five disciplines. These tools will aid in ensuring that the requirements of each discipline is consistently applied, audited, & enforced.
  • #16: What third parties can be used to accomplish similar goals?
  • #26: Talk track: The CAF model to governance is a way of approaching governance that allows us to decompose complex and emotional topics into smaller units of actionable change. In the sections on Defining Corporate Policy, we change the topic from alignment to current IT governance requirements to a realistic look at tangible risks created by cloud adoption. Those risks can generate policy & compliance statements and recurring processes, which augment existing IT Governance Policy. Actioning on those policy statements, is done in one of five buckets of activity that span the governance conversations. In each of the five disciplines, the Cloud Governance Team leverages the Configuration Management capabilities of the Azure Govern and Azure Manage tools to help IT Governance, IT Security, Identity, and Networking teams apply requirements consistently across all Azure adoption. In this session, we will focus on the tools that establish a foundation for governance in Azure, which can be used to accelerate all five disciplines. These tools will aid in ensuring that the requirements of each discipline is consistently applied, audited, & enforced.
  • #30: CSA, FTA, PSS, SSP or Partner can help modify the initial design based on Decision Guidance in CAF. Review and adjust this pattern to fit before presenting to the customer.