Cloud Governance

You might also like

Download as docx, pdf, or txt
Download as docx, pdf, or txt
You are on page 1of 4

The Cloud Operation Governance Layer model outlines which of the processes are in scope of each

layer and which specific IMF controls are applicable to the services provided in a layer.

 Layer 0: Public Cloud


This layer covers the vendor provided services and is governed by the Third Party Risk
Assessment (TPRM) assessments, procurement processes as well as Risk Management
process for Third Party Management services delivery by the public cloud provider.

 Layer 1: Cloud Platform Infrastructure


This layer is governed by infrastructure and cloud platform (includes all cloud management
tools) specific controls, its implementation and monitoring during operation.

 Layer 2: Cloud Core Service Management


In this layer, Security Compliance & Monitoring process must be followed especially for the
architecture & service design of the Cloud infrastructure platform

 Layer 3: Engineering Service Management


This layer covers the design, architecture and the implementation of reusable engineering
solutions and components that will be applied on layer 4 and 5 and is governed by
infrastructure and software engineering specific controls relevant for those components.

 Layer 4: Product Support Service


This layer covers infrastructure instances and services running within a cloud account
and is governed by infrastructure and platform specific controls, its implementation and
monitoring during operation.

 Layer 5: Informatics Layer


This layer covers the end user facing information processing capabilities running
within a cloud account and is governed by application specific controls, its implementation
and monitoring during operation.

Layers 1 to 5 are all subject to information risk management process.


What is in scope of Insightcloud sec?

In Scope IT security alerts impacting cloud services, applications, or infrastructure hosted in Novartis
Public cloud environment. This includes any real or suspected loss, unauthorized access, change, or
misuse of information or technology maintained within Novartis public cloud environment only.

Cloud Security operations works on security alerts in Novartis cloud environment recognized by primarily
CSPM tool (InsightCloudSec).

All AWS accounts within NIBR and CTS organization.


All Azure subscriptions within CTS organization.
WHAT IS IMF - The
Information Management Framework (IMF) is defining a
governance framework to integrate and align information management
requirements and practices, enabling digital at scale and driving simplification
across the organization.

The selection of IMF Controls in scope of Cloud Platform security enforcement will be done jointly by
Cloud Engineering Team and ISRM (1)

Selection of IMF Controls


2 set of controls were reviewed :

 Primary Scope using the IMF control matrix built-in filters for PaaS & IaaS Controls Controls.
 Secondary Scope using the IMF control matrix built-in filters for Infrastructure controls
(Network, Server, Database) and not already covered with PaaS & IaaS filtering
Control Domain

Access Control Design

Access Management

Asset Management
Backup Management

Business Information Management


Continuity and Availability

Continuity and Availability


Configuration Management

Change Management

Data Center Management

Data Management

Encryption Management
Global Governance Control

Global Governance Control


Incident Management

Logging and Monitoring


Network and Infrastructure

Network and Infrastructure


System Development & Operation

System Development & Operation


Security Incident Management

Social Media Account Management


Third Party Management

Threat and Vulnerability Management


Website Management

You might also like