Stay on top of the Azure Governance game

Stay on top of the Azure Governance game

Do you also feel that there is an exponential growth of resources in your cloud environments?

In my job, I have had to plan, design, architect, and develop solutions for the cloud ecosystem. When it is time to operate and maintain them, it gets a bit trickier if you have many departments. Demands will vary by department, and requirements on the technology you use might look different in other parts of the organization.

A key thing I've learned over the years is that you need a proper governance plan. It would help if you allowed the business to thrive. Operations and your security teams should be enabled to stay on top of the game.

Here are a few simple tips to help understand what is going on in your Azure environment.
 

Azure Resource Graph

The built-in capabilities in Azure for querying resources are extensive. Azure Resource Graph provides us with a way to use Kusto Query Language (KQL) queries to ask Azure about the state of our Azure resources.

Use cases, for me, include:

  • Extended audits and reviews
  • Cross-subscription resource insights
  • Determine the impact of an Azure Policy action before rolling out
  • Continuously discover changes to resources
  • Visualize your inventory

Read more about the Azure Resource Graph and how it can help: Using the Azure Resource Graph to improve your Azure Governance game.
 

Custom recommendations in Azure Security Center

Getting insights from more than one angle helps. With Azure Security Center, we can stay on top of many industry-standard regulations. We can enforce and ensure we have good security posture and good data sovereignty (laws and regulations of where data resides and is stored).

Great functionality in the Azure Security Center that I've been making use of a lot is creating custom recommendations with Azure Policies. If the rules we need to play by do not exist, we can roll out custom recommendations.

Read more about creating a custom Azure Security Center recommendation with Azure Policy.
 

The Security Development Lifecycle (SDL) process

Continuously rolling out new resources doesn't have to be a bad thing. But do you know what they are and what they do? Perhaps they comply with Azure Policies and all recommendations in Azure Security Center. However, that does not mean that they are trustworthy or okay to roll out.

To add another layer of control in an ever-growing landscape of technology and rapid changes in development and deployments, a Security Development Lifecycle, or SDL, can help a lot.

I have a few key points.

  • Security should be an organization-wide responsibility.
  • Introducing DevSecOps will naturally help your ops (operations), hence strengthening your governance early in the game.
  • Security breaches often happen from poorly configured resources or third-party code. I would rather have them mitigated during this process than find out in production.

Read more about embracing a Security Development Lifecycle (SDL) for Azure.
 

Over to you!

Do you ever consider the governance aspect of your cloud journey, or is that someone else's department? How does it work in your organization?







This email was sent to you
why did I get this?    unsubscribe from this list    update subscription preferences
zimmergren.net · Solursgatan 28 · Bunkeflostrand 21847 · Sweden

Older messages

Digest from Zimmergren - September 30, 2020

Sunday, September 5, 2021

Here's a curated summary of recent popular posts, and other interesting things to note. A summary - September 2020 Since you subscribed to updates from my blog, here's a curated summary of the

Digest from Zimmergren - October 31, 2020

Sunday, September 5, 2021

Here's a curated summary of recent popular posts, and other interesting things to note. A summary - October 2020 Since you subscribed to updates from my blog, here's a curated summary of the

You Might Also Like

Daily Coding Problem: Problem #1707 [Medium]

Monday, March 3, 2025

Daily Coding Problem Good morning! Here's your coding interview problem for today. This problem was asked by Facebook. In chess, the Elo rating system is used to calculate player strengths based on

Simplification Takes Courage & Perplexity introduces Comet

Monday, March 3, 2025

Elicit raises $22M Series A, Perplexity is working on an AI-powered browser, developing taste, and more in this week's issue of Creativerly. Creativerly Simplification Takes Courage &

Mapped | Which Countries Are Perceived as the Most Corrupt? 🌎

Monday, March 3, 2025

In this map, we visualize the Corruption Perceptions Index Score for countries around the world. View Online | Subscribe | Download Our App Presented by: Stay current on the latest money news that

The new tablet to beat

Monday, March 3, 2025

5 top MWC products; iPhone 16e hands-on📱; Solar-powered laptop -- ZDNET ZDNET Tech Today - US March 3, 2025 TCL Nxtpaper 11 tablet at CES The tablet that replaced my Kindle and iPad is finally getting

Import AI 402: Why NVIDIA beats AMD: vending machines vs superintelligence; harder BIG-Bench

Monday, March 3, 2025

What will machines name their first discoveries? ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏

GCP Newsletter #440

Monday, March 3, 2025

Welcome to issue #440 March 3rd, 2025 News LLM Official Blog Vertex AI Evaluate gen AI models with Vertex AI evaluation service and LLM comparator - Vertex AI evaluation service and LLM Comparator are

Apple Should Swap Out Siri with ChatGPT

Monday, March 3, 2025

Not forever, but for now. Until a new, better Siri is actually ready to roll — which may be *years* away... Apple Should Swap Out Siri with ChatGPT Not forever, but for now. Until a new, better Siri is

⚡ THN Weekly Recap: Alerts on Zero-Day Exploits, AI Breaches, and Crypto Heists

Monday, March 3, 2025

Get exclusive insights on cyber attacks—including expert analysis on zero-day exploits, AI breaches, and crypto hacks—in our free newsletter. ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌ ͏ ‌

⚙️ AI price war

Monday, March 3, 2025

Plus: The reality of LLM 'research' ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌

Post from Syncfusion Blogs on 03/03/2025

Monday, March 3, 2025

New blogs from Syncfusion ® AI-Driven Natural Language Filtering in WPF DataGrid for Smarter Data Processing By Susmitha Sundar This blog explains how to add AI-driven natural language filtering in the