Book Image

Policy Design in the Age of Digital Adoption

By : Ricardo Ferreira
Book Image

Policy Design in the Age of Digital Adoption

By: Ricardo Ferreira

Overview of this book

Policy as Code (PaC) is a powerful paradigm that enables organizations to implement, validate, and measure policies at scale. Policy Design in the Age of Digital Adoption is a comprehensive guide to understanding policies, their design, and implementation for cloud environments using a DevOps-based framework. You'll discover how to create the necessary automation, its integration, and which stakeholders to involve. Complete with essential concepts, practical examples, and self-assessment questions, this book will help you understand policies and how new technologies such as cloud, microservices, and serverless leverage Policy as Code. You'll work with a custom framework to implement PaC in the organization, and advance to integrating policies, guidelines, and regulations into code to enhance the security and resilience posture of the organization. You'll also examine existing tools, evaluate them, and learn a framework to implement PaC so that technical and business teams can collaborate more effectively. By the end of this book, you'll have gained the confidence to design digital policies across your organizational environment.
Table of Contents (18 chapters)
1
Section 1: Foundation
5
Section 2: Framework
10
Section 3: Tooling

Vendor ecosystems

In this section, we will introduce some tools from the PaC ecosystem. Here, the main difference is that we will focus on paid tools, in some cases listing vendors that provide a free version and an enterprise version at a cost.

As you might know, Terraform, an Infrastructure as Code (IaC) tool, is part of HashiCorp, which also provides an enterprise paid version called Terraform Enterprise. It makes sense to list them, primarily in organizations that need assurances, such as Service-Level Agreements (SLAs), and dedicated support.

HashiCorp

As discussed in Chapter 8, Policy Engines, HashiCorp Sentinel provides a PaC framework for enterprise users. One of the great benefits of this is integrating with the HashiCorp ecosystem, especially Terraform, the de facto tool for IaC, and providing comprehensive policies to the Terraform code.

You can find more information at https://www.hashicorp.com/sentinel.

Styra

Styra provides OPA enterprise support and...