Book Image

Policy Design in the Age of Digital Adoption

By : Ricardo Ferreira
Book Image

Policy Design in the Age of Digital Adoption

By: Ricardo Ferreira

Overview of this book

Policy as Code (PaC) is a powerful paradigm that enables organizations to implement, validate, and measure policies at scale. Policy Design in the Age of Digital Adoption is a comprehensive guide to understanding policies, their design, and implementation for cloud environments using a DevOps-based framework. You'll discover how to create the necessary automation, its integration, and which stakeholders to involve. Complete with essential concepts, practical examples, and self-assessment questions, this book will help you understand policies and how new technologies such as cloud, microservices, and serverless leverage Policy as Code. You'll work with a custom framework to implement PaC in the organization, and advance to integrating policies, guidelines, and regulations into code to enhance the security and resilience posture of the organization. You'll also examine existing tools, evaluate them, and learn a framework to implement PaC so that technical and business teams can collaborate more effectively. By the end of this book, you'll have gained the confidence to design digital policies across your organizational environment.
Table of Contents (18 chapters)
1
Section 1: Foundation
5
Section 2: Framework
10
Section 3: Tooling

Chapter 13: Real-World Scenarios and Architectures

As we reach the end of this book, we will be looking at some real-world scenarios and architectures. We will choose four examples and apply the policy framework we introduced. This allows us to consolidate our knowledge and understand how to use the framework to design policies and architectures that support our goals.

In this chapter, we will discuss several policies. The first use case will show how to tackle costs through a policy. The second example will cover authorization, focusing on supply chain security and highlighting the benefits of attestation. The third example will cover a service migration policy where we will focus on the people aspect to support a transformation effort. Finally, we will cover a compliance enforcement scenario with Open Policy Agent (OPA).

For this chapter, we will use the framework established in Chapter 4, Framework for Digital Policies. Every section will use it to discuss the design and implementation...