Book Image

Policy Design in the Age of Digital Adoption

By : Ricardo Ferreira
Book Image

Policy Design in the Age of Digital Adoption

By: Ricardo Ferreira

Overview of this book

Policy as Code (PaC) is a powerful paradigm that enables organizations to implement, validate, and measure policies at scale. Policy Design in the Age of Digital Adoption is a comprehensive guide to understanding policies, their design, and implementation for cloud environments using a DevOps-based framework. You'll discover how to create the necessary automation, its integration, and which stakeholders to involve. Complete with essential concepts, practical examples, and self-assessment questions, this book will help you understand policies and how new technologies such as cloud, microservices, and serverless leverage Policy as Code. You'll work with a custom framework to implement PaC in the organization, and advance to integrating policies, guidelines, and regulations into code to enhance the security and resilience posture of the organization. You'll also examine existing tools, evaluate them, and learn a framework to implement PaC so that technical and business teams can collaborate more effectively. By the end of this book, you'll have gained the confidence to design digital policies across your organizational environment.
Table of Contents (18 chapters)
1
Section 1: Foundation
5
Section 2: Framework
10
Section 3: Tooling

Highly regulated industries and their policy needs

The previous chapter highlighted that policies are used to achieve a specific goal and establish governance using different instruments. Regulation is a type of coercive instrument defined to help achieve compliance and model behaviors. Regulation can also be a law, for example, General Data Protection Regulation (GDPR), or in other cases, acts of parliament. In the EU, due to the primacy of European Union law, a legal principle establishes the precedence of European Union law over conflicting national laws of EU member states.

This leads us to the regulatory bodies of several key industries, such as finance, healthcare, government, and more. These bodies create regulations that all organizations in specific sectors must abide by, usually coming in two types:

  • Guidelines: A piece of advice used to provide direction and information; for example, the UK's Financial Conduct Authority (FCA) published the FG 16/5 Guidance...