Book Image

Policy Design in the Age of Digital Adoption

By : Ricardo Ferreira
Book Image

Policy Design in the Age of Digital Adoption

By: Ricardo Ferreira

Overview of this book

Policy as Code (PaC) is a powerful paradigm that enables organizations to implement, validate, and measure policies at scale. Policy Design in the Age of Digital Adoption is a comprehensive guide to understanding policies, their design, and implementation for cloud environments using a DevOps-based framework. You'll discover how to create the necessary automation, its integration, and which stakeholders to involve. Complete with essential concepts, practical examples, and self-assessment questions, this book will help you understand policies and how new technologies such as cloud, microservices, and serverless leverage Policy as Code. You'll work with a custom framework to implement PaC in the organization, and advance to integrating policies, guidelines, and regulations into code to enhance the security and resilience posture of the organization. You'll also examine existing tools, evaluate them, and learn a framework to implement PaC so that technical and business teams can collaborate more effectively. By the end of this book, you'll have gained the confidence to design digital policies across your organizational environment.
Table of Contents (18 chapters)
1
Section 1: Foundation
5
Section 2: Framework
10
Section 3: Tooling

The challenges of hybrid environments

In Chapter 5, Policy for Cloud-Native Environments, we discussed cloud-native environments and how policy tools for Container as Service (CaaS) and Function as a Service (FaaS) might help create enforcement patterns.

This chapter will look at the hybrid environments and their definitions, compositions, and challenges.

While I believe that the future is on public cloud platforms using service models such as FaaS, the current reality is multi-cloud with private and on-premises environments. This pattern is still prevalent in large organization segments where there is a need for a hybrid environment due to legal, regulatory, and localization requirements. This is evident as the EU launched efforts such as GAIA-X in 2020 and a draft of the candidate European Union Cybersecurity Certification Scheme for Cloud Services (EUCS) scheme in 2021.

In this section, we will define a hybrid environment and discuss its architecture, along with the benefits...