Book Image

Policy Design in the Age of Digital Adoption

By : Ricardo Ferreira
Book Image

Policy Design in the Age of Digital Adoption

By: Ricardo Ferreira

Overview of this book

Policy as Code (PaC) is a powerful paradigm that enables organizations to implement, validate, and measure policies at scale. Policy Design in the Age of Digital Adoption is a comprehensive guide to understanding policies, their design, and implementation for cloud environments using a DevOps-based framework. You'll discover how to create the necessary automation, its integration, and which stakeholders to involve. Complete with essential concepts, practical examples, and self-assessment questions, this book will help you understand policies and how new technologies such as cloud, microservices, and serverless leverage Policy as Code. You'll work with a custom framework to implement PaC in the organization, and advance to integrating policies, guidelines, and regulations into code to enhance the security and resilience posture of the organization. You'll also examine existing tools, evaluate them, and learn a framework to implement PaC so that technical and business teams can collaborate more effectively. By the end of this book, you'll have gained the confidence to design digital policies across your organizational environment.
Table of Contents (18 chapters)
1
Section 1: Foundation
5
Section 2: Framework
10
Section 3: Tooling

Policy DLC – coherence, congruence, and consistency

As seen in the first chapters, policies are a mix of goals and instruments. As time passes, policies go through several iterations that can introduce drifting from the original intent, either by introducing a new layer as they are updated, changing instruments as they are converted to other goals, or completely being replaced due to new goals.

In this section, we will talk about the life cycle and the key concern to maintain fit between the policy design elements, such as ensuring we get congruence of the goal and instrument, consistency at an instrumental level, and making sure that goals are coherent.

The three Cs

It is crucial to refer to the ability of the PolicyOps team to manage different policies with coherent goals, which means that as long as the goals refer to the same policy objectives and can be pursued concurrently, there is coherency.

The most pressing issue that affects the need for a PolicyOps...