Book Image

Policy Design in the Age of Digital Adoption

By : Ricardo Ferreira
Book Image

Policy Design in the Age of Digital Adoption

By: Ricardo Ferreira

Overview of this book

Policy as Code (PaC) is a powerful paradigm that enables organizations to implement, validate, and measure policies at scale. Policy Design in the Age of Digital Adoption is a comprehensive guide to understanding policies, their design, and implementation for cloud environments using a DevOps-based framework. You'll discover how to create the necessary automation, its integration, and which stakeholders to involve. Complete with essential concepts, practical examples, and self-assessment questions, this book will help you understand policies and how new technologies such as cloud, microservices, and serverless leverage Policy as Code. You'll work with a custom framework to implement PaC in the organization, and advance to integrating policies, guidelines, and regulations into code to enhance the security and resilience posture of the organization. You'll also examine existing tools, evaluate them, and learn a framework to implement PaC so that technical and business teams can collaborate more effectively. By the end of this book, you'll have gained the confidence to design digital policies across your organizational environment.
Table of Contents (18 chapters)
1
Section 1: Foundation
5
Section 2: Framework
10
Section 3: Tooling

Preface

The increase of digital enablement is a critical priority for countries and business organizations. With an estimate of US$2.8 trillion of spending in digital transformation globally by 2025, it is crucial to support and have the tools to make these efforts as smooth as possible.

Currently, most digital transformations are aspirational; only a small percentage goes beyond pilot mode, as evidenced by the latest reports by McKinsey and Harvard Business Review. This book leans on the best practices of design thinking and public policy design to bring frameworks and best practices to design and implement digital policies at scale into an organization to significantly improve its digital transformation effort.

It focuses on the intersection of people, technology, and processes. Throughout the book, we focus on people. We elevate the people aspect dimension with PolicyOps and how it brings the dimensions of automation, native digital platforms, and people to build instruments that foster a culture of inclusivity and experimentation.

We discuss and review the state of art in Policy as Code, policy engines (PEs), giving a focus to Open Policy Agent, and how to use it effectively to build guardrails, authorization (coercive instruments) across digital services. We focus on instruments adapted for hybrid environments and the native cloud providers' policy capabilities.

Finally, we talk about frameworks and how to link policies to business processes using information technology service management (ITSM) tools present in any modern organization.

These concepts allow you to build policies that work across the fundamental tenets of the organization, by using the robust frameworks discussed in the book coupled with PEs such as Open Policy Agent to accelerate digital adoption.