Loading...

What is a Cloud Adoption Security Review?

What is a Cloud Adoption Security Review?

What is a Cloud Adoption Security Review?

The Cloud Adoption Security Review (CASR) is aimed to self-assess an Azure landing zone (ALZ) environment that has achieved baseline security against the Secure Methodology of the Cloud Adoption Framework (CAF).

 

Security is an ongoing journey of incremental progress and maturity, and not a static destination. The Cloud Adoption Framework provides security guidance for this journey by providing clarity to the processes and best practices. This guidance is based on real world experiences of our customers, of Microsoft's own security journey and lessons learned, and the work with other organizations like NIST (National Institute of Standards and Technology) or CIS (Center for Internet Security).

 

The outcome is manifested in the Cloud Adoption Framework Secure Methodology which provides a vision of the complete end state of your security journey and follows the Zero Trust principle (assume breachverify explicitlyuse least privilege access).

This assessment gives you the opportunity to self-assess your security journey of your cloud adoption against this secure methodology.

 

What are the areas we are addressing with this assessment?

This assessment targets the CAF secure methodology. This methodology provides guidance on the integration of security with business processes (also called business alignment) and security disciplines. The following domain areas are covered in the Cloud Adoption Security Review:

 

AriyaKhamvongsa_0-1682984131707.jpeg

 

 

When should you do a Cloud Adoption Security Review?

Before cloud adoption can begin you need to have Azure landing zones created which will host the workloads. Within CAF this is called the Ready phase. At this phase or stage, you should already have designed your Azure landing zones and you should know about your cloud operation model because security is critical here. You should have a secure design or plan before you are going to the next phases and deploy your workload resources into your landing zones. 

 

AriyaKhamvongsa_1-1682984131715.jpeg

 

 

 

What are the benefits of doing a Cloud Adoption Security Review?

It will help you to identify opportunities for critical security optimizations to better align to the secure methodology of CAF and improve your Azure landing zone security. At the end of this assessment, you will receive actionable recommendations to incrementally improve your security. Actionable means that you can import those recommendations into your Azure DevOps or GitHub project and are able to track the implementation progress through standard project management processes and tasks. You can create multiple versions (Milestones) of the assessment and track your progress over time.

 

AriyaKhamvongsa_2-1682984131716.jpeg

 

 

More Information

  • Watch the corresponding Azure Enablement Show video about this Cloud Adoption Security Review

CAF Security Review.jpg

Published on:

Learn more
Need help with this product?

We can help you with What is a Cloud Adoption Security Review?

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

Azure Architecture Blog articles
Azure Architecture Blog articles

Azure Architecture Blog articles

Share post:

Related posts

End-to-End Full-Stack Web Application with Azure AD B2C Authentication: A Complete Guide

Application Overview The purpose of this sample application is to demonstrate the usage of Azure Active Directory B2C (Azure AD B2C) for authe...

1 year ago

Complex Data Extraction using Document Intelligence and RAG

Section 1: Introduction   Historically, data extraction from unstructured documents was a manual and tedious process. It consisted of a c...

1 year ago

Harnessing Generative AI with Weaviate on Azure Kubernetes Service and Azure NetApp Files

Table of Contents Introduction Prerequisites Install Weaviate Approximate Nearest Neighbor (ANN) Benchmarks ANN Benchmarks Setup ANN Benchmark...

1 year ago

Securing Containerized Applications with SSH Tunneling

As cloud engineers and architects embrace containerization, ensuring secure communication becomes paramount. Data transmission and access cont...

1 year ago

Exploring AI Agent-Driven Auto Insurance Claims RAG Pipeline.

Introduction: In this post, I explore a recent experiment aimed at creating a RAG pipeline tailored for the insurance industry, specificall...

1 year ago

Azure NetApp Files now stores sensitive data DoD IL5 compliant in Azure US Government regions

Table of Contents Introduction Why Azure NetApp Files? DoD IL5 compliance in Azure Government Azure NetApp Files reaches feature parity betwee...

1 year ago

Data Intelligence End-to-End with Azure Databricks and Microsoft Fabric

This Azure Architecture Blog was written in conjunction with Isaac Gritz, Senior Solutions Architect, at Databricks.   The Data Inte...

1 year ago

AI Studio End-to-End Baseline Reference Implementation

  Azure AI Studio is designed to cater to the growing needs of developers seeking to integrate advanced AI capabilities into their appli...

1 year ago

Mastering AI adoption: Essentials to building, operating and optimizing genAI workloads on Azure

Mastering your AI adoption: Essentials to building, operating and optimizing genAI workloads on Azure As the demand for scalable, efficient AI...

2 years ago

Optimize Azure Stack HCI with the Well-Architected Framework

  Azure Stack HCI is a hyperconverged infrastructure (HCI) solution that provides storage, network, and compute resources in on-premises...

2 years ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.