Sample Cloud Security Roadmap
June 22, 2017Short Term
- Develop Cloud Security overlay for cloud foundry
- Perform holistic Cloud Security assessment (current state, gaps, future state)
- Develop strategies / roadmap / plans for each domain within Cloud Security
- Research Cloud and Cloud Security Solutions
Medium Term
- Develop governance structure (sponsorship, stakeholders, funding)
- Establish program to manage roadmap, initiatives and strategy changes
- Establish Cloud Security Services Catalog
- Establish Support Structure
Long Term
- Secure transition to Hybrid Cloud
Actions
- First action requires a review and approval of this strategy by IT management
- Next develop an action plan for short term activities
- Other actions articulated through this document:
-
- Develop a Cloud Security Governance strategy
- Start a Cloud Security Program
- Continue to build and develop the Cloud Security IT Team
- Mature Cloud Security Process Model
- Provide recommendations for policy change
- Provide guiding principles
- Provide recommendations for dealing with corporate technology complexity and footprint
- Provide recommendations to improve private Cloud Security by domain
- Work with technology partners to influence the selection of platforms (hardware / software) that align with the IT Strategy.
- Perform Holistic Cloud Security Assessment
- Inventory current controls applicable to securing Private Cloud
- Identify methods capabilities that align with the strategy
- Identify methods / capabilities that align with the strategy
- Identify the assurance levels achievable by the method
- Use information to establish the inception of the Cloud Security Services catalog Identify gaps for meeting the strategy
- Identify solutions to address gaps
- Inventory current controls applicable to securing Private Cloud
- Further develop strategy, roadmap and target state for Internal, on premise, private Cloud Security