Wednesday, 22 July 2026

Filled under:

 

Database Risk Engineering & Control Framework – Emerging DB

  • Strengthened security and compliance controls across Cosmos DB, Redis/AMR and DocumentDB through TLS 1.2 enforcement, Entra ID-based access, access-key restrictions and audit-to-deny policy updates.
  • Updated Cosmos DB ICC evidence and progressed privileged-access controls for controlled and monitored database access through CyberArk.
  • Introduced lower-environment governance policies covering autoscale restrictions, low-cost AMR SKUs and HA configuration auditing to support risk reduction and cost optimisation.
  • Rolled over to Q3: BigID scanning remediation, remaining HA audit-policy coverage for Redis, Cosmos DB and DocumentDB, and completion of the Azure Redis Cache deny-policy readiness checks.
  • The central CMK Key Vault removal and Cosmos NoSQL MIM-group enablement were initiated toward the end of Q2 and completed in early Q3.

Note: Unlike Q3, Q2 did not have a dedicated Cost Optimisation epic. Cost-related policy items were therefore included and tracked under the Risk Engineering & Control Framework epic from the outset.

0 comments:

Post a Comment