Database Risk Engineering & Control Framework – Emerging DB
- Strengthened security and compliance controls across Cosmos DB, Redis/AMR and DocumentDB through TLS 1.2 enforcement, Entra ID-based access, access-key restrictions and audit-to-deny policy updates.
- Updated Cosmos DB ICC evidence and progressed privileged-access controls for controlled and monitored database access through CyberArk.
- Introduced lower-environment governance policies covering autoscale restrictions, low-cost AMR SKUs and HA configuration auditing to support risk reduction and cost optimisation.
- Rolled over to Q3: BigID scanning remediation, remaining HA audit-policy coverage for Redis, Cosmos DB and DocumentDB, and completion of the Azure Redis Cache deny-policy readiness checks.
- The central CMK Key Vault removal and Cosmos NoSQL MIM-group enablement were initiated toward the end of Q2 and completed in early Q3.
Note: Unlike Q3, Q2 did not have a dedicated Cost Optimisation epic. Cost-related policy items were therefore included and tracked under the Risk Engineering & Control Framework epic from the outset.





0 comments:
Post a Comment