Cloud Security Assessment Review with ARM : Assessment
NCC Group plc
NCC Group will perform a thorough AZURE Cloud Configuration Assessment, in addition to reviewing specific workloads (maximum of four representative workloads per platform) as a sample set of those currently in operational use, we will assess the following applicable to each environment: • Access keys and root account status • Segregation of resources • Network Security Groups and ACLs • Region in which data is held • Identity and Access Management configurations & password policyUser groups and privileges • Encryption of snapshots and volumes The Cloud Configuration Assessment will give a broad overview of the security of your cloud computing estate. Due to the large number of cloud resources in scope NCC Group proposes a sampled configuration review which will provide a solid representation of ARM’s wider estate. This will guide future assessments and the CSAR process. DEliverables: This finding will be produced in a report format to include:
- Executive Summary a. Summary of Findings b. Impact c. Prioritized Recommendations d. Conclusion
- NIST Assessment Results a. Assessment Methodology b. Summary of Findings and Recommendations c. Detailed scoring of controls against NIST-CSF 2.0 Maturity Framework d. Scoring Definitions e. Controls Marked as N/A f. Summary of NIST-CSF Control Maturity Ratings
- Technical Cloud Configuration review, providing a RAG status of configuration findings together with recommendations.
- ARM Target Operating Model assessment and recommendations, with a particular requirement to provide a ‘people’ focused benchmark.
- Recommendations and prioritisation roadmap plan for remediation – strategic, operational and technical
- Appendices - Cybersecurity Maturity Rating Detail by Control