PRIVATECLOUD.HK
Security and governanceCONTROL DOSSIER

Make control boundaries, ownership and evidence reviewable.

Architecture can support customer requirements, but certification or provider controls do not automatically make a customer compliant.

Security and governance

Controls are only useful when ownership is visible.

The target design should connect each control to its technical boundary, operator, evidence and exception process. This model supports review; it does not claim blanket compliance.

Isolation and segmentation

Define tenant, network, management and workload boundaries for the selected platform.

Identity and privilege

Map IAM, MFA, administrator access, break-glass procedure and review ownership.

Encryption and keys

Document encryption options, key ownership, certificate handling and exceptions.

Logging and monitoring

Agree event sources, retention, alert routing, triage and escalation responsibilities.

Backup and recovery

Separate backup, high availability and disaster recovery; define immutable options and tests.

Lifecycle controls

Scope patching, vulnerability handling, change control, capacity review and evidence.

Provider scope

  • Platform operation [TBD]
  • Monitoring and escalation [TBD]
  • Backup/recovery execution [TBD]

Customer scope

  • Application configuration
  • User access approvals
  • Data classification and business recovery priorities

Joint decisions

  • Data placement and flows
  • Recovery objectives and tests
  • Change windows and incident communications
Review the shared-responsibility model
Control evidence

Ask four questions for every control.

  1. 01

    What is the boundary?

    System, network, identity, data, management plane or process.

  2. 02

    Who performs it?

    Provider, customer, partner or a named joint workflow.

  3. 03

    What proves it?

    Configuration, log, ticket, test result, review record or approved exception.

  4. 04

    What remains outside scope?

    Applications, users, endpoints, data classification, legal review or third parties.

Turn security requirements into scoped controls and ownership.

Start with workload placement, connectivity, data flows, recovery objectives, migration risk and the full commercial scope.

Book an architecture assessment
WhatsApp