- Google Cloud PBMM Landing Zone: https://github.com/GoogleCloudPlatform/pubsec-declarative-toolkit
- AWS Secure Environment Accelerator: https://github.com/aws-samples/aws-secure-environment-accelerator
- Azure Landing Zones for Canadian Public Sector: https://github.com/Azure/CanadaPubSecALZ/
- Google Cloud Security Command Center Premium - Compliance tab - requires additional automation on evidence capture
- https://aws.amazon.com/audit-manager/
- https://github.com/cloud-quickstart/gcp-landing-zone (GCP Java SDK in progress)
- https://cloud.google.com/architecture/landing-zones
- https://github.com/GoogleCloudPlatform/pbmm-on-gcp-onboarding (Terraform)
- Google Cloud PBMM Landing Zone: https://github.com/GoogleCloudPlatform/pubsec-declarative-toolkit (Kubernetes Config Controller)
- https://cloud.google.com/anthos-config-management/docs/tutorials/landing-zone
Guardrail |
CSP |
Reference |
Details |
Links |
---|---|---|---|---|
IAM modification | "Use Google Cloud's operations suite to set up alerts that will notify you when a SetIamPolicy() API call is made. This will send an alert when anyone modifies any IAM policy." | https://cloud.google.com/resource-manager/docs/super-admin-best-practices |
https://wiki.gccollab.ca/index.php?title=GC_Cloud_Infocentre&mobileaction=toggle_view_desktop
https://github.com/Azure/GuardrailsSolutionAccelerator/blob/main/docs/controls.md#guardrail-12-configuration-of-cloud-marketplaces https://learn.microsoft.com/en-us/defender-cloud-apps/connect-google-gcp
https://github.com/canada-ca/accelerators_accelerateurs-gcp
https://github.com/canada-ca/cloud-guardrails-gcp/tree/main/guardrails-validation
https://github.com/canada-ca/cloud-guardrails/tree/master/EN
https://github.com/GoogleCloudPlatform/pbmm-on-gcp-onboarding
https://cloud.google.com/docs/security/infrastructure/design
https://cloud.google.com/architecture/security-foundations
https://cloud.google.com/vpc-service-controls/docs/secure-data-exchange
https://cloud.google.com/security/compliance/offerings#/regions=Canada
https://github.com/aws-samples/aws-secure-environment-accelerator
https://github.com/Azure/devops-governance
https://repo1.dso.mil/dsawg-devsecops/kubernetes-srg/k8-srg-artifacts/-/tree/master
https://cloud.google.com/blog/topics/public-sector/announcing-google-public-sector