Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesMedium
A global financial institution is implementing a new cloud-based trading platform. The platform must adhere to stringent regulatory requirements, including data residency and privacy laws across multiple jurisdictions. The cybersecurity architect is tasked with evaluating technical strategies to ensure compliance while maintaining operational efficiency. Which of the following strategies best addresses the need for consistent security controls and regulatory adherence across diverse global regions?
- AImplementing separate, region-specific security policies and configurations for each cloud deployment.
- BRelying on the cloud provider's default security services and shared responsibility model for all compliance needs.
- CUtilizing a centralized cloud security posture management (CSPM) solution with policy as code and regional enforcement capabilities.
- DDeploying a decentralized security information and event management (SIEM) system with local data storage in each region.
Show answer & explanationAnswer & explanation
Correct answer: C. Utilizing a centralized cloud security posture management (CSPM) solution with policy as code and regional enforcement capabilities.
A centralized CSPM solution with policy as code allows for consistent definition and automated enforcement of security policies across all cloud environments, adapting to regional nuances while maintaining a unified compliance posture. This approach directly addresses the challenge of diverse global regulations.
Why the other options are wrong
- A. Separate policies can lead to inconsistencies, increased management overhead, and potential compliance gaps across regions.
- B. Default cloud provider services are a baseline; they do not automatically ensure compliance with specific, stringent regulatory requirements, and the shared responsibility model places significant onus on the customer for their data and configurations.
- D. While local data storage is important for data residency, a decentralized SIEM alone doesn't ensure consistent security control enforcement or proactive compliance management.
Cloud Security Posture Management (CSPM)
CSPM solutions continuously monitor cloud environments for misconfigurations, compliance violations, and security risks, providing visibility and automated remediation capabilities.
- Automates compliance checks against industry standards and regulations.
- Identifies and remediates misconfigurations in cloud resources.
- Offers continuous visibility into cloud security posture.
Memory trick: Global Compliance Needs Central Cloud Guard