Unified Compliance Auditing Across Multiple Accounts

更新时间:
复制 MD 格式

Overview

As enterprises migrate their business to the cloud for long-term operations, they face new risks and management challenges. After migrating, operations become more frequent, flexible, and autonomous. Data storage, network architecture, and security design all adopt new patterns. These changes place new demands on central audit teams, compliance teams, and operations teams.

In this cloud environment, central management teams must handle complex deployments that involve multiple accounts, business units, and environments. They need a top-down management framework to continuously monitor enterprise-wide security and compliance, promptly detect issues, and respond quickly to avoid risks such as data breaches, service interruptions, and cost overruns.

This solution provides central management teams with a multi-account compliance management approach. It enforces unified compliance baselines from the top down and enables centralized, continuous monitoring of the compliance status of all business units. This approach increases visibility and control for central teams, ensures effective oversight, and mitigates potential risks.

Benefits

Avoid IT Operations Risks

Many business risks stem from IT governance failures, such as data breaches, service outages, cost overruns, and non-compliant IT systems. These failures can lead to financial loss, reputational damage, missed opportunities, and the loss of certifications. This solution helps enterprises build mechanisms to enforce compliant and reliable IT operations and reduce these risks.

Ease IT Operations Responsibilities

IT operations teams constantly face risks in their daily work. Misconfigurations, oversights, or inconsistent management during deployment and delivery can introduce security vulnerabilities, which can lead to account compromise, cost overruns, or data leaks. This solution enables central audit and compliance teams to oversee operations teams. It also helps operations teams implement systematic self-monitoring, shifting the reliance from human diligence to system capabilities.

Customer Scenarios

Enforce Compliance Across Multiple Accounts

Scenario Description

An enterprise uses multiple Alibaba Cloud accounts to support various business applications. Its central audit, compliance, or operations teams need to centrally monitor the security of all accounts. First, the central team must define compliance policies that all business units must follow. Then, the team needs top-down enforcement mechanisms to prevent and immediately detect violations. This ensures that policies are correctly implemented and followed. For example, the audit team may require all accounts to enable ActionTrail to continuously log cloud control-plane events.

Target Customers

  • Enterprise customers who manage multiple cloud accounts using Resource Directory

  • Enterprise customers who use multiple Alibaba Cloud accounts

  • Enterprises with centralized operations or audit teams

  • Enterprises with dedicated compliance teams

Customer Use Cases

Background

An overseas company provides independent credit ratings, index services, risk assessments, investment research, and data services to global capital markets and is an industry leader.

Pain Points

The company has over 20 Alibaba Cloud accounts. Compliance requirements vary based on account function. With resources hosted on the cloud, building a unified Configuration Management Database (CMDB) and log center is a challenge. Centralized compliance assessment, monitoring, and improvement across the entire system are not feasible. When facing MLPS 2.0 compliance audits, all 20 accounts must be treated as a single information system, which is an extremely cumbersome and costly process.

Implementation

  • Use Resource Directory for unified multi-account management.

  • Use Cloud Config to enforce different compliance baselines across accounts.

  • Use Cloud Config for thorough pre-checks against MLPS 2.0 requirements.

Customer Benefits

  • Using Resource Directory and audit products, the company can centrally manage compliance across multiple accounts and aggregate operation logs and configuration snapshots to a unified location.

  • You can use Cloud Config to enforce account-specific compliance baselines and continuously monitor the compliance status of IT systems across all cloud accounts.

  • Using Cloud Config for comprehensive MLPS 2.0 pre-checks, the company can accelerate certification for MLPS 2.0 Level 3.

Solution Architecture

Key Workflow

  1. Create an organization in Resource Directory and manage accounts using a tree structure.

  2. From the management account, create an account group in Cloud Config based on the Resource Directory structure to define the scope of compliance management.

  3. Create and apply compliance rules within the account group in Cloud Config.

  4. View the organization-wide compliance status in Cloud Config.

Pricing and Terminology

Pricing

Product Name

Description

Pricing

Resource Directory (RD)

Resource Directory (RD) is a multi-level account and resource relationship management service for enterprise customers.

Free. For details, see Pricing.

Cloud Config

Cloud Config is a configuration management and IT governance service on Alibaba Cloud. It aggregates your resources across regions into a global resource list for easy searching. It records configuration change history for cloud IT resources and lets you continuously collect full configuration data and history files into a specified storage location. It also automatically and continuously evaluates the compliance of your cloud resource configurations to support IT governance.

Paid. For details, see Billing.

Terminology

Name

Description

Management Account

When an enterprise uses multiple Alibaba Cloud accounts, the management account is the administrator account with permissions to manage resources in other accounts. It manages multiple accounts, configures identity and access permissions centrally, views bills for all cloud accounts, and defines and deploys audit rules to member accounts.

Security

Resource Directory Role Permissions

The Resource Directory service-linked role (AliyunServiceRoleForResourceDirectory) provides a trusted access channel for integrated Resource Directory services. For more information, see Resource Directory Service-Linked Role.

Cloud Config Service-Linked Role

The Cloud Config service-linked role (AliyunServiceRoleForConfig) is a RAM role that grants Cloud Config temporary access to other Alibaba Cloud services to perform certain functions. For more information, see Cloud Config Service-Linked Role.

Notes

Supported Products in Cloud Config

  • Cloud Config supports resource configuration data from many Alibaba Cloud services. For a complete list, see Supported Products.

  • Configuration updates typically complete within 10 minutes. In rare cases, synchronization may take up to T+2 days.

Cloud Config Billing

Cloud Config is currently free of charge. However, enterprises may incur charges in the future for storing resource snapshots in Cloud Config.

Resource Directory Limits

  • Each management account in a Resource Directory can create up to 5 account groups. To request a higher limit, you can submit a ticket or contact your account manager.

  • A Resource Directory organization tree can contain up to 200 member accounts. The same limit applies to the number of accounts within any account group.

For more information, see Limits.

Implementation Steps

Preparations

A landing zone has been set up. For more information, see enterprise multi-account unified architecture.

Estimated Duration

If the preparations are complete, the implementation takes approximately 5 minutes.

Procedure

Configure Audit Log Delivery

  1. Log on to the Cloud Governance Center console using the management account.

  2. In the navigation pane on the left, choose Landing Zone > Landing Zone Setup.

  3. On the Configuration Blueprint page, in the Added Items section, click Unified Log Delivery for Cloud Config. If the item is not listed, click Add Item to include it.

  4. In the Account Selection drop-down list, choose the destination account for log delivery. By default, audit logs are delivered to the log archive account created during the Landing Zone Setup.

  5. Turn on the switch for your preferred delivery method and configure its parameters.

    Delivery Method

    Manual Configuration

    Deliver to Simple Log Service (SLS)

    • Region: The region where the SLS Logstore is located.

    • Logstore Name: The name must be globally unique. We recommend that you use your company name as a prefix, such as landingzone-config-xxxx.

    • Data Retention Period: The period for which audit logs are retained in SLS. Logs are deleted after this period expires.

    Deliver to Object Storage Service (OSS)

    • Region: The region where the OSS bucket is located.

    • Bucket Name: The name must be globally unique. We recommend that you use your company name as a prefix, such as landingzone-config-xxxx.

  6. After the configuration is complete, a new SLS project and OSS bucket are created in the log archive account. A global account group is also created in the current management account.

Configure Protection Rules

  1. Log on to the Cloud Governance Center console.

  2. In the navigation pane on the left, choose Multi-Account Management > Protection Rules.

  3. In the Overview section, you can view Risk-Detected Rules, Enabled Rules, Disabled Rules, and Last Modified Time.

  4. On the All tab, click a protection rule name to manage the rule.

    • On the Rule Details tab, you can view rule information. You can also enable or disable recommended and optional rules.

    • On the Detection Results tab, you can view the compliance results for your resources.

Following best practices, you can enable the following rule types as needed:

  • Required Rules: Basic protection rules that are enforced automatically. You cannot disable them.

  • Recommended Rules: Security and compliance rules that we recommend you enable. You can choose which ones to enable and disable them later if needed.

  • Optional Rules: Rules that you can enable based on your specific needs. You can disable them later.

Related Content