Alibaba Cloud Landing Zone Service Description
1. Service overview
1.1. Service description
The Landing Zone service helps you design and validate cloud-based IT governance solutions that use Alibaba Cloud products during your cloud migration. The service helps you design solutions for account management, network planning, financial management, resource management, compliance auditing, and security protection, and provides technical validation for these solutions. Using this service, you can follow Alibaba Cloud best practices to more quickly set up a secure, multi-account Alibaba Cloud environment.
The Landing Zone service includes three sub-services. You can choose the one that best fits your business needs:
Landing Zone service (Required, choose one of the following three options)
Basic Edition
Lightweight consulting service: Includes solution design and technical consulting for account management and your choice of either network planning or security protection.
Includes technical validation of the solutions to verify the selected technologies.
Standard Edition
Standard consulting service: Includes solution design and technical consulting for account management, network planning, financial management, resource management, compliance auditing, and security protection, tailored to your needs.
Includes technical validation of the solutions to verify the selected technologies.
Includes integration solutions for your self-built systems, such as Single Sign-On (SSO), Configuration Management Database (CMDB), and billing systems.
Advanced Edition
Advanced consulting service: Includes solution design, technical consulting, and solution implementation for account management, network planning, financial management, resource management, compliance auditing, and security protection, tailored to your needs.
Includes technical validation and implementation of the solutions to verify the selected technologies. It also includes integration solutions for your self-built systems, such as SSO, CMDB, and billing systems.
Any work or solutions not defined in this Statement of Work (SOW) are outside the scope of this project.
2. Scope of service
The service is available in three editions: Landing Zone Basic Edition, Landing Zone Standard Edition, and Landing Zone Advanced Edition. You can choose the edition that best meets your needs.
2.1. Landing Zone Basic Edition scope of service
The Landing Zone Basic Edition includes the following:
Landing Zone analysis and assessment
Analysis of the current state of your application technology stack using surveys and interviews. Assessment of the feasibility of implementing cloud-based IT governance for your enterprise and definition of the Landing Zone procedure.
Recommendation of a technical path for your landing zone based on the assessment results.
Account management solution
Design of an account management solution based on the Landing Zone analysis and assessment. This includes:
Accounts: Planning for Alibaba Cloud accounts, permission classification, and Resource Access Management (RAM) account usage standards.
MFA: A support solution for multi-factor authentication (MFA).
SSO integration: Integration with your existing SSO system for unified logon and identity federation to connect user authentication systems.
Identity authentication: Identification of identity usage scenarios and design of a federated authentication integration solution for each scenario.
Network planning solution (Choose either network planning or security protection)
Design of a network planning solution based on the Landing Zone analysis and assessment. This includes:
Network access solution: Planning for connecting your data center to the cloud platform network using a VPN. This includes the design of solutions for access layer firewalls, application layer firewalls, and a jump server.
Internal cloud network solution: Definition of the network architecture plan, including VPC division, CIDR block and IP address planning, and cloud DMZ division.
Inter-cloud connection solution: Use of Cloud Enterprise Network (CEN) to establish VPC peering across different regions, accounts, and data centers, with interconnection authorization granted by account as required.
Security protection solution (Choose either network planning or security protection)
Design of a security protection solution based on the Landing Zone analysis and assessment. This includes:
Network security: Configuration of security groups and design of a cloud network security domain division plan. Isolation of applications using network security zones and configuration of connectivity for specific application needs.
Data security: Design of a data security solution that meets your security requirements. This includes key management, database access control, and storage access control.
Note that the security solution covers only security related to the cloud platform itself and follows enterprise security management standards. It does not cover your applications or other security requirements.
Technical validation
Technical validation of the solutions for account management, network planning, or security protection. The goal of this stage is to verify the technologies selected for the solutions. The scope of technical validation includes:
User account, permission, and identity management validation.
Network allocation, CIDR block division, and network connectivity validation.
2.2. Landing Zone Standard Edition scope of service
The Landing Zone Standard Edition includes the following:
Landing Zone analysis and assessment
Analysis of the current state of your application technology stack using surveys and interviews. Assessment of the feasibility of implementing cloud-based IT governance for your enterprise and definition of the Landing Zone procedure.
Definition of the scope of the Landing Zone work based on the assessment results.
Account management solution
Design of an account management solution based on the Landing Zone analysis and assessment. This includes:
Accounts: Planning for Alibaba Cloud accounts, permission classification, and RAM account usage standards.
MFA: Added support for MFA.
SSO integration: Integration with your existing SSO system for unified logon and identity federation to connect user authentication systems.
Identity authentication: Identification of identity usage scenarios and design of a federated authentication integration solution for each scenario.
Network planning solution
Design of a network planning solution based on the Landing Zone analysis and assessment. This includes:
Network access solution: Planning for connecting your data center to the cloud platform network. This includes the design of solutions for access layer firewalls, application layer firewalls, and a jump server.
Internal cloud network solution: Definition of the network architecture plan, including VPC division, CIDR block and IP address planning, and cloud DMZ division.
Inter-cloud connection solution: Use of CEN to establish VPC peering across different regions, accounts, and data centers, with interconnection authorization granted by account as required.
Financial management solution
Design of a financial management solution based on the Landing Zone analysis and assessment. This includes:
Cost allocation: Design of a cost accounting model and a bill analysis solution for cloud expenditures based on cost centers.
Cost analysis: Design of a financial analysis solution. Provision of a solution for integrating with Alibaba Cloud's billing capabilities to help you connect to your internal financial analysis platform and obtain cost data such as bills and expense details.
Cost optimization: Provision of best practices, deployment solutions, and audit solutions for cost optimization of the cloud services used.
Resource management solution
Design of a resource management solution based on the Landing Zone analysis and assessment. This includes:
Provision of a solution for integrating with Alibaba Cloud's billing capabilities to help you connect to your internal billing platform and obtain cost data such as bills and invoices.
For enterprises without a standard billing model or platform, provision of a cost management solution based on a resource directory and a cost allocation design.
Compliance audit solution
Design of a compliance audit solution based on the Landing Zone analysis and assessment. This includes:
Provision of enterprise firewall configuration standards to meet classified protection compliance requirements for security zone border protection.
Provision of enterprise-level multilayer protection standards, including server-side encryption, client-based encryption, hotlink protection, and IP blacklists and whitelists configuration standards.
Customization of an audit solution that meets your enterprise audit requirements. This includes operation audit, account audit, and log audit.
Security protection solution
Design of a security protection solution based on the Landing Zone analysis and assessment. This includes:
Network security: Configuration of security groups and design of a cloud network security domain division plan. Isolation of applications using network security zones and configuration of connectivity for specific application needs.
Data security: Design of a data security solution that meets your security requirements. This includes key management, database access control, and storage access control.
Note that the security solution covers only security related to the cloud platform itself and follows enterprise security management standards. It does not cover your applications or other security requirements.
Technical validation
Technical validation of the solutions for account management, network planning, financial management, resource management, compliance audit, and security protection. The goal of this stage is to verify the technologies selected for the solutions. The scope of technical validation includes:
User account, permission, and identity management validation.
Network allocation, CIDR block division, and network connectivity validation.
Cost allocation validation.
IP whitelist, network security group, and operation audit validation.
Security domain isolation and data access whitelist validation.
Enterprise IT infrastructure integration validation: SSO, CMDB, and billing platform.
2.3. Landing Zone Advanced Edition scope of service
The Landing Zone Advanced Edition includes the following:
Landing Zone analysis and assessment
Analysis of the current state of your application technology stack using surveys and interviews. Assessment of the feasibility of implementing cloud-based IT governance for your enterprise and definition of the Landing Zone procedure.
Definition of the scope of the Landing Zone work based on the assessment results.
Account management solution
Design of an account management solution based on the Landing Zone analysis and assessment. This includes:
Accounts: Planning for Alibaba Cloud accounts, permission classification, and RAM account usage standards.
MFA: A support solution for MFA.
SSO integration: Integration with your existing SSO system for unified logon and identity federation to connect user authentication systems.
Identity authentication: Identification of identity usage scenarios and design of a federated authentication integration solution for each scenario.
Network planning solution
Design of a network planning solution based on the Landing Zone analysis and assessment. This includes:
Network access solution: Planning for connecting your data center to the cloud platform network. This includes the design of solutions for access layer firewalls, application layer firewalls, and a jump server.
Internal cloud network solution: Definition of the network architecture plan, including VPC division, CIDR block and IP address planning, and cloud DMZ division.
Inter-cloud connection solution: Use of CEN to establish VPC peering across different regions, accounts, and data centers, with interconnection authorization granted by account as required.
Financial management solution
Design of a financial management solution based on the Landing Zone analysis and assessment. This includes:
Cost allocation: Design of a cost accounting model and a bill analysis solution for cloud expenditures based on cost centers.
Cost analysis: Design of a financial analysis solution. Provision of a solution for integrating with Alibaba Cloud's billing capabilities to help you connect to your internal financial analysis platform and obtain cost data such as bills and expense details.
Cost optimization: Provision of best practices, deployment solutions, and audit solutions for cost optimization of the cloud services used.
Resource management solution
Design of a resource management solution based on the Landing Zone analysis and assessment. This includes:
Provision of a solution for integrating with Alibaba Cloud's billing capabilities to help you connect to your internal billing platform and obtain cost data such as bills and invoices.
For enterprises without a standard billing model or platform, provision of a cost management solution based on a resource directory and a cost allocation design.
Compliance audit solution
Design of a compliance audit solution based on the Landing Zone analysis and assessment. This includes:
Provision of enterprise firewall configuration standards to meet classified protection compliance requirements for security zone border protection.
Provision of enterprise-level multilayer protection standards, including server-side encryption, client-based encryption, hotlink protection, and IP blacklists and whitelists configuration standards.
Customization of an audit solution that meets your enterprise audit requirements. This includes operation audit, account audit, and log audit.
Security protection solution
Design of a security protection solution based on the Landing Zone analysis and assessment. This includes:
Network security: Configuration of security groups and design of a cloud network security domain division plan. Isolation of applications using network security zones and configuration of connectivity for specific application needs.
Data security: Design of a data security solution that meets your security requirements. This includes key management, database access control, and storage access control.
Note that the security solution covers only security related to the cloud platform itself and follows enterprise security management standards. It does not cover your applications or other security requirements.
Technical validation
Technical validation of the solutions for account management, network planning, financial management, resource management, compliance audit, and security protection. The goal of this stage is to verify the technologies selected for the solutions. The scope of technical validation includes:
User account, permission, and identity management validation.
Network allocation, CIDR block division, and network connectivity validation.
Cost allocation validation.
IP whitelist, network security group, and operation audit validation.
Security domain isolation and data access whitelist validation.
Enterprise IT infrastructure integration validation: SSO, CMDB, and billing platform.
Solution implementation
Implementation of the designed and validated solutions for account management, network planning, financial management, resource management, compliance audit, and security protection.
This service does not include the following:
The Landing Zone service covers only IT governance on the cloud. It does not provide enterprise-level IT governance consulting. If you require this service, you must purchase it separately.
The security governance in the solutions includes only design related to security audit and governance at the cloud platform level. It does not cover the application security or content security of your business systems, or your classified protection compliance requirements.
For integration with your own platforms, such as SSO, CMDB, and billing platforms, we provide only the integration solution. We are not responsible for handling technical issues with your platforms or for the specific implementation of the integration.
Party B assumes no responsibility for schedule delays caused by Party A.
You must not restrict the service delivery method. Alibaba Cloud will conduct detailed analysis and solution design on-site or remotely as required to produce the final results.
Alibaba Cloud is not responsible for providing any technical documents other than official Alibaba Cloud documentation and documents within the project delivery scope.
Party B is not responsible for Party A's business system planning, architecture design, cloud migration and transformation, or the implementation and maintenance of the application.
Alibaba Cloud is not responsible for troubleshooting, technical support, or answering questions about non-Alibaba Cloud platforms, such as third-party software or application systems.
3. Prerequisites
You must request this service at least 15 business days in advance. This allows Alibaba Cloud to assess your business goals and timeline feasibility and to confirm whether to accept the service request.
If your request involves many resources, you must submit it one month in advance. The specific timeline will be negotiated based on a supply chain assessment.
You must provide Alibaba Cloud with all necessary and reasonable documents, information, data, charts, and required system permissions and remote access channels in a timely manner so that Alibaba Cloud can provide the service. All such materials are subject to the confidentiality clauses of this agreement. You agree that all information you have disclosed or will disclose to Alibaba Cloud is true, accurate, and not misleading.
For the Basic, Standard, and Advanced Editions of the landing zone, remote service is provided regardless of the project location, primarily through phone, DingTalk, and email.
During the project delivery, you are the primary implementer. Alibaba Cloud primarily provides solution design and troubleshooting during implementation. You are responsible for the specific IT governance implementation actions.
The service provider provides delivery services for this project during business hours: 9:00 AM to 6:00 PM (UTC+8), Monday to Friday, excluding national public holidays.
During the project, both parties will use a mutually agreed-upon communication method, such as DingTalk, the Internet, fax, or email. The project managers from both parties are responsible for exchanging the necessary written information for the project.
All project deliverables will be provided in Simplified Chinese, and the working language will be Chinese. All deliverables will be in Microsoft Office format (such as PPT, Word, Excel, or Visio) and submitted as electronic copies.
Party A and Party B shall perform the project work in accordance with the agreed-upon work plan, resource plan, and project schedule. If the release of iterations for Party A's business systems is delayed, the project schedule will be extended accordingly, and Party B will not be held responsible for the delay.
If a third party is involved, you and Alibaba Cloud are each responsible for signing contracts with your respective third parties. Alibaba Cloud is not responsible for the actions of or delays caused by your subcontractors or vendors. Likewise, you are not responsible for the actions of or delays caused by Alibaba Cloud's subcontractors or vendors.
Neither party is liable for any special, incidental, or indirect damages or consequential economic damages (including loss of profits or savings) under this contract, even if that party has been advised of the possibility of such damages.
4. Roles and responsibilities
4.1. Customer and Alibaba Cloud
After you purchase a Landing Zone edition (Basic, Standard, or Advanced), Alibaba Cloud will review and confirm the service.
For the duration of the service, both parties will agree on and confirm specific business goals and scope.
Service Type | Phase | Task Name | Task Details | Customer | Alibaba Cloud |
Landing Zone | Current state analysis | Infrastructure analysis | Analyze the user's deployment architecture. Collect data on the current relationships between compute, storage, middleware, and applications. Statistically analyze this data. | A/S/C/I | R/I |
Business and application system analysis | Understand the customer's current IT governance status and needs for cloud IT governance through remote information collection and on-site discussions. | A/S/C/I | R/I | ||
Landing Zone standards analysis | Collect the user's IT governance standards, such as security, network, account management, and billing standards, to understand the enterprise IT governance architecture. | A/S/C/I | R/I | ||
Solution design | Account management solution design | Design a management solution for enterprise user accounts, including SSO integration, MFA, and permission management. | A/S/C/I | R/I | |
Network planning solution design | Design a network planning solution based on the customer's network plan to meet the system's network requirements. | A/S/C/I | R/I | ||
Financial management solution design | Design a cloud cost management solution for the enterprise based on cost allocation tags to provide data support for future cost optimization and business decisions. | A/S/C/I | R/I | ||
Resource management solution design | Design a resource management plan based on the assessed cloud resource needs of the system to meet the application's requirements. | A/S/C/I | R/I | ||
Compliance audit solution design | Develop a compliance and audit solution using cloud products based on enterprise compliance audit standards to meet enterprise requirements. | A/S/C/I | R/I | ||
Security protection solution design | Develop a security protection solution using cloud products based on enterprise security standards to meet enterprise requirements. This only includes cloud security. | A/S/C/I | R/I | ||
Technical validation | Landing Zone solution technical validation | Validate the solution's technology and assist with issues encountered during the validation process. | A/S/C/I/R | S/C/I | |
Solution implementation | Landing Zone solution implementation | Implement the solution and assist with the technical implementation. | A/S/C/I | R/S/C/I |
Legend: R - Responsible, A - Accountable, C - Consulted, I - Informed, S - Support (assists "R" in completing the task)
4.1.1. Customer
You must appoint a project manager with appropriate skills and experience as the primary contact for communication with Alibaba Cloud. This person will be directly responsible for planning, coordinating, supervising, and controlling the project implementation, along with for escalating issues and risks. They will also have full authority to make decisions on all aspects of this project on your behalf.
The project manager for Party A coordinates resources and leads the research and technical validation for the Landing Zone based on the project requirements.
At the beginning of the project, you must provide internal IT governance-related materials and standard documents, and clearly state the execution requirements.
4.1.2. Alibaba Cloud
Alibaba Cloud will assign an experienced technical manager to manage the Landing Zone project, assemble and manage the Alibaba Cloud project team, and act as the primary contact for your project manager.
Alibaba Cloud will analyze the current state of your system to understand its basic architecture, business scenarios, technical components, and development frameworks, and to assess the Landing Zone standards.
You can design a landing zone solution based on an assessment of your current environment.
Alibaba Cloud will cooperate with you on the technical validation of the Landing Zone solution and help resolve any issues that arise during the process.
4.1.3. Completion criteria
Landing Zone Basic Edition completion criteria
Once the client confirms the Landing Zone solution design, it must include two components: account management, and network planning and security protection.
Deliverables:
Landing Zone Basic Governance Solution
Landing Zone Standard Edition completion criteria
The Landing Zone solution design is completed and confirmed by you. It must include account management, network planning, financial management, resource management, compliance audit, and security protection.
Deliverables:
Landing Zone Standard Governance Solution
Landing Zone Advanced Edition completion criteria
The Landing Zone solution is designed, implemented, and confirmed by you. It must include account management, network planning, financial management, resource management, compliance audit, and security protection.
Deliverables:
Landing Zone Advanced Governance Solution
4.2. Service catalog
The Landing Zone service includes the following services to help you meet your business goals:
Phase Name | Service Catalog | Landing Zone Basic Edition | Landing Zone Standard Edition | Landing Zone Advanced Edition |
Current state analysis | Infrastructure analysis | Supported | Support | Support |
Business and application system analysis | Support | Supported | Supported | |
Landing Zone standards analysis | Support | Support | Support | |
Solution design | Account management | Support | Support | Supported |
Network planning | Supported (Choose either network planning or security protection) | Support | Support | |
Financial management | Support | Supported | ||
Resource management | Support | Supported | ||
Compliance audit | Supported | Help and support | ||
Security protection | Supported (Choose either network planning or security protection) | Supported | Supported | |
Technical validation | Landing Zone solution technical validation | Support | Support | Support |
Solution implementation | Landing Zone solution implementation | Support |
5. Service-Level Agreement (SLA)
Provision of the Landing Zone service.
Provision of solution technical validation and on-site support as required during the service period.
Delivery of the "Landing Zone Basic Governance Solution," "Landing Zone Standard Governance Solution," or "Landing Zone Advanced Governance Solution" that corresponds to the purchased service edition.
6. Service flow
Landing Zone service flow

7. Acceptance criteria
7.1. Acceptance checklist
No. | Delivery Phase | Delivery Detail | Deliverable | Deliverable Type |
1 | Current state analysis phase | Infrastructure analysis | Landing Zone Current State Analysis Report | Document |
Business and application system analysis | ||||
Landing Zone standards analysis | ||||
2 | Solution design phase | Account management | Landing Zone Basic Governance Solution Landing Zone Standard Governance Solution Landing Zone Advanced Governance Solution | |
Network planning | ||||
Financial management | ||||
Resource management | ||||
Compliance audit | ||||
Security protection | ||||
3 | Technical validation | Solution technical validation | None | |
4 | Solution implementation | Solution technical implementation | None |
7.2. Acceptance standards
During project delivery, the provider offers Landing Zone consulting and records key information in the documentation. When you accept these document deliverables, you should confirm that the content meets your requirements.
If your business process requires internal reviews before deliverables are submitted, you are responsible for completing these reviews and reports before the acceptance deadline.
If the document content needs modification after a review meeting, Alibaba Cloud will make the changes and resubmit it for your acceptance. A representative designated by you will confirm receipt. Acceptance is confirmed by clicking the acceptance confirmation button on the public cloud service system page.
Landing Zone Basic Edition acceptance standard
The "Landing Zone Basic Governance Solution" meets your requirements.
Landing Zone Standard Edition acceptance standard
The "Landing Zone Standard Governance Solution" meets your requirements.
Landing Zone Advanced Edition acceptance standard
The Landing Zone Standard Administration Solution meets the required criteria.
7.3. Acceptance plan
Party A agrees to accept the project deliverables from Party B according to the acceptance plan detailed below. This plan is based on the content and deliverables specified for each phase in the '7.1 Acceptance Checklist'.
Landing Zone Basic Edition acceptance plan
No. | Acceptance Milestone | Acceptance Content | Acceptance Completion Signal |
1 | "Landing Zone Basic Governance Solution" design and validation completed | "Landing Zone Basic Governance Solution" | Customer confirms acceptance of the solution |
Landing Zone Standard Edition acceptance plan
No. | Acceptance Milestone | Acceptance Content | Acceptance Completion Signal |
1 | "Landing Zone Standard Governance Solution" design and validation completed | "Landing Zone Standard Governance Solution" | Customer confirms acceptance of the solution |
Landing Zone Advanced Edition acceptance plan
No. | Acceptance Milestone | ||
1 | "Landing Zone Advanced Governance Solution" design, validation, and implementation completed | "Landing Zone Advanced Governance Solution" | Customer confirms acceptance of the solution |
8. Completion signal
Customer acceptance is complete.