Enable Self-Service Infrastructure & Deployment
This standard mandates the enablement of self-service infrastructure and deployment to reduce dependencies on central teams by providing controlled autonomy.
1. Enable Self-Service Infrastructure & Deployment:
Reduce dependencies on central teams by providing controlled autonomy. This approach ensures faster deployments and reduces bottlenecks.
- 1.1 Infrastructure as Code (IaC) Utilisation:
- 1.1.1 Pre-Approved Modules:
- Use Infrastructure as Code (IaC) with pre-approved modules.
- Automate the generation of pre-approved IaC modules.
- 1.1.2 Module Management:
- Automate the management of IaC module updates.
- Implement module usage tracking.
- 1.2 Automated Security Configurations:
- 1.2.1 Runtime Protections:
- Provide automated security configurations and runtime protections.
- Automate the configuration of security settings.
- 1.2.2 Protection Implementation:
- Automate the implementation of runtime protections.
- Implement protection feedback collection.
- 1.3 Role-Based Access Control (RBAC):
- 1.3.1 Just-In-Time (JIT) Approvals:
- Implement role-based access control (RBAC) with just-in-time (JIT) approvals.
- Automate the approval process.
- 1.3.2 Access Management:
- Automate the tracking of access requests.
- Implement access request tutorials.
By enabling self-service infrastructure, organisations can ensure faster deployments and reduce dependencies.