Purpose
This standard establishes the requirements for the governance, approval, operation, consumption, and lifecycle management of enterprise shared services.
The standard defines how shared services may be provided and consumed across Innovation, Enterprise, and Regulated workloads while maintaining appropriate governance, security, operational accountability, workload boundaries, and compliance requirements.
Scope
This standard applies to:
- Identity services
- Monitoring services
- Governance services
- Management services
- Automation services
- Integration services
- Platform services
- Shared data services
- University-managed shared technology capabilities
Shared Service Principles
Service Reuse
Common platform capabilities should be provided through approved shared services when practical.
Shared services reduce duplication, improve consistency, simplify operations, and support operational sustainability.
Governed Consumption
Shared service consumption shall follow approved governance processes, architecture requirements, and operational procedures.
Workload Boundaries
Consumption of a shared service does not eliminate workload ownership, workload accountability, security responsibilities, or workload boundary requirements.
Security Consistency
Shared services shall provide capabilities in a manner consistent with approved security, governance, monitoring, and compliance requirements.
Shared Service Categories
Shared services may include, but are not limited to:
- Identity services
- Monitoring services
- Governance services
- Management services
- Automation services
- Integration services
- Platform services
Shared Service Approval
Services shall be reviewed and approved before being designated as enterprise shared services.
Approval activities shall consider:
- Security requirements
- Operational requirements
- Data handling requirements
- Governance requirements
- Workload classification requirements
- Regulatory requirements
Service Classification
Approved Shared Services
Services may operate as approved shared services when they satisfy applicable governance, security, operational, and compliance requirements.
Approved shared services may support multiple workloads and workload classifications simultaneously when approved through governance processes.
Workload-Boundary Services
Services that require workload-specific deployment due to regulatory, security, contractual, architectural, or operational requirements shall remain within the applicable workload boundary.
Shared Service Consumption
Workloads may consume approved shared services when:
- The service has been approved for the workload classification.
- The service satisfies applicable security requirements.
- The service satisfies applicable governance requirements.
- The service satisfies applicable data handling requirements.
Workload owners remain accountable for their workload even when consuming shared services.
Identity Services
Approved shared identity services may provide:
- Authentication
- Identity governance
- Directory services
- Federation services
- Privileged access services
- Service identity capabilities
Monitoring Services
Approved shared monitoring services may provide:
- Operational monitoring
- Security monitoring
- Audit logging
- Alerting
- Reporting
- Investigation support
Governance Services
Approved governance services may provide:
- Policy enforcement
- Compliance visibility
- Governance reporting
- Standards implementation support
- Governance automation
Management Services
Approved management services may provide:
- Platform administration
- Inventory capabilities
- Operational management
- Administrative support services
Automation Services
Approved automation services may provide:
- Infrastructure deployment
- Platform automation
- Operational automation
- Configuration management
- Workflow orchestration
Security Requirements
Shared services shall implement security controls appropriate to the workloads and data they support.
Shared service implementations shall support:
- Identity governance
- Monitoring and auditability
- Operational accountability
- Incident investigation
- Compliance activities
Data Handling Requirements
Shared services that store, process, transmit, replicate, expose, or otherwise interact with protected data shall comply with applicable data protection requirements.
Data protection requirements remain applicable regardless of whether the service operates centrally or within a workload boundary.
Operational Responsibilities
Shared Service Owners
Shared service owners are responsible for: