Body
Purpose
This standard defines the governance requirements that provide consistent security, compliance, operational, financial, and management controls for Azure environments.
The standard establishes governance controls that support workload onboarding, operational sustainability, compliance management, and platform consistency through centralized governance processes and Management Group inheritance.
Scope
This standard applies to:
- Azure Management Groups
- Azure subscriptions
- Shared services environments
- Regulated workloads
- Non-regulated workloads
- Platform services
- Enterprise-managed Azure resources
This standard applies to all cloud environments governed through approved University Azure management structures.
Requirements
1. Management Group Governance
Azure Management Groups shall serve as the primary governance boundary for Azure environments.
Governance controls should be inherited through approved Management Group structures whenever practical.
2. Governance Inheritance
Subscriptions must inherit approved governance controls through Management Group placement.
Direct subscription-specific governance configurations should be minimized when inherited governance controls can be applied.
3. Policy Governance
Governance requirements shall be implemented through approved governance mechanisms including policies, standards, architecture patterns, automation, and operational processes.
Governance controls should be implemented consistently across supported environments.
4. Compliance Visibility
Governance controls must provide visibility into compliance status and governance adherence.
Governance implementations must support audit, review, and compliance activities.
5. Security Governance
Security controls must align with approved security standards, policy requirements, and platform governance controls.
Security governance should be implemented consistently across supported workloads.
6. Identity Governance
Governance processes must support approved identity management, access governance, role management, and privileged access controls.
Identity governance requirements must align with approved identity standards and patterns.
7. Monitoring Governance
Governance implementations must support operational monitoring, auditability, logging, compliance reporting, and incident investigation capabilities.
Monitoring controls must align with approved monitoring standards.
8. Resource Accountability
Cloud resources must have identified ownership and governance accountability.
Governance processes must support operational ownership, business ownership, and lifecycle accountability.
9. Lifecycle Governance
Governance processes must support:
- Provisioning
- Modification
- Operational management
- Decommissioning
through approved governance processes.
10. Shared Services Governance
Enterprise shared services supporting governed workloads must be evaluated and approved through governance and architecture processes.
Governance controls must identify approved shared services and applicable usage requirements.
11. Automation
Governance controls should be implemented through approved platform automation whenever practical.
Automation should support:
- Governance enforcement
- Policy deployment
- Compliance visibility
- Subscription onboarding
- Platform standardization
12. Governance Reviews
Governed environments must support periodic governance reviews sufficient to evaluate governance effectiveness, compliance status, security alignment, and operational adherence to approved standards.
13. Architecture Review
Implementations that deviate from approved governance structures, standards, or architecture patterns require architecture review and approval before implementation.
14. Exceptions
Exceptions to this standard require documented approval through the approved architecture exception process.