| Service | Description | Owner | Key Outputs |
|---|---|---|---|
| Policy-as-Code | Baseline policies and initiatives for Azure and hybrid | Cloud Security Service | Policy initiatives, assignments, compliance reports |
| Identity Security | Privileged access and role hygiene | Cloud Security Service | PIM reports, role reviews, break-glass controls |
| Logging & SIEM | Centralized logging and detections | Cloud Security Service | Log onboarding, analytic rules, dashboards |
| Incident Response | Coordinated response for cloud incidents | SecOps | Incident records, postmortems, lessons learned |
| Risk & Audit | Evidence and risk reporting | Service Manager | Risk register, audit evidence packs |
| Service | Description | Trigger |
|---|---|---|
| Configuration Review | Targeted posture review for workloads | Quarterly reviews or upon request |
| Threat Modeling Support | Guided threat modeling for new services | Project intake |
| Architecture Review | Security architecture advisory | New platform features |
- Operating model:
05-operating-model.md - Metrics & KPIs:
07-metrics-and-kpis.md