cloud-security-service-model is a public-safe, enterprise-grade operating model for a Cloud
Security Service delivered as a service/product for Azure and hybrid environments. It is a
docs-only repo — Markdown, Mermaid diagrams, and Bicep/policy-as-code implementation stubs;
no application code, no test suite.
Head of Cloud Platform Services, security leadership (CISO org), cloud engineering leads, audit/compliance stakeholders.
- Start with the executive overview and service definition.
- Use the operating model and metrics & KPIs to set expectations.
- Apply the templates and runbooks in operational workflows.
- Extend the implementation stubs in your own environment.
- Architecture — service model architecture and the NO-AZURE deploy / bicep-ready posture of the implementation stubs
- Operations — verified navigation and validation commands
- Decisions — index of recorded architectural decisions, including the in-progress DoNotEnforce policy ADR