Enterprise Security Framework with Azure Arc based Compliance
The customer is a leading insurance provider in the United States. The client needed an infrastructure that was HITRUST and PCI compliant, while securing their applications hosted on Azure and on-premises. Their challenges included:
No centralized way to manage their operations or hybrid workloads.
No visibility into server workloads that have security and compliance risks.
No SIEM tools were in place for their current infrastructure a
The client’s tech team had limited experience with the Azure security tool set.
SNP proposed the Enterprise Security Framework with Azure Arc based Compliance where:
We introduced Azure Sentinel and integrated all the services for SOAR (Security Orchestration and Automation) for their infrastructure and applications.
Azure Arc was enabled for their application servers and Kubernetes environment.
We applied the HITRUST & PCI blueprint for all their required resources in the infrastructure and verified the compliance state.
SNP identified and applied remediations to non-compliant workloads
After a successful delivery of the engagement, the following benefits were achieved:
Securing the environment with all the required policies
Bringing visibility with Azure Sentinel and Azure Arc for their hybrid infrastructure
Continuous governance and compliance scanning across their hybrid workloads
Quick turnaround on remediating non-compliant workloads
Quick turnaround on applying compliance practices to their on-premises servers
Saved 500-man hours of efforts for customer’s internal security team to be ready