Microsoft Defender for Cloud
Cloud and workloads

Determine ownership requirements for multicloud security planning

In brief

The article now focuses on identifying teams and ownership for multicloud security. It adds ownership-planning goals and best practices, updates section headings and anchors, and refreshes metadata.

What Defender admins need to know

Administrators can use the revised guidance to identify security functions, assign team responsibilities, and align ownership when planning multicloud Defender for Cloud deployments.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Determine ownership requirements

Identify teams and ownership for multicloud security

When you deploy a multicloud security solution with Microsoft Defender for Cloud, you need to determine which teams own specific security functions. This article is one of a series providing guidancehelps you plan ownership requirements as you design a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) solution across multicloud resources with Microsoft Defenderresources. It helps you identify the security teams involved in your multicloud environment, define their functions and responsibilities, align teams on ownership for Cloud.security decision making, and choose between centralized and decentralized operating models.

GoalOwnership planning goals

Identify the teams involved in your multicloud security solution, and plan how they will align and work together.

SecurityDefine security functions and responsibilities

Depending on the size of your organization, separate teams will manage security functions. In a complex enterprise, functions might be numerous.

|Posture management|Continuously reporting on, and improving, your organizational security posture.| |Incident preparation|Building tools, processes, and expertise to respond to security incidents. |

Team alignmentAlign teams on ownership responsibilities

Despite the many different teams who manage cloud security, it's critical that they work together to figure out who's responsible for decision making in the multicloud environment. Lack of ownership creates friction that can result in stalled projects and insecure deployments that couldn't wait for security approval.

|Application workloads|Focus on security controls for specific workloads. The goal is to integrate security assurances into development processes and custom line of business (LOB) applications.|Joint responsibility of application development and central IT operations teams.| |Identity security and standards | Understand Permission Creep Index (PCI) for Azure subscriptions, AWS accounts, and GCP projects, in order to identify risks associated with unused or excessive permissions across identities and resources.| Joint responsibility of identity and key management, policy and standards, and security architecture teams. |

Best practices for assigning ownership

Consider the following best practices when assigning ownership and aligning teams in a multicloud security model:

  • Although multicloud security might be divided across different areas of the business, teams should manage security across the multicloud estate. This is better than having different teams secure different cloud environments. For example where one team manages Azure and another team manages AWS. Teams working across multicloud environments helps to prevent sprawl within the organization. It also helps to ensure that security policies and compliance requirements are applied in every environment.
  • Often, teams that manage Defender for Cloud don't have privileges to remediate recommendations in workloads. For example, the Defender for Cloud team might not be able to remediate vulnerabilities in an AWS EC2 instance. The security team might be responsible for improving the security posture, but unable to fix the resulting security recommendations. To address this issue:the gap between security posture responsibility and remediation authority:
  • Depending on organizational models, we commonly see these options for central security teams operating with workload owners:

Next steps

In this article, you have learnedThis guidance covered how to determine ownership requirements when designing a multicloud security solution. Continuesolution with Microsoft Defender for Cloud. To plan ownership, identify the next stepsecurity functions your organization needs, assign clear team responsibilities for each function, and choose a centralized or decentralized operating model. After you establish ownership, continue to Determine access control requirements.