Governance¶
Governance covers the tenant-wide rules and evidence that keep the platform under control: which policies apply, how resources are tagged, what is logged, how posture is measured, and where the platform knowingly departs from its own rules. The Security Model decides who can change the tenant. Governance makes sure every change is checked and leaves a record.
Policy and standards
- Azure Policy (EPAC): policy as code, the three-layer model, moving from audit to enforcement, and exemptions.
- Tagging Standard: the eleven mandatory tags, and how they are applied and checked.
- Regulatory Compliance: the standards measured in Defender for Cloud, and the evidence behind them.
Logging and evidence
- Entra ID Diagnostic Settings: Entra ID sign-in, audit and identity-protection logs to the central workspace.
- Subscription Activity Logs: every subscription's Activity Log to the same workspace, through Terraform and Azure Policy.
Measuring and reporting
- Defender for Cloud Secure Score: what the score measures, and why it can swing sharply from week to week.
- Governance Reporting: AzGovViz, the analyzer, the RBAC extract and the Entra role reports.
Decisions and exceptions
- Exceptions Register: every accepted exception and known gap in one place.
- Architecture Decision Records: an index of the platform's recorded decisions.
Related: