Skip to main content
Back to Tags

Governance

34 items tagged with "governance"

Filter by type:

Best Practices21

Best Practice

Azure Well-Architected Framework

Microsoft’s five-pillar guidance (reliability, security, cost, performance, ops) for designing and operating workloads on Azure.

Best Practice

FinOps Cloud Cost Best Practices

Shared responsibility model for cloud spend: Inform, Optimize, Operate phases.

Best Practice

OWASP Software Assurance Maturity Model (SAMM)

A maturity model that helps organizations assess and improve their software security program across governance, design, implementation, verification, and operations.

Best Practice

NIST Cybersecurity Framework 2.0

A voluntary framework of cybersecurity outcomes organized into six functions, govern, identify, protect, detect, respond, and recover, for managing organizational cyber risk.

Best Practice

NIST SP 800-53 Security and Privacy Controls

A comprehensive catalog of security and privacy controls for information systems, organized into control families with baselines for different risk levels.

Best Practice

Cloud Landing Zone

A pre-configured, secure, multi-account cloud foundation with baked-in identity, networking, governance, and guardrails so teams can deploy workloads safely at scale.

Best Practice

Data Governance Framework

A structured set of roles, policies, and processes that make an organization accountable for the quality, security, and proper use of its data assets.

Best Practice

Data Contracts

Explicit, version-controlled agreements between data producers and consumers that define schema, semantics, quality, and SLAs to prevent breaking changes.

Best Practice

Data Lineage

The traceable record of data's origin, movement, and transformation across systems, enabling impact analysis, debugging, compliance, and trust.

Best Practice

Schema Evolution and Schema Registry

Managing how data schemas change over time with compatibility rules and a central registry so producers and consumers evolve without breaking each other.

Best Practice

Data Catalog and Discovery

A searchable inventory of an organization's data assets with metadata, ownership, and lineage so people can find, understand, and trust the data they need.

Best Practice

ISO/IEC 42001 AI Management System

ISO/IEC 42001 is the first international standard for an Artificial Intelligence Management System, giving organizations a certifiable framework to govern AI responsibly.

Best Practice

AI TRiSM (Trust, Risk and Security Management)

AI TRiSM is a framework for managing the trust, risk, and security of AI systems across explainability, model operations, data protection, and runtime application security.

Best Practice

API-First Design

An approach that treats the API contract as a product designed before implementation, so teams agree on the interface, then build clients and servers in parallel.

Best Practice

API Backward Compatibility

Evolving an API without breaking existing clients by making only additive changes, versioning breaking changes, and deprecating fields gracefully over time.

Best Practice

Team Topologies

Team Topologies is a model for organizing business and technology teams using four team types and three interaction modes to optimize fast flow and reduce cognitive load.

Best Practice

Architecture Decision Records (ADRs)

An Architecture Decision Record (ADR) is a short, version-controlled document that captures one significant architectural decision, its context, and its consequences for future maintainers.

Best Practice

SOC 2 Compliance

SOC 2 is an AICPA auditing framework that assesses how a service organization protects customer data against five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.

Best Practice

PCI DSS Compliance

PCI DSS is the global security standard for organizations that handle payment card data, defining requirements to protect cardholder data across networks, systems, and processes.

Best Practice

GDPR Compliance Engineering

GDPR compliance engineering turns the EU General Data Protection Regulation's legal principles into concrete technical controls: lawful processing, data minimization, consent, and data-subject rights.

Best Practice

Cloud Cost Allocation and Tagging

Cloud cost allocation and tagging is the FinOps practice of labeling cloud resources with consistent metadata so spend can be attributed accurately to teams, products, and environments.