A Framework for Cloud-Integrated Database Hardening in Hybrid AWS-Azure Environments: Security Posture Automation Through Wiz-Driven Insights
DOI:
https://doi.org/10.38124/ijsrmt.v1i12.1098Keywords:
Cloud-Integrated Database Security, Hybrid Cloud Security Architecture, AWS–Azure Hybrid Environments, Database Hardening Framework, Cloud Security Posture Management (CSPM), Automated Security Posture Assessment, Wiz Security Insights, Multi-Cloud Risk Visibility, Cloud-Native Database Protection, Zero Trust Data Security, Security Posture Automation, Misconfiguration Detection in Cloud Databases, Compliance Monitoring in Hybrid Clouds, Continuous Security Assurance, Cloud Attack Surface Management, Identity and Access Management for Databases, Infrastructure-as-Code Security Validation, Threat Modeling for Hybrid Databases, Cross-Cloud Governance and Controls, DevSecOps-Driven Database SecurityAbstract
Cloud services allow enterprises to establish hybrid, multi-cloud environments. Such proliferation increases complexity and the attack surface, leading to needed security-, privacy-, and accessibility-compliance controls. Existing tools underutilize cloud providers’ compliance tools. Wiz automates asset inventory, vulnerability management, compliance drift detection, risk insights, and identity and access management. Cloud-integrated database hardening uses Wiz insights and guidance to automate hardening and compliance in heterogeneous clouds. Assets—data stores, storage accounts, and databases— proliferate in Azure and AWS, often within a single logical entity. A framework automates security posture, improving cloudintegrated database hardening in hybrid AWS–Azure environments. Data collection and telemetry follow Wiz-driven insights. Controls satisfy technical risks for hybrid asset-sharing scenarios. Attack surfaces and risks in heterogeneous AWS–Azure environments are specified and mitigated. Security controls are mapped to family and subfamily participants. Identity and access management splits responsibilities between Azure and AWS security flaws. Database service encryption meets Azure Secrets store and KMS risk categories. The threat landscape of hybrid solutions is broader than that of single- or multi-cloud deployments. Data-exfiltration-databaseleaking-risk scenarios for Azure are addressed by Wiz identity and access management recommendations and Microsoft and AWS database-service data-in-transit-and-at-rest-encryption controls. These recommendations automate security-compliance attestation. Azure data resource characteristics and Wiz approach are combined with risk categories for remaining clouds. A simple security-architecture pattern for control-expression mapping creates the required hardening.
Downloads
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2022 International Journal of Scientific Research and Modern Technology

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
PlumX Metrics takes 2–4 working days to display the details. As the paper receives citations, PlumX Metrics will update accordingly.