A cloud landing zone is not a one-time security configuration. It is a governed operating environment that must keep identity, networks, data, workloads, changes, vendors, monitoring, and recovery within approved boundaries as modernization teams release new services.
Begin with shared responsibility
For each service and control, identify what the cloud provider, software provider, implementation partner, managed service, and bank operate. Map ownership to policies, procedures, technical enforcement, monitoring, testing, exceptions, evidence, and escalation. Do not assume a provider certification proves the bank's configuration or operating control.
Build preventive and detective controls together
Identity and privilege
Federate identity, require strong authentication, separate roles, limit standing privilege, control service identities, review access, and log material actions.
Network and workload boundaries
Segment environments, restrict ingress and egress, approve connectivity, harden images, scan dependencies, protect secrets, and control administrative paths.
Data protection and use
Classify data, enforce encryption, keys, access, masking, retention, deletion, lineage, residency, nonproduction use, and loss-prevention requirements.
Logging and response
Centralize tamper-resistant logs, monitor control and configuration changes, define alerts, preserve evidence, test escalation, and coordinate provider incidents.
Make infrastructure and policy reproducible
Use version-controlled infrastructure and policy definitions, peer review, automated checks, separation of duties, approved pipelines, artifact integrity, environment promotion, drift detection, and verified rollback. Preserve the approved version and deployment evidence for material changes.
Design resilience for banking dependencies
Set recovery objectives based on business service, not individual components. Map identity, networks, keys, data, vendors, regions, integrations, and operator access required for recovery. Test degraded modes, backup integrity, restoration, failover, failback, and reconciliation of transactions and data.
Use continuous evidence
Collect configuration, access, deployment, vulnerability, logging, backup, recovery, incident, exception, vendor, and remediation evidence from controlled sources. Link evidence to control owners and define how often it is evaluated, what constitutes failure, and how issues are tracked to closure.
A practical control rollout
- Map business services, data, dependencies, responsibilities, and regulatory obligations.
- Define a minimum landing-zone control baseline and approved exception process.
- Automate preventive policies and the evidence needed to confirm operation.
- Pilot with one bounded workload and test normal, failure, recovery, and change scenarios.
- Scale through reusable patterns, monitoring, ownership, and periodic independent testing.




