Tier0
Overview
Tier0 is a cloud enabled shared services infrastructure. It has the common capabilities required by state government security and compliance standards.
It is a unified environment to support SGS customers and products in helping them enforcing government issued guidelines so that the client can completely focus on application development.
It provides core capabilities like Centralized Logging (Launchpad), Perimeter Protection (Ingress), Policies and Tier0 Sentinel.
Tier0 services provide a security baseline enforced through Azure Policy/Perimeter Protection. Additional policies for more stringent compliance frameworks can be layered into individual client solutions.
It has a strong governance that provides uniform rules for resource management, resource naming convention and deployment. It also helps in keeping the products secure and compliant.
The solution is built to provide Security, Permieter Protection and Governance to the client as a single package offering. Furthermore, it is an expandable product and keep adding more client services.
Benefits
- Goverment policies compliant.
- Centralized governance and control in SGS.
- Reusable services and patterns.
- Redundant and high availability - Event driven services failover.
- Cost effective – Common/shared services allows to reduce overall cost for the clients.
- Expandable – Can add more services.
Key Product Offerings
- Centralized Logging (Launchpad) Centralized logging architecture gathers and consolidates log data from multiple servers, applications, and services across cloud platforms into a central location for easy analysis and management.
- Perimeter Protection (Ingress) Ingress acts as the entry point for the cluster. It offers a simplistic gateway type solutions. Ingress settings are enforced through a set of rules that control the routing of external and internal traffic.
- Policy The policies help enforce adherence to the minimally required security measures, assisting teams in meeting those criteria right away and giving them a simple way to detect and swiftly fix any serious findings. Typically covered policies are CL, Launchpad and HCC.
- Sentinel Alert/ Health Alerts Security Alert configured via Sentinel and Health Alert of resources.