You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: source/docs/cloud/aws-shared-responsibility-model.html.md.erb
+1-1Lines changed: 1 addition & 1 deletion
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ review_in: 12 months
7
7
# <%= current_page.data.title %>
8
8
9
9
Cabinet Office Digital Cloud provides these added-values activities and services, in addition to the [standard services](https://docs.aws.amazon.com/whitepapers/latest/aws-overview/amazon-web-services-cloud-platform.html) offered by AWS
10
-
# AWS Cloud Shared Responsibility Model
10
+
## AWS Cloud Shared Responsibility Model
11
11
12
12
Cabinet Office Digital Cloud provides these added-values activities and services, in addition to the [standard services](https://docs.aws.amazon.com/whitepapers/latest/aws-overview/amazon-web-services-cloud-platform.html) offered by AWS.
Copy file name to clipboardExpand all lines: source/docs/cloud/sandbox-policy.html.md.erb
+11-11Lines changed: 11 additions & 11 deletions
Original file line number
Diff line number
Diff line change
@@ -5,21 +5,21 @@ review_in: 6 months
5
5
---
6
6
# <%= current_page.data.title %>
7
7
8
-
## **1.0 Purpose**
8
+
## **Purpose**
9
9
10
10
This policy governs the use of cloud sandbox environments. It ensures that innovation and experimentation can happen safely, securely, and cost-effectively. It provides a clear process for managing sandboxes from creation to deletion, and for moving successful experiments towards production.
11
11
12
12
This applies to both AWS and Azure accounts.
13
13
14
-
## **2.0 Scope**
14
+
## **Scope**
15
15
16
16
This policy applies to all technical staff using or managing cloud sandbox environments on AWS, Azure and other hosting environments. This includes developers, engineers, data scientists, and architects. It also applies to anyone responsible for approving or reviewing sandbox activity, including the Head of Engineering and the Technical Design Authority (TDA).
17
17
18
18
This policy covers all cloud environments designated as a 'sandbox'. A sandbox is a temporary, isolated environment for prototyping, training, or experimentation. It is not intended for hosting live services.
19
19
20
-
## **3.0 Key Policies**
20
+
## **Key Policies**
21
21
22
-
### **3.1 Data Usage**
22
+
### **Data Usage**
23
23
24
24
You must not use live, production-level, sensitive data or personally identifiable information (PII) in any sandbox environment.
25
25
@@ -29,15 +29,15 @@ You must not use live, production-level, sensitive data or personally identifiab
29
29
30
30
You must use synthetic or anonymised data for testing and development in a sandbox.
31
31
32
-
### **3.2 System Integration**
32
+
### **System Integration**
33
33
34
34
You must not connect a sandbox to any live production system, service, or network.
35
35
36
36
All sandbox environments must be completely isolated. This prevents experimental code from affecting the stability and security of live services. It also protects production systems from potential vulnerabilities in test environments.
37
37
38
-
## **4.0 Governance Process**
38
+
## **Governance Process**
39
39
40
-
### **4.1 Requesting a Sandbox**
40
+
### **Requesting a Sandbox**
41
41
42
42
To get a sandbox, you must submit a request to the Head of Engineering for approval.
43
43
@@ -48,13 +48,13 @@ Your request must include:
48
48
* A justification for the experiment
49
49
* Estimated sandbox duration
50
50
51
-
### **4.2 Budget and Timeline**
51
+
### **Budget and Timeline**
52
52
53
53
Your request must define a maximum budget (spend cap) and a fixed timeline (expiry date) for the sandbox.
54
54
55
55
The platform team will monitor spending against your approved budget. The sandbox and all its resources will be decommissioned on the agreed expiry date. You must request a formal extension from the Head of Engineering if you need more time.
56
56
57
-
### **4.3 Path to Production (TDA Approval)**
57
+
### **Path to Production (TDA Approval)**
58
58
59
59
You must get formal approval from the Technical Design Authority (TDA) before a project developed in a sandbox can move into production-level development.
60
60
@@ -65,7 +65,7 @@ To get approval, you must present the outcomes of your experiment to the TDA. Th
65
65
* Full cost analysis for production, including running and support costs
66
66
* Alignment with departmental technology strategy
67
67
68
-
## **5.0 Roles and Responsibilities**
68
+
## **Roles and Responsibilities**
69
69
70
70
**You (the sandbox user)** are responsible for:
71
71
@@ -90,7 +90,7 @@ The **Platform Team** is responsible for:
90
90
* Monitoring sandbox costs and security compliance
91
91
* Decommissioning sandboxes on their expiry date
92
92
93
-
## **6.0 Policy Violations**
93
+
## **Policy Violations**
94
94
95
95
Failure to comply with this policy will result in the immediate suspension or deletion of your sandbox environment.
0 commit comments