Data security in a cloud computing environment
An event notification can be received. The event notification can indicate a customer impacting event and a cloud resource name of a cloud resource to which the customer impacting event pertains. Data contained in the cloud resource name can be parsed. Information specifically relevant to the customer impacting event and the cloud resource to which the customer impacting event pertains can be accessed. A document or file including at least a portion of the information specifically relevant to the customer impacting event and the cloud can be created. Responsive to the link to the uniform resource identifier assigned to the document or file being selected, the document or file including the at least the portion of the information specifically relevant to the customer impacting event and the cloud resource to which the customer impacting event pertains can be communicated to a client device.
1 . A computer-implemented method, comprising:
receiving an event notification, wherein
the event notification indicates a customer impacting event and a cloud resource name of a cloud resource to which the customer impacting event pertains, and
the event notification comprises a link to a record that initially is empty;
based on the receiving of the event notification, parsing, in real time, data contained in the cloud resource name;
querying, using at least a plurality of parameters parsed from the cloud resource name, a compliance evidence database;
accessing, based on the querying of the compliance evidence database, information specifically relevant to the customer impacting event and the cloud resource;
creating, in real time using a processor, a document or a file including at least a portion of the information specifically relevant to the customer impacting event and the cloud resource, wherein the document or the file is accessible to a client device using the link to a uniform resource identifier;
assigning the uniform resource identifier to the document or the file based on the creating of the document or the file, wherein the assigning of the uniform resource identifier to the document or the file includes writing the record that initially is empty with the document or the file; and
based on the link to the uniform resource identifier being selected, communicating to the client device the document or the file.
2 . The computer-implemented method of claim 1 , wherein the accessing of the information specifically relevant to the customer impacting event and the cloud resource comprises accessing security compliance exceptions pertaining to at least one security vulnerability to which the cloud resource is susceptible.
3 . The computer-implemented method of claim 2 , further comprising:
determining a severity of the at least one security vulnerability based on one or more missing or insufficient mitigation measures for the at least one security vulnerability in the security compliance exceptions.
4 . The computer-implemented method of claim 2 , wherein the accessing of the security compliance exceptions pertaining to the at least one security vulnerability to which the cloud resource is susceptible comprises accessing the security compliance exceptions from a governance risk and compliance system.
5 . The computer-implemented method of claim 1 , wherein
the parsing of the data contained in the cloud resource name comprises parsing, from the cloud resource name, a location of the cloud resource; and
the querying of the compliance evidence database comprises querying of the compliance evidence database using the location of the cloud resource as a query search parameter.
6 . The computer-implemented method of claim 1 , further comprising:
limiting dissemination of sensitive security information pertaining to the customer impacting event only to information that is useful for analyzing and resolving the customer impacting event.
7 . A system, comprising:
a processor programmed to initiate executable operations comprising:
receiving an event notification, wherein
the event notification indicates a customer impacting event and a cloud resource name of a cloud resource to which the customer impacting event pertains, and
the event notification comprises a link to a record that initially is empty;
based on the receiving of the event notification, parsing, in real time, data contained in the cloud resource name;
querying, using at least a plurality of parameters parsed from the cloud resource name, a compliance evidence database;
accessing, based on the querying of the compliance evidence database, information specifically relevant to the customer impacting event and the cloud resource;
creating, in real time, a document or a file including at least a portion of the information specifically relevant to the customer impacting event and the cloud resource, wherein the document or file is accessible to a client device using the link to a uniform resource identifier;
assigning the uniform resource identifier to the document or the file based on the creating of the document or the file, wherein the assigning of the uniform resource identifier to the document or the file includes writing the record that initially is empty with the document or the file; and
based on the link to the uniform resource identifier-being selected, communicating to the client device the document or the file.
8 . The system of claim 7 , wherein the accessing of the information specifically relevant to the customer impacting event and the cloud resource comprises accessing security compliance exceptions pertaining to at least one security vulnerability to which the cloud resource is susceptible.
9 . The system of claim 8 , the executable operations further comprising:
determining a severity of the at least one security vulnerability based on one or more missing or insufficient mitigation measures for the at least one security vulnerability in the security compliance exceptions.
10 . The system of claim 8 , wherein the accessing of the security compliance exceptions pertaining to the at least one security vulnerability to which the cloud resource is susceptible comprises accessing the security compliance exceptions from a governance risk and compliance system.
11 . The system of claim 7 , wherein
the parsing of the data contained in the cloud resource name comprises parsing, from the cloud resource name, a location of the cloud resource; and
the querying of the compliance evidence database comprises querying of the compliance evidence database using the location of the cloud resource as a query search parameter.
12 . The system of claim 7 , the executable operations further comprising:
limiting dissemination of sensitive security information pertaining to the customer impacting event only to information that is useful for analyzing and resolving the customer impacting event.
13 . A computer program product, comprising:
one or more computer readable storage mediums having program code stored thereon, the program code stored on the one or more computer readable storage mediums collectively executable by a data processing system to initiate operations including:
receiving an event notification, wherein
the event notification indicates a customer impacting event and a cloud resource name of a cloud resource to which the customer impacting event pertains, and
the event notification comprises a link to a record that initially is empty;
based on the receiving of the event notification, parsing, in real time, data contained in the cloud resource name;
querying, using at least a plurality of parameters parsed from the cloud resource name, a compliance evidence database;
accessing, based on the querying of the compliance evidence database, information specifically relevant to the customer impacting event and the cloud resource;
creating, in real time, a document or a file including at least a portion of the information specifically relevant to the customer impacting event and the cloud resource, wherein the document or file is accessible to a client device using the link to a uniform resource identifier;
assigning the uniform resource identifier to the document or the file based on the creating of the document or the file, wherein the assigning of the uniform resource identifier to the document or the file includes writing the record that initially is empty with the document or the file; and
based on the link to the uniform resource identifier being selected, communicating to the client device the document or the file.
14 . The computer program product of claim 13 , wherein the accessing of the information specifically relevant to the customer impacting event and the cloud resource comprises accessing security compliance exceptions pertaining to at least one security vulnerability to which the cloud resource is susceptible.
15 . The computer program product of claim 14 , wherein the program code further initiate the operations comprising:
determining a severity of the at least one security vulnerability based on one or more missing or insufficient mitigation measures for the at least one security vulnerability in the security compliance exceptions.
16 . The computer program product of claim 14 , wherein the accessing of the security compliance exceptions pertaining to the at least one security vulnerability to which the cloud resource is susceptible comprises accessing the security compliance exceptions from a governance risk and compliance system.
17 . The computer program product of claim 13 , wherein
the parsing of the data contained in the cloud resource name comprises parsing, from the cloud resource name, a location of the cloud resource; and
the querying of the compliance evidence database comprises querying of the compliance evidence database using the location of the cloud resource as a query search parameter.