Providing customers visibility into security and compliance of services in a customer cloud infrastructure environment
Techniques for presenting information indicating infrastructure security and compliance of services of a customer cloud environment to a customer-facing dashboard are disclosed. The information presented to the customer-facing dashboard is a subset of information available to operators associated with a cloud service provider (CSP). A tier-one dashboard service obtains information indicating infrastructure security and compliance of services in the customer cloud infrastructure environment. The tier-one dashboard service presents the information indicating infrastructure security and compliance to CSP operators on a CSP-facing dashboard. The CSP-facing dashboard is not accessible by customer operators. A tier-two dashboard service obtains the infrastructure security and compliance information from the tier-one dashboard service and filters the infrastructure security information to create a subset of information indicating the security and compliance of the services. The subset of infrastructure security and compliance information is presented to operators associated with a customer of the CSP on a customer-facing dashboard.
1 . One or more non-transitory computer-readable media comprising instructions which, when executed by one or more hardware processors, cause performance of operations comprising:
obtaining, from a tier-one dashboard service, information indicating infrastructure security of a first set of one or more services;
wherein a first visual representation of the information indicating infrastructure security of the first set of one or more services is made available to a cloud service provider (CSP) via a CSP-facing dashboard;
filtering the information indicating infrastructure security of the first set of one or more services, obtained from the tier-one dashboard service, to generate a subset of the information indicating infrastructure security;
generating a first customer-facing dashboard comprising a second visual representation of the subset of the information indicating infrastructure security; and
presenting the first customer-facing dashboard to a first customer operator associated with a first customer of the CSP,
wherein the CSP is a first entity, the first customer of the CSP is a second entity, and the first customer of the CSP provides cloud services to an end user associated with a third entity.
2 . The one or more non-transitory computer-readable media of claim 1 , the operations further comprising:
obtaining, by the tier-one dashboard service, the information indicating infrastructure security of the first set of one or more services, wherein obtaining the information comprises:
monitoring the first set of one or more services; and
obtaining logs of the first set of one or more services;
generating, by the tier-one dashboard service, the CSP-facing dashboard; and
presenting, by the tier-one dashboard service, the CSP-facing dashboard to a CSP operator associated with the CSP.
3 . The one or more non-transitory computer-readable media of claim 1 , wherein based on one or more access policies, (a) the first customer-facing dashboard is accessible by the first customer operator, and (b) the CSP-facing dashboard is accessible by a CSP operator associated with the CSP and inaccessible by the first customer operator.
4 . The one or more non-transitory computer-readable media of claim 1 , the operations further comprising:
selecting, by the first customer of the CSP, a first compliance regime for the first set of one or more services, wherein the first customer-facing dashboard comprises a third visual representation of a first compliance status of the first set of one or more services according to the first compliance regime;
selecting, by a second customer of the CSP, a second compliance regime for a second set of one or more services;
generating a second customer-facing dashboard comprising a fourth visual representation of a second infrastructure status of the second set of one or more services, wherein the second customer-facing dashboard comprises a fifth visual representation of a second compliance status of the second set of one or more services according to the second compliance regime; and
presenting the second customer-facing dashboard to a second customer operator associated with the second customer of the CSP.
5 . The one or more non-transitory computer-readable media of claim 1 , wherein filtering the information indicating infrastructure security comprises:
removing one or more of proprietary information or personally identifying information to generate the subset of the information indicating infrastructure security.
6 . The one or more non-transitory computer-readable media of claim 1 , wherein the first set of one or more services is hosted by the CSP.
7 . The one or more non-transitory computer-readable media of claim 1 , wherein the first customer of the CSP subscribes to the first set of one or more services.
8 . The one or more non-transitory computer-readable media of claim 1 , wherein the end user of the first customer of the CSP uses the first set of one or more services.
9 . The one or more non-transitory computer-readable media of claim 1 , wherein the information indicating infrastructure security is made available to the first customer-facing dashboard via one or more APIs associated with the tier-one dashboard service.
10 . The one or more non-transitory computer-readable media of claim 1 , wherein obtaining, from the tier-one dashboard service, the information indicating infrastructure security of the first set of one or more services comprises: making calls to one or more APIs associated with the tier-one dashboard service for the information indicating infrastructure security of the first set of one or more services.
11 . The one or more non-transitory computer-readable media of claim 1 , wherein the first set of one or more services comprises one or more of: a security service; an abuse detection service; a fraud detection service; or a compliance service.
12 . A method comprising:
obtaining, from a tier-one dashboard service, information indicating infrastructure security of a first set of one or more services;
wherein a first visual representation of the information indicating infrastructure security of the first set of one or more services is made available to a cloud service provider (CSP) via a CSP-facing dashboard;
filtering the information indicating infrastructure security of the first set of one or more services, obtained from the tier-one dashboard service, to generate a subset of the information indicating infrastructure security;
generating a first customer-facing dashboard comprising a second visual representation of the subset of the information indicating infrastructure security;
presenting the first customer-facing dashboard to a first customer operator associated with a first customer of the CSP, and
wherein the CSP is a first entity, the first customer of the CSP is a second entity, and the first customer of the CSP provides cloud services to an end user associated with a third entity,
wherein the method is performed by at least one device including a hardware processor.
13 . The method of claim 12 , further comprising:
obtaining, by the tier-one dashboard service, the information indicating infrastructure security of the first set of one or more services, wherein obtaining the information comprises:
monitoring the first set of one or more services; and
obtaining logs of the first set of one or more services;
generating, by the tier-one dashboard service, the CSP-facing dashboard; and
presenting, by the tier-one dashboard service, the CSP-facing dashboard to a CSP operator associated with the CSP.
14 . The method of claim 12 , wherein based on one or more access policies, (a) the first customer-facing dashboard is accessible by the first customer operator, and (b) the CSP-facing dashboard is accessible by a CSP operator associated with the CSP and inaccessible by the first customer operator.
15 . The method of claim 12 , further comprising:
selecting, by the first customer of the CSP, a first compliance regime for the first set of one or more services, wherein the first customer-facing dashboard comprises a third visual representation of a first compliance status of the first set of one or more services according to the first compliance regime;
selecting, by a second customer of the CSP, a second compliance regime for a second set of one or more services;
generating a second customer-facing dashboard comprising a fourth visual representation of a second infrastructure status of the second set of one or more services, wherein the second customer-facing dashboard comprises a fifth visual representation of a second compliance status of the second set of one or more services according to the second compliance regime; and
presenting the second customer-facing dashboard to a second customer operator associated with the second customer of the CSP.
16 . The method of claim 12 , wherein filtering the information indicating infrastructure security comprises:
removing one or more of proprietary information or personally identifying information to generate the subset of the information indicating infrastructure security.
17 . The method of claim 12 , wherein obtaining, from the tier-one dashboard service, the information indicating infrastructure security of the first set of one or more services comprises: making calls to one or more APIs associated with the tier-one dashboard service for the information indicating infrastructure security of the first set of one or more services.
18 . A system comprising:
at least one device including a hardware processor; and
the system being configured to perform operations comprising:
obtaining, from a tier-one dashboard service, information indicating infrastructure security of a first set of one or more services;
wherein a first visual representation of the information indicating infrastructure security of the first set of one or more services is made available to a cloud service provider (CSP) via a CSP-facing dashboard;
filtering the information indicating infrastructure security of the first set of one or more services, obtained from the tier-one dashboard service, to generate a subset of the information indicating infrastructure security;
generating a first customer-facing dashboard comprising a second visual representation of the subset of the information indicating infrastructure security; and
presenting the first customer-facing dashboard to a first customer operator associated with a first customer of the CSP,
wherein the CSP is a first entity, the first customer of the CSP is a second entity, and the first customer of the CSP provides cloud services to an end user associated with a third entity.