EN DE
Cloud

Infrastructure compliance at scale

Coriolis empowered a leading data security provider to revolutionize infrastructure compliance for banks and federal institutes worldwide. By swiftly implementing a comprehensive solution spanning private and public clouds, we enabled continuous assessment and remediation of infrastructure configurations. Our innovative approach not only optimized compliance for multiple clients but also secured lucrative contracts, including a major deal with a top US bank.

Client overview

  • Our client is a leading provider in data security and identity solutions which are used by leading banks, federal institutes across the US, EU and other regions of the world. With the increasing adoption of private and public clouds, it is important to ensure resources like VMs, data stores etc. on the cloud adhere to a defined set of configurations to ensure access and data security. There are various industry standards such as PCI DSS, GDPR etc which define expected sets of configurations.

The primary challenge faced by the client

Client wanted a solution which continually assesses and ensures infrastructure compliance with following requirements:

Supports pre-defined infrastructure config sets and a way to define custom configs.

Has scheduled validation of resources as per the defined configs.

Generates scheduled and on-demand reports per stakeholders’ requirements.

Supports automated and configurable remediation methods for non-compliant resources.

Solution

  • The Coriolis team worked on the design and implementation of an end to end solution which handles infrastructure compliance across both private and public clouds.

Implementation

The Coriolis team worked on the design and implementation of an end to end solution which handles infrastructure compliance across both private and public clouds.

Configuration and scheduling engine

We designed and implemented a configuration and scheduling engine which enables administrators to define configuration requirements specific to their infrastructure and schedule checks at different intervals.

Assessment and remediation engine

On request by scheduling service, assessment and remediation service is responsible for performing checks, remediation of non compliant resources and generating detailed results.

Reporting engine

Generates reports on demand or at predefined intervals. Generated reports can be used by administrators and IT teams to get overview of the infrastructure compliance readiness and act accordingly.

Results

  • We delivered this solution in a short time frame of around 4 months.

  • It helped our client to bag new contracts from several customers including one of the biggest banks in the US.

  • It helped several customers identify and fix a significant number of misconfigured resources, which in turn helped them optimize their infrastructure compliance.

Conclusion

  • Our innovative approach to infrastructure compliance across platforms empowered our client to meet the stringent security and compliance requirements of their banking clientele. The quick turnaround time helped them in getting new contracts. By delivering a fully automated fire and forget solution, we positioned our client for continued success in the rapidly evolving infrastructure landscape.

Other case studies