Security review of an enterprise analytics platform
- Sector
- Financial services
- Scale
- Enterprise analytics platform, large and varied data estate
Situation
A large analytics platform was coming up to production. Given the size of the data estate it ran over, it needed an architectural security review and regulatory assurance before it could go live.
Constraints
The delivery timeline was live, so the review had to keep pace with it. The data estate was large and varied. The regulatory obligations had to be evidenced rather than asserted, which is a higher bar than it sounds.
Approach
I led the review. That meant threat modelling the platform, assessing the design against both enterprise standards and the regulatory requirements that applied to it, and then setting out the conditions it had to meet before it could proceed.
Outcome
The platform went to production with an evidenced compliance position and an agreed set of mitigations, rather than a general assurance that it looked sound.
Frameworks: NIST CSF v2 · Regulatory compliance · Threat modelling