Failure to meet compliance requirements can result in expulsion from industry groups, hefty fines and, at worst, prosecution. Compliance monitoring is a critical practice, both on premises and in the cloud.

Compliance monitoring encompasses areas from the database to the network, and tasks from application updates to incident response. To build a cloud compliance monitoring strategy, first understand the regulations or standards that affect your business. Then, implement monitoring practices and tools based on your specific compliance requirements and the cloud platforms in use.

Understand compliance requirements Every industry has regulations, as well as bodies that issue certifications and accreditations. Government entities enforce regulations and standards. To track these, a company's legal department should have a list of applicable compliance standards. Some organizations include a compliance officer, and they may have an internal audit group as well. Common compliance standards or regulations include GDPR, the Sarbanes-Oxley Act, HIPAA and PCI DSS. Each compliance standard has an associated set of procedures that an organization must follow, as well as safeguards to apply. Cloud compliance monitoring is a matter of collecting and organizing data on these procedures and safeguards.

Key monitoring tasks Compliance monitoring in the cloud requires a number of tasks, including: application-access monitoring

database protection and surveillance

application change management

incident management and escalation

network monitoring and security

log monitoring and management One common strategy is to use the data collected by cloud and network monitoring tools to create a centralized view of compliance status across all these domains. This approach aligns well with current cloud and network monitoring practices. To start a cloud compliance monitoring strategy, divide the tasks identified above. Some are design-time considerations. Here, an application will meet or fall short of compliance standards based on how developers build it. Others are run-time considerations, meaning the application requires surveillance during operations to validate compliance. The specific tools and procedures an organization applies to its cloud applications depend on how compliance requirements map to these categories. Enforce design-time compliance standards into the development pipeline, and validate them through logging and version monitoring. The former requires a systematic way to initiate, execute, review, test and deploy cloud software. Teams must identify tools that enforce and document the requirements of each applicable standard. During application design and development, developers should insert event or logging triggers into code to make compliance events visible to monitoring tools. Tools for software security and pipeline management, such as Veracode and Checkmarx, help enforce design-time compliance requirements. Tools that audit software and data practices, including Momentum QMS, Black Duck from Synopsys and Gensuite, can be helpful additions. They are not specific to a particular cloud platform. Compliance management tools that control how user accounts access cloud applications and resources may also be useful, such as with Active Directory, LDAP and application access control or zero-trust tools. Cloud teams can use IT log and event management tools and practices to confirm design-time compliance. For example, log analysis can detect the completion of a records backup or a possible compliance violation via unauthorized access. The goal is to validate the practices established during application design, ensure their successful implementation, and identify anything missed or done incorrectly. Log aggregation, management and monitoring tools include products from Dynatrace, Sumo Logic, SolarWinds and many others.