Securing NRC's cloud environment with Microsoft Azure
The Norwegian Refugee Council (NRC) needed a secure foundation for its growing use of cloud services. Working with Cloudworks, NRC assessed its cloud security maturity and established security requirements and recommended configurations for Microsoft Azure, helping the organization scale its cloud environment while maintaining security and control.
Building a secure cloud platform
NRC relies on Microsoft services to support collaboration and knowledge sharing across its global organization. As the organization expanded its use of cloud services, seamless integration and strong security controls were essential.
Microsoft Azure provided the cloud platform, while NRC remained responsible for configuring appropriate security controls and protecting its applications and data. Cloudworks was engaged to help assess the existing security environment and establish a structured approach to securing NRC's cloud services.
Assessing cloud security maturity
The first step was to understand NRC's requirements and establish a clear picture of its existing security controls.
Cloudworks conducted a gap analysis to assess NRC's cloud security maturity, identifying the current state, potential gaps, and areas for improvement. The assessment provided a structured foundation for prioritizing security measures and developing the cloud environment further.
Establishing security requirements for Azure
Based on the assessment and NRC's requirements, Cloudworks helped establish security principles, requirements, and recommended configurations for the organization's Azure environment.
The work covered key areas including networking, data storage, role assignment, access control, certificates, encryption, logging, and incident response.
This provided NRC with a consistent approach to cloud security and a foundation for securely onboarding existing and future applications.
When we started using Microsoft Azure, it was crucial for us to get it right from the outset. With assistance from Cloudworks and their Cloud Security Framework, we established a structured approach to cloud security that could scale while maintaining control over services and third parties.
Mads Grandt, former Specialist Adviser Global ICT Operations in NRC
Building internal knowledge and long-term security
An important part of the project was also strengthening NRC's internal cloud security knowledge.
By establishing clear security requirements and recommendations, NRC gained a more structured approach to evaluating and onboarding cloud services. This enabled the organization to continue developing its Azure environment while maintaining greater control over security measures, services, and third parties.
