Skip to content

a-bonfim-tech/audit-only-cloud-governance-kit

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

6 Commits
 
 
 
 

Repository files navigation

Audit-Only Cloud Governance Kit (GCP-first, multicloud-aware)

EN PT-BR DE

Sponsor

What this is

A public, open-source kit for cloud governance with a strict audit-only posture:

  • IAM baseline checks and least-privilege patterns
  • Compliance-aware evidence packs
  • Threat-model driven playbooks
  • GCP-first reference implementations, with multicloud awareness

Sponsor principles (ethics-first)

I study ethics seriously. For me, ethics also includes loyalty and belonging with no expiration date. If you sponsor this work, you are supporting a long-term, credibility-first program: reproducible security governance assets, shipped in public, with transparent reporting.

Master’s in Technology (secured seat/offer)

I already hold a secured seat/offer for a Master’s in Technology. Sponsorship helps sustain the time and infrastructure required to keep this project shipping at a professional standard while advancing that degree.

Discreet Brazil travel (privacy and security)

There is also a required, discreet trip to Brazil for privacy and personal security reasons, to conduct stakeholder alignment and requirements gathering connected to: Cloud computing + governance + cybersecurity + IAM. The output of that fieldwork will be reflected as public deliverables in this repository, without exposing sensitive personal logistics.

What ships every month (baseline commitment)

  • 1 new or upgraded playbook (with validation steps)
  • 1 policy template or guardrail pattern
  • 1 audit-only script improvement (reporting/evidence)
  • 1 sponsor report in /reports

Repository structure

  • /playbooks — reproducible security governance playbooks
  • /policies — policy templates and rationale
  • /scripts-audit-only — state collection and reports (audit-only)
  • /evidence-packs — audit evidence structure
  • /adr — architecture decisions
  • /reports — monthly sponsor reports
  • /assets — images used in the README

About

Audit-only cloud governance kit for documenting security decisions, evidence, controls, and compliance-safe cloud risk reasoning.

Topics

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

No releases published

Sponsor this project

 

Packages

 
 
 

Contributors