This document serves as a practical, regulator-ready reference for designing, implementing, and operating a Microsoft Azure Landing Zone for Banking workloads, with explicit alignment to ISO 27001, PCI-DSS, FFIEC, and RBI (India) regulatory guidelines.
1. Azure Landing Zone for Banks
Azure Landing Zone (ALZ) is a predefined, policy-driven cloud foundation that enables banks to securely host regulated workloads while meeting governance, security, audit, and compliance mandates.
Core ALZ Principles
- Subscription isolation by environment and risk tier
- Centralized identity and access management
- Hub-and-Spoke network architecture
- Security-by-default with Zero Trust
- Policy-as-code enforcement
- Full auditability and traceability
2. Reference Architecture (Banking Grade)
Management Group Hierarchy
- Root Management Group (Bank)
- Platform MG
o Connectivity Subscription
o Security Subscription
o Management Subscription
- Landing Zone MG
o Production Subscriptions
o Non-Production Subscriptions
o DR Subscriptions
Compliance Value: Enforces segregation of duties, blast-radius containment, and audit scope isolation.
3. Identity & Access Management (IAM)
Azure Services
- Microsoft Entra ID (Azure AD)
- Privileged Identity Management (PIM)
- Conditional Access
- MFA (Mandatory)
Compliance Mapping
|
Regulation |
Requirement |
Azure Control |
|
ISO 27001 A.9 |
Access control |
RBAC, PIM |
|
PCI-DSS 7 & 8 |
Least privilege, MFA |
Entra ID, CA |
|
FFIEC |
Strong authentication |
MFA, PIM |
|
RBI |
Role-based access |
RBAC, CA |
4. Network Security Architecture
Mandatory Controls
- Hub-Spoke VNets
- Azure Firewall Premium (IDPS, TLS inspection)
- NSGs + UDRs
- Azure DDoS Protection Standard
- Private Endpoints for PaaS
- No direct internet exposure to core workloads
Compliance Mapping
|
Regulation |
Requirement |
Azure Control |
|
ISO 27001 A.13 |
Network security |
Firewall, NSG |
|
PCI-DSS 1 |
Network segmentation |
Hub-Spoke |
|
FFIEC |
Perimeter defense |
Firewall, WAF |
|
RBI |
Secure network zoning |
Hub-Spoke |
5. Data Protection & Cryptography
Azure Services
- Azure Key Vault (HSM-backed)
- Customer Managed Keys (CMK)
- Encryption at Rest & Transit
- Azure Disk Encryption
Compliance Mapping
|
Regulation |
Requirement |
Azure Control |
|
ISO 27001 A.10 |
Cryptography |
Key Vault |
|
PCI-DSS 3 |
Cardholder data encryption |
CMK |
|
FFIEC |
Key management |
HSM |
|
RBI |
Bank-owned keys |
CMK |
6. Logging, Monitoring & SIEM
Azure Services
- Azure Monitor
- Log Analytics
- Microsoft Sentinel
- Defender for Cloud
Controls Implemented
- Centralized log retention (minimum 1 year)
- Immutable audit logs
- Real-time security alerts
- Integration with Bank SOC/SIEM
Compliance Mapping
|
Regulation |
Requirement |
Azure Control |
|
ISO 27001 A.12 |
Logging & monitoring |
Azure Monitor |
|
PCI-DSS 10 |
Audit logging |
Sentinel |
|
FFIEC |
Continuous monitoring |
SIEM |
|
RBI |
Incident reporting |
Sentinel |
7. Vulnerability Management & Threat Protection
Azure Services
- Microsoft Defender for Cloud
- Vulnerability Assessment
- Azure Update Manager
Compliance Mapping
|
Regulation |
Requirement |
Azure Control |
|
ISO 27001 A.12.6 |
Vulnerability mgmt |
Defender |
|
PCI-DSS 11 |
Regular testing |
VA |
|
FFIEC |
Threat detection |
Defender |
|
RBI |
Cyber resilience |
Defender |
8. Business Continuity & Disaster Recovery
Azure Services
- Azure Site Recovery (ASR)
- Azure Backup
- Multi-region deployment (India regions)
Controls
- Defined RPO/RTO per application
- DR drills (minimum annually)
- Separate DR subscriptions
Compliance Mapping
|
Regulation |
Requirement |
Azure Control |
|
ISO 27001 A.17 |
BC/DR |
ASR |
|
PCI-DSS |
Availability |
Multi-region |
|
FFIEC |
Resilience testing |
DR drills |
|
RBI |
BCP compliance |
ASR |
9. Data Residency & Sovereignty (India)
Controls
- Deployment restricted to Azure India regions
- Azure Policy to block non-India regions
- Geo-redundancy within India only
- Controlled cross-border access
RBI Alignment: Data localization, supervisory access, audit rights.
10. Governance, Policy & Compliance Automation
Azure Services
- Azure Policy
- Policy Initiatives (Regulatory Compliance)
- Azure Blueprints (where applicable)
Examples
- Deny public IP on VMs
- Enforce encryption
- Enforce diagnostic logging
- Restrict SKU usage
11. Audit, Regulatory & Supervisory Access
Controls
- Read-only auditor access via RBAC
- Exportable logs and reports
- Documented HLD/LLD
- Support for RBI / CERT-In audits
12. Exit Management & Data Destruction
Controls
- VM export (VHD)
- Secure wipe (NIST-aligned)
- Certificate of data destruction
- Knowledge transfer
13. Summary – Why Azure Landing Zone for Banks
- Microsoft CAF-aligned architecture
- Regulator-accepted controls
- India data residency
- Strong audit and exit posture
- Proven adoption by Tier-1 banks