Cloud Security Framework — CivicNexus
Designed and implemented a cohesive Cloud Security Framework for a Smart City Operations Platform, aligning layered controls with ISO 27001 Annex A.
The problem
CivicNexus Innovations was deployed with insecure configurations, leaving critical assets exposed to data breaches, ransomware and weak access controls.
What I built
- 01
Conducted a group-level Asset-Threat-Vulnerability (ATV) analysis covering web servers, database servers and VDI instances.
- 02
Implemented network-layer controls with firewall rules and Security Groups/NACLs enforcing least-privilege access.
- 03
Hardened VM instances by managing access keys and hardening OS images; disabled non-essential services and applied patches.
- 04
Implemented data-at-rest encryption and file-level permissions to protect sensitive urban and personnel data.
- 05
Mapped all controls to ISO 27001 Annex A domains (A.5, A.8, A.12) for governance and compliance.
Project stages
No screenshots yet — add image URLs to this project’s images list to build the slideshow.