---
title: "The Three Pillars of Cloud Governance"
description: "Security Governance, Financial Governance and Operational Governance: concrete guardrails, maturity levels and what good versus poor governance looks like in practice."
sidebar:
  order: 1
  label: "Three Pillars"
source_url: "https://framework.stackit.cloud/advisory/governance/three-pillars/"
source_file: "docs/advisory/governance/three-pillars.mdx"
---

## The governance triangle

Cloud governance rests on three equally important pillars. Weakness in any one pillar destabilises the entire framework.

The three pillars form an equilateral triangle: Security Governance stands at the apex, Financial Governance and Operational Governance form the base. Weakness in one pillar destabilises the whole framework — an organisation that operates only Security Governance loses cost control and operational stability; one that focuses only on Operational Governance opens security gaps and budget risk.

## Pillar 1: Security Governance

**Purpose:** Ensure that cloud resources introduce no security vulnerabilities, that regulatory requirements are met, and that compliance is demonstrable.

### Core Security Guardrails

| Guardrail                          | Description                                             | Enforcement    |
| ---------------------------------- | ------------------------------------------------------- | -------------- |
| Geographic restriction             | Resources only in approved cloud regions within Germany | Hard-Mandatory |
| Encryption at rest                 | All data resources encrypted (AES-256 minimum)          | Hard-Mandatory |
| No public access without allowlist | No unrestricted public endpoints                        | Hard-Mandatory |
| IAM Least Privilege                | No wildcard permissions in production                   | Hard-Mandatory |
| MFA for all human access           | Console and API access with MFA                         | Hard-Mandatory |
| Immutable audit logs               | Logs in a separate, non-deletable logging project       | Hard-Mandatory |

### Security Governance Maturity

| Level                   | Characteristics                                                                           |
| ----------------------- | ----------------------------------------------------------------------------------------- |
| **Level 1: Reactive**   | Security problems are fixed after incidents. No preventive controls.                      |
| **Level 2: Preventive** | Core guardrails implemented. New resources are compliant. Legacy estate still open.       |
| **Level 3: Proactive**  | Continuous compliance monitoring. Automatic detection and alerting on deviations.         |
| **Level 4: Predictive** | Automated remediation. Security reviews in CI/CD. Threat modelling for new architectures. |

**Realistic target:** Level 3 after 12 months.

## Pillar 2: Financial Governance

**Purpose:** Ensure that cloud spend is transparent, traceable and within budget.

### Core Financial Guardrails

| Guardrail                  | Description                                       | Enforcement                          |
| -------------------------- | ------------------------------------------------- | ------------------------------------ |
| Mandatory tagging (6 tags) | No resource without a complete tag set            | Hard-Mandatory (deployment blocked)  |
| Budget alerts              | Alert at >80 % and >100 % of monthly budget       | Automatically configured             |
| Anomaly detection          | Alert at >20 % daily deviation from 7-day average | Automatically configured             |
| Sandbox budget caps        | Maximum monthly budget per sandbox project        | Hard-Cap (resources stopped)         |
| Reserved Instance policy   | Baseline workloads must be covered with RIs       | Advisory (recommended, not enforced) |

## Pillar 3: Operational Governance

**Purpose:** Ensure that cloud resources are operated, monitored and maintained to defined standards.

### Core Operational Guardrails

| Guardrail                       | Description                                               | Enforcement                |
| ------------------------------- | --------------------------------------------------------- | -------------------------- |
| IaC mandatory for production    | No manual portal configuration in production              | Process + audit            |
| Backup policy                   | All production data resources with backup policy          | Advisory + compliance scan |
| Monitoring minimum requirements | CPU, memory, disk, error rate for all services            | Mandatory for go-live      |
| Runbook requirement             | Every production service has an incident response runbook | Pre-go-live checklist      |
| Patch management                | Managed services: automatic. IaaS: within 30 days         | Monitoring                 |

## What good versus poor governance looks like in practice

|                 | Poor Governance                                    | Good Governance                                     |
| --------------- | -------------------------------------------------- | --------------------------------------------------- |
| **Security**    | Security reviews as a one-time gate before go-live | Continuous security as code in every pipeline       |
| **Financial**   | Monthly cost shock, unknown cost drivers           | Daily visibility, teams own their cloud costs       |
| **Operational** | Incident → chaos, nobody knows who is responsible  | Alert → runbook → defined team responds in \<30 min |

## Practical steps

1. **Governance maturity assessment**: Where does your organisation stand in each pillar?
2. **Core guardrails** implemented as Policy-as-Code
3. **Governance KPI dashboard** configured
4. **Monthly governance review** anchored in the CCoE rhythm
