Information Security and Technology
Financial Crimes and Fraud Risk
What We Offer
search icon
exit icon
Information Security and Technology
Financial Crimes and Fraud Risk
search close button
Article
7/13/2023

infrastructure solution checklist

Build The Requirements for a Secure, Resilient Cloud Strategy

JH-BRAND-FY26-RDP-ArticleImage-DiversifyRevenueAndRetainCustomers-1420x900

Executive Summary

As you evaluate cloud providers, bringing together your technology, operations, security, risk, compliance, and finance stakeholders together ensures everyone aligns on what your financial institution requires.

Use these criteria to prioritize capabilities, uncover tradeoffs, and translate objectives into RFP criteria.


cloud architecture and control

  • Fits within a broader cloud strategy, including requirements for public, private, hybrid, or multi-cloud environments
  • Supports your core environment and required applications without unnecessary technology dependencies
  • Provides a dedicated Azure tenant you own, with co-management, Entra ID/RBAC access, audit visibility, and revocable provider access
  • Provides a transparent cost model that accounts for required computing, storage, licensing, and consumption while helping contain variable cloud expenses
  • Allows for built-in, secure connectivity, eliminating the need for complex, custom third-party integration routing. Ask vendors: What access and visibility will we have within our cloud environment?

Ask vendors: What access and visibility will we have within our cloud environment?

security and threat response

  • Applies standardized infrastructure controls, including infrastructure-as-code, drift control, policy guardrails, and role-based access control (RBAC)
  • Provides SASE capabilities, including next-generation firewall, secure web gateway, threat protection, DLP, CASB, DNS protection, and Zero Trust Network Access
  • Includes real-time EDR and 24/7 managed detection and response for cloud servers and cloud PCs, with options to extend protection to on-premises endpoints
  • Integrates security events through SIEM monitoring, alerting, and reporting

Ask vendors: Which security responsibilities do you manage and which remain with our financial institution?

resilience and recovery

  • Defines target RTO and RPO and provides dual-region failover to reduce dependency on a single environment
  • Provides immutable, air-gapped backups outside the Azure tenant, with defined retention and granular recovery options
  • Defines recovery capabilities for cyber events, natural disasters, infrastructure failures, and cloud outages
  • Includes ongoing business continuity and disaster recovery management

Ask vendors: How will you enable rapid recovery when preventive controls aren’t enough?

governance, risk, and compliance

  • Provides asset-inventory integration, governance policy templates, GRC tooling, expert advisory reviews, tabletop-test reporting, and gap-analysis reporting
  • Applies documented security and governance baselines aligned to CIS/NIST requirements and provides evidence such as a NIST 800-53 gap analysis
  • Maintains change-management logging and asset tracking
  • Provides accessible compliance evidence through dashboards, scheduled reports, and on-demand reporting
  • Helps consolidate oversight across cloud hosting, firewall, backup, endpoint protection, monitoring, and compliance

Ask vendors: How much evidence collection and ongoing platform governance will still fall to our employees?

operations and vendor management

  • Clearly defines responsibility for OS patching, network management, monitoring, platform management, security, and recovery
  • Provides comprehensive reporting and transparency of usage
  • Offers regular service reviews and access to governance, risk, compliance, and security expertise

Ask vendors: What does our team need to continue owning, and what operational responsibilities do you take on?

your RFP takeaway

The right infrastructure decision isn’t simply cloud versus on premises. Define the combination of control, security, resilience, compliance, cost predictability, and managed expertise your financial institution needs, then ask each provider to demonstrate how it delivers against those criteria.


enhance your cloud strategy with MSC-Azure

See how Jack Henry® Managed Secure Cloud, delivered through the Gladiator® Suite of Services, can help you balance modernization with control, security, resilience, and operational oversight as part of your broader cloud strategy.

floating background gradient

contact us