Aug 2026· American Journal of Technology· Vol 5, pp. 84-105· 0 citations
TL;DR
Organizations operating regulated database workloads across two or more public clouds should prioritize federated identity management, policy-as-code security baselines, centralized telemetry, and automated audit-evidence generation before expanding provider-specific security tooling.
Abstract
Aim: This study aims to develop a provider-neutral security architecture and a quantitative decision model for evaluating alternative approaches to securing regulated database workloads across multiple public clouds.
Methods: The study employs a model-driven comparative evaluation rather than an empirical research design. Three PCI DSS v4.0- and HIPAA-regulated workload profiles are evaluated across centralized, fragmented, and hybrid multi-cloud security architectures. The analysis integrates published cloud-service pricing, task-level estimates of operational effort, a five-theme compliance-coverage rubric, and sensitivity analysis covering variations in cost, labor rates, tooling requirements, log volumes, and data-residency assumptions. All inputs used in the worked example are reproduced in the study to facilitate transparency and replication.
Results: The modeled results indicate that the centralized UMDSP architecture costs 20.7%–25.2% less annually than the fragmented architecture, with a 22.1% cost reduction in the worked example, while maintaining comparable overall compliance-control coverage. However, the centralized approach provides greater audit-evidence coverage, reaching 94% compared with 83% for the fragmented architecture. The cost advantage remains relatively stable under variations in log volume and labor rates but declines to approximately 12% - 18% under conservative assumptions concerning operational effort and tooling. The advantage also decreases when data-residency requirements necessitate duplicated regional analytics. The findings are based entirely on modeled scenarios and have not yet been validated through production deployments.
Conclusion: The modeled cost advantage appears to arise primarily from reducing duplicated and inconsistent governance processes rather than from eliminating security controls.
Recommendations: Organizations operating regulated database workloads across two or more public clouds should prioritize federated identity management, policy-as-code security baselines, centralized telemetry, and automated audit-evidence generation before expanding provider-specific security tooling.
Telecommunications organizations face mounting pressure to manage data infrastructure that is simultaneously scalable, cost-efficient, privacy-compliant, and secure. Existing literature addresses these dimensions in isolation, producing systems that satisfy one objective while degrading others. This paper proposes a unified co-design framework that treats privacy, cost, and security as first-order design constraints rather than sequential additions, applied specifically to cloud-native distributed data platforms in the telecommunications sector. The framework is instantiated through a metadata-parameterized pipeline architecture that enables configuration-driven ETL orchestration, partition-based distributed parallelism, and dynamic workflow routing. Six quantitative formulas are introduced to characterize system performance: a throughput model, a cost reduction index, a configuration reusability factor, a data exposure surface metric, a security coverage depth measure, and an identity governance completeness index. Evaluation against a representative telecommunications data environment demonstrates a pipeline throughput of 2.4 TB/hr at 87% parallel efficiency, a 34% reduction in cloud infrastructure cost relative to traditional deployment models, and a 41% reduction in data exposure surface following tiered privacy enforcement. Security coverage depth reached 0.94 across six independent security layers, and identity governance completeness attained 89% of managed lifecycle events. The framework is validated against GDPR Article 5(1)(c), CCPA Section 1798.100, CISA Zero Trust Maturity Model v2.0, and NIST IR 8505 guidance for cloud-native data protection. Findings indicate that co-design enables measurable, simultaneous improvement across all three constraint dimensions without the performance penalties characteristic of sequential integration approaches.
Suresh Tambe· International journal of com...· 0 citations
Aim: This study aimed to design and evaluate a cloud-native reference architecture for real-time payment processing that integrates microservices, event-driven communication, infrastructure-as-code, and federated AIOps to improve scalability, resilience, regulatory compliance, and operational efficiency. The novelty of the study is the federated three-tier integration model that combines ITIL-aligned governance, DevOps continuous delivery, and AIOps-driven anomaly detection within a single payment-specific reference architecture.
Methods: A mixed-methods design was employed, combining a structured synthesis of peer-reviewed and industry literature with quantitative benchmarking of instrumented cloud-native reference deployments. The deployments were scaled from 1 to 128 service replicas across two public clouds and an on-premise environment and were evaluated against a representative monolithic baseline.
Results: The findings show that the proposed cloud-native architecture reduced end-to-end p99 latency from approximately 850 ms in the monolithic baseline to approximately 180 ms, representing a 4.7× improvement. Sustained throughput scaled near-linearly to 78,000 transactions per second across 128 service replicas, compared with approximately 3,800 transactions per second in the baseline. Federated AIOps reduced Mean Time to Detect (MTTD) by 60% and Mean Time to Resolve (MTTR) by 50%, while alert volume and false-positive rates decreased by 70% and 82%, respectively. The architecture achieved 99.99% availability, with a Recovery Time Objective (RTO) of less than five minutes and a Recovery Point Objective (RPO) of less than 30 seconds across multi-region active-active deployments. The study also identifies operational complexity, multi-cloud cost overhead, and managed-service vendor lock-in as key limitations.
Conclusion: The findings indicate that cloud-native architectures can substantially improve the scalability, operational resilience, and regulatory readiness of real-time payment systems compared with conventional monolithic designs.
Recommendation: Financial institutions planning payment modernization should consider a phased adoption of cloud-native architectures supported by integrated governance, automation, and observability practices. The proposed framework should also be validated across diverse production payment environments.
Midhun Michael Nelavala· American Journal of Technolo...· 0 citations
The use of multi-clouds has taken the form of a leading architecture trend in organizations that desire a resilient, vendor-independent enterprise, regulatory-compliant, and cost-performance trade-off platforms. Nevertheless, allocating workloads, data and identities among heterogeneous cloud service providers (CSPs) present challenging and dynamic security issues. In this paper, the author offers an in-depth and detailed discussion of the current changes in the multi-cloud security frameworks, focusing on the architectural foundations, threat patterns, governance processes, and new technologies that are defining the secure multi-cloud environments. The abstract expounds the rationale behind the need of multi-cloud security, constraints in the single-cloud security posture, and the need to have coherent but provider-understanding security models. In this paper, the researcher has synthesized academic literature, industry white papers, and standards that have been published before 2024 to arrive at major security trends, such as zero trust architecture and systems, cloud security posture management (CSPM), cloud workload protection systems (CWPP), identity-centric security, confidential computing, policy-as-code, and AI-assisted threat detection. A multi-layered approach has been suggested that incorporates the governance, identity, data, network, and application security among various CSPs with Interoperability and compliance. The discussion and results lead to a qualitative assessment of the efficiency of the proposed framework in comparison to the existing findings and a significant enhancement of the visibility, decrease of the risk, and consistency in the operations. The conclusion provides the future direction of research, such as autonomous security orchestration and cryptography resilience. The paper provides a systematic resource to researchers and practitioners developing secure, scalable and compliant multi-cloud environments
Ahmed Hassan· International Journal of Eme...· 0 citations
This study aims to conduct a comprehensive comparative evaluation of traditional three-tier and application-centric data center network architectures within an enterprise environment. The research adopts a descriptive qualitative approach using a comparative case study design combined with design evaluation techniques. Empirical data were collected from a real-world data center operating both architectures concurrently across multiple sites, supported by documentation analysis, operational monitoring, and direct observation. The analysis is structured around five key capability dimensions, namely scalability, security, reliability, operational simplicity and agility, as well as network visibility and virtualization awareness. The findings demonstrate that the application-centric architecture significantly outperforms the traditional model in scalability, security, operational efficiency, and visibility. It supports a higher number of endpoints and nodes with lower resource utilization, achieves reduced network latency, enables fine-grained security segmentation, and provides centralized policy-based management with integrated monitoring capabilities. Although the traditional architecture shows slightly higher aggregate availability, this is primarily influenced by operational maturity rather than architectural superiority. The results indicate that the application-centric approach offers a more adaptive, scalable, and secure solution for modern enterprise data center environments. This study contributes practical insights for network engineers and decision-makers by providing an evidence-based evaluation framework and highlighting key considerations for infrastructure transformation strategies.
A. Fadhilah, A. Ramadhan· Journal La Multiapp· 0 citations
Enterprise database systems are frequently targeted due to their reliance on perimeter-based, static access control models that lack continuous verification and privilege minimization. This study designed and empirically validated a three-layer Zero Trust architecture for Microsoft SQL Server that natively integrates instance-level authentication governance, enhanced Role-Based Access Control (RBAC) with Row-Level Security (RLS) and Just-in-Time (JIT) privilege elevation, and metadata-driven Attribute-Based Access Control (ABAC) through data classification — all without requiring external security middleware. Employing design science and applied experimental methodology, architecture was deployed in a live production environment comprising 589 databases and 132 identities over a 90-day post-implementation period. Chi-square tests of independence with Cramér's V effect size confirmed statistically significant reductions: login misuse declined by 82.1%, malicious authentication attempts by 66.7%, deployment errors by 59.8%, and reporting disruptions by 43.7%. Overprivileged accounts decreased by 84.2%. These results demonstrate that a coordinated, database native Zero Trust pipeline substantially reduces attack surfaces and insider risk in enterprise SQL Server environments. The proposed architecture aligns with globally recognized compliance frameworks, including ISO/IEC 27001 and GDPR, offering a replicable and regulatory-ready deployment model for enterprise environments across diverse jurisdictions.
Maynard Capil, D. Dasig· JPAIR Multidisciplinary Rese...· 0 citations
Results demonstrate that HPA effectively responds to workload increases by provisioning additional pods, maintaining system stability and throughput during high-demand periods, with CPU usage and RPS exhibiting predictable scaling behavior aligned with the 15-second Metrics Server scraping interval.
Shamsuddeen Rabiu, Sani Muhammad Tanko, Eli Adama Jiya· Journal of Basics and Applie...· 0 citations