Skip to main content
Information Security for Workload Factory

Learn about information security for NetApp Workload Factory

Contributors netapp-rlithman

Information security is a core part of NetApp Workload Factory design and operation. Information Security, Cloud Platform, and Storage teams can use these details to evaluate and onboard Workload Factory in a way that supports enterprise security requirements.

What Workload Factory is

Workload Factory is a SaaS life-cycle management platform designed to help you optimize and manage workloads (for example, storage, VMware migrations, EDA projects, and database environments) using Amazon FSx for NetApp ONTAP. Your workloads run in AWS.

Workload Factory uses AWS APIs for all FSx for ONTAP operations that are natively available through AWS, and ONTAP REST APIs for Workload Factory operations that are supported by the platform but not natively available through AWS APIs.

Core security principles used in this guide

Confidentiality

Protect data from unauthorized access through identity controls, least privilege, encryption, and network boundaries.

Integrity

Protect systems and configurations from unauthorized or unintended change using permission scoping, change control, and auditability.

Availability

Ensure authorized users can access the service and workloads through resilient AWS designs and operational monitoring.

Types of information covered in this guide

The following sections provide information to help you evaluate and onboard Workload Factory in a way that supports enterprise security requirements.

  1. Security model and responsibilities

  2. Architecture and connectivity

  3. Identity, credentials, and least privilege

  4. Data governance, privacy, and lifecycle

  5. Observability and monitoring

  6. AI controls and VPC components

Get started quickly

  • Start with view, planning, and analysis (read-only) permissions and expand only as required.

  • Use AWS CloudTrail to validate sts:AssumeRole activity for the integration role.

  • Decide upfront whether you need ONTAP-native operations that require deploying a Lambda link or NetApp Console agent.

  • Decide upfront whether generative AI is permitted and whether residency constraints require single-region inference profiles.