Statement of Work
Cloud Security Architecture
Prepared by Starks Enterprise — starksenterprise.com · Irving "Gene" Starks Jr. · [email protected] · (980) 355-9706
Purpose & Overview
Starks Enterprise will design and harden Client's cloud security architecture — landing zones, identity, network segmentation, and guardrails — so that security is enforced by design rather than bolted on after deployment.
Scope of Work
Current-state architecture review across cloud accounts, subscriptions, and projects
Landing-zone design: account structure, org policies, and baseline guardrails
Identity-centric controls: federation, least-privilege roles, and privileged-access design
Network segmentation, egress control, and private-connectivity patterns
Encryption, key management, and secrets-management architecture
Detection and logging baseline (cloud-native SIEM ingestion, alert priorities)
Infrastructure-as-code guardrails and policy-as-code implementation samples
Roadmap with prioritized remediation and reference architectures
Deliverables
Current-state security architecture assessment
Target-state reference architecture with diagrams
Landing-zone and guardrail configuration guidance (IaC samples)
Prioritized remediation roadmap with effort estimates
Timeline
| Phase | Activities | Duration |
|---|---|---|
| Phase 1 | Discovery & current-state assessment | 2 weeks |
| Phase 2 | Architecture design & guardrail definition | 2-3 weeks |
| Phase 3 | Roadmap, handover & knowledge transfer | 1 week |
Pricing & Payment Terms
| Item | Timing | Fee |
|---|---|---|
| Architecture assessment & design (one-time) | Due at kickoff (50%) / handover (50%) | $18,000 - $40,000 |
| Implementation support (per sprint) | As consumed | $8,000 - $15,000/sprint |
| Architecture review retainer (monthly) | Monthly, in advance | $2,500 - $5,000/mo |
Invoices are due net 15. Retainer hours expire at the end of each month.
Client Responsibilities & Assumptions
Client will provide read access to cloud environments and existing architecture documentation.
Client will identify compliance obligations and data-classification requirements up front.
Client engineering staff will participate in design workshops.
Out of Scope
Hands-on implementation of all remediations (available as implementation sprints)
Managed detection and response operations
On-premises / data-center network redesign
Acceptance Criteria
Reference architecture delivered and reviewed with Client engineering
Guardrail IaC samples validated in a Client sandbox environment
Roadmap accepted with owner and timeline assignments
Term & Termination
This SOW is effective upon signature by both parties and remains in effect through delivery and acceptance of all deliverables, or until terminated by either party with 30 days' written notice. Fees for work performed and expenses incurred prior to termination are non-refundable. This SOW is governed by, and incorporated into, the Master Services Agreement between Starks Enterprise and Client.