openskills.info
Open Course

Cloud Security

Cloud security protects data, applications, and infrastructure running on cloud platforms. It covers shared responsibility models, identity and access controls, network segmentation, encryption, compliance, and the configuration hygiene needed when the provider manages the hardware but not the policy.

itCloud computing

Don't Panic - Cloud Security

Cloud security is the work of managing cybersecurity risk in services somebody else runs. You look after the data, the identities, the applications, and the settings; the provider looks after the parts of the service it operates. That division has a name, shared responsibility, and the most useful thing to know about it is that the line moves depending on which service you bought.

Before the cloud, one organization held most of its technology in one building and could draw a fence around it. A cloud service takes those layers and splits them between two companies. With raw infrastructure you keep the operating system, the network configuration, and more. With a managed platform or a finished application, the provider runs more of the stack, and you are left with the identities, the data, and a surprising number of configuration switches. Nobody hands you the map. You read the service documentation and assign every control to an owner.

Three ideas carry most of the weight. The first is that identity is the control plane, the set of interfaces used to create and change resources: people and software act on the cloud through credentials and APIs, so a stolen key or session is not a foothold, it is the keys to the building. The second is that a private network address is routing information and not a statement of trust, and that encryption protects stored and moving data without settling who is allowed to ask for it back. The third is evidence: if you are not collecting logs of who did what, and keeping them somewhere the workload itself cannot reach, an incident becomes a guessing game.

Here is the part that catches people out. A clean posture dashboard, the tool that checks your configuration against a benchmark, is not the same as being secure. It cannot see the detection you never wrote or the containment step you never tested, and it will report a healthy score while all of that is missing. Posture is also not a finish line. Many hands change a cloud account every day, so the real question is whether you fix unsafe settings faster than you create them, and often the honest answer is no.

Where to go next. The intro is the real overview and defines each term once. The cheatsheet is a set of review prompts you can run against one workload. Field Notes carries the judgment the neutral explanations leave out, including why the workload's own permissions decide how bad an application bug gets. The Timeline shows how the practice arrived here, from the first control frameworks to the misconfiguration years. The HOWTO tab has the two incident procedures worth rehearsing before you need them: containing a leaked credential, and containing a compromised instance.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources