Cloud Security
Cloud security protects data, applications, and infrastructure running on cloud platforms. It covers shared responsibility models, identity and access controls, network segmentation, encryption, compliance, and the configuration hygiene needed when the provider manages the hardware but not the policy.
itCloud computing | OpenSkills.info
Intro
Cloud Security
Cloud security is the work of managing cybersecurity risk in cloud services. You protect data, identities, applications, and configurations while a cloud provider protects defined parts of the underlying service.
That division is the first mental model to learn. Moving a workload to the cloud transfers some operating duties. It does not transfer accountability for your data, users, business outcomes, or legal obligations.
Why cloud security is different
A traditional data center gives one organization direct control of most technology layers. A cloud service divides those layers between a provider and a customer. The exact boundary changes with each service.
With infrastructure as a service, you usually control more of the operating system, network configuration, applications, and data. With platform or software services, the provider operates more of the stack. You still control identities, access decisions, data, and many configuration choices.
This arrangement is called shared responsibility. It is a responsibility map, not a guarantee. You must inspect the documentation for each service and assign every required control to an owner.
Cloud environments also change quickly. Teams can create resources through consoles, application programming interfaces, and infrastructure as code. That speed helps delivery, but it can also spread an unsafe setting across many resources. Cloud security therefore depends on repeatable guardrails and continuous evidence, not a one-time review.
Start with the workload
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/144/final
Supports
- Governance, compliance, trust, architecture, identity, data protection, availability, and incident-response considerations
- Assessment of security and privacy before outsourcing data, applications, or infrastructure
- Protection of data, interfaces, credentials, logs, backups, and recovery capabilities
- https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20
Supports
- Cybersecurity risk management outcomes for organizations of any size or sector
- Govern, Identify, Protect, Detect, Respond, and Recover functions
- Use of profiles and tiers to understand, assess, prioritize, and communicate cybersecurity work
- https://csrc.nist.gov/pubs/sp/800/207/final
Supports
- No implicit trust based only on physical or network location or asset ownership
- Authentication and authorization before access to an enterprise resource
- Resource-focused protection for cloud-based assets and remote access
- https://www.cisa.gov/sites/default/files/2023-02/cloud_security_technical_reference_architecture_2.pdf
Supports
- Vendor-neutral guidance for secure cloud deployment and migration
- Shared services, secure development, zero trust, and cloud security posture management
- Continuous posture monitoring, logging, risk assessment, incident response, and data protection
- https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility
Supports
- Division of responsibilities across on-premises, IaaS, PaaS, and SaaS
- Customer responsibility for data, configurations, identities, users, and controlled cloud components
- Provider responsibility for physical infrastructure and service-dependent platform layers
- https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/shared-responsibility.html
Supports
- Provider security of cloud infrastructure and customer security in customer-selected services
- Customer operating-system, application, firewall, data, classification, and permission duties by service type
- Shared operation and verification of information-technology controls
- https://docs.cloud.google.com/architecture/framework/security/shared-responsibility-shared-fate
Supports
- Service-specific customer security tasks and control selection
- Customer responsibility for access policies and data across service models
- Secure foundations, blueprints, landing zones, and ongoing provider-customer cooperation
- https://cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4-1
Supports
- Cloud-specific security and privacy control framework
- Control mappings, assessment questions, implementation guidance, and continuous auditing metrics
- Shared security responsibility guidance for cloud providers and customers
