Cloud Security
Cloud security protects data, applications, and infrastructure running on cloud platforms. It covers shared responsibility models, identity and access controls, network segmentation, encryption, compliance, and the configuration hygiene needed when the provider manages the hardware but not the policy.
itCloud computing | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic - Cloud Security
Cloud security is the work of managing cybersecurity risk in services somebody else runs. You look after the data, the identities, the applications, and the settings; the provider looks after the parts of the service it operates. That division has a name, shared responsibility, and the most useful thing to know about it is that the line moves depending on which service you bought.
Before the cloud, one organization held most of its technology in one building and could draw a fence around it. A cloud service takes those layers and splits them between two companies. With raw infrastructure you keep the operating system, the network configuration, and more. With a managed platform or a finished application, the provider runs more of the stack, and you are left with the identities, the data, and a surprising number of configuration switches. Nobody hands you the map. You read the service documentation and assign every control to an owner.
Three ideas carry most of the weight. The first is that identity is the control plane, the set of interfaces used to create and change resources: people and software act on the cloud through credentials and APIs, so a stolen key or session is not a foothold, it is the keys to the building. The second is that a private network address is routing information and not a statement of trust, and that encryption protects stored and moving data without settling who is allowed to ask for it back. The third is evidence: if you are not collecting logs of who did what, and keeping them somewhere the workload itself cannot reach, an incident becomes a guessing game.
Here is the part that catches people out. A clean posture dashboard, the tool that checks your configuration against a benchmark, is not the same as being secure. It cannot see the detection you never wrote or the containment step you never tested, and it will report a healthy score while all of that is missing. Posture is also not a finish line. Many hands change a cloud account every day, so the real question is whether you fix unsafe settings faster than you create them, and often the honest answer is no.
Where to go next. The intro is the real overview and defines each term once. The cheatsheet is a set of review prompts you can run against one workload. Field Notes carries the judgment the neutral explanations leave out, including why the workload's own permissions decide how bad an application bug gets. The Timeline shows how the practice arrived here, from the first control frameworks to the misconfiguration years. The HOWTO tab has the two incident procedures worth rehearsing before you need them: containing a leaked credential, and containing a compromised instance.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/144/final
Supports
- Governance, compliance, trust, architecture, identity, data protection, availability, and incident-response considerations
- Assessment of security and privacy before outsourcing data, applications, or infrastructure
- Protection of data, interfaces, credentials, logs, backups, and recovery capabilities
- Timeline; 2011 NIST public cloud security and privacy guidance milestone
- https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20
Supports
- Cybersecurity risk management outcomes for organizations of any size or sector
- Govern, Identify, Protect, Detect, Respond, and Recover functions
- Use of profiles and tiers to understand, assess, prioritize, and communicate cybersecurity work
- https://csrc.nist.gov/pubs/sp/800/207/final
Supports
- No implicit trust based only on physical or network location or asset ownership
- Authentication and authorization before access to an enterprise resource
- Resource-focused protection for cloud-based assets and remote access
- Timeline; 2020 Zero Trust Architecture definition milestone
- https://www.cisa.gov/sites/default/files/2023-02/cloud_security_technical_reference_architecture_2.pdf
Supports
- Vendor-neutral guidance for secure cloud deployment and migration
- Shared services, secure development, zero trust, and cloud security posture management
- Continuous posture monitoring, logging, risk assessment, incident response, and data protection
- Timeline; 2022 CISA Cloud Security Technical Reference Architecture milestone
- https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility
Supports
- Division of responsibilities across on-premises, IaaS, PaaS, and SaaS
- Customer responsibility for data, configurations, identities, users, and controlled cloud components
- Provider responsibility for physical infrastructure and service-dependent platform layers
- https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/shared-responsibility.html
Supports
- Provider security of cloud infrastructure and customer security in customer-selected services
- Customer operating-system, application, firewall, data, classification, and permission duties by service type
- Shared operation and verification of information-technology controls
- https://docs.cloud.google.com/architecture/framework/security/shared-responsibility-shared-fate
Supports
- Service-specific customer security tasks and control selection
- Customer responsibility for access policies and data across service models
- Secure foundations, blueprints, landing zones, and ongoing provider-customer cooperation
- https://cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4-1
Supports
- Cloud-specific security and privacy control framework
- Control mappings, assessment questions, implementation guidance, and continuous auditing metrics
- Shared security responsibility guidance for cloud providers and customers
- https://cloudsecurityalliance.org/about/history
Supports
- Timeline; 2009 CSA founding and first Security Guidance for Critical Areas of Focus in Cloud Computing
- Timeline; 2010 first release of the Cloud Controls Matrix
- Timeline; 2012 launch of the Security, Trust, Assurance and Risk (STAR) registry
- https://aws.amazon.com/about-aws/whats-new/2006/08/24/announcing-amazon-elastic-compute-cloud-amazon-ec2---beta
Supports
- Timeline; 2006 public beta of Amazon EC2 and the arrival of self-service infrastructure at scale
- https://aws.amazon.com/about-aws/whats-new/2013/11/13/announcing-aws-cloudtrail/
Supports
- Timeline; 2013 AWS CloudTrail announcement and account-level API activity recording
- https://ncp.nist.gov/checklist/revision/5615
Supports
- Timeline; 2016 first release (v1.0.0) of the CIS Amazon Web Services Foundations Benchmark configuration baseline
- https://dl.acm.org/doi/full/10.1145/3546068
Supports
- Timeline; 2019 disclosure of the Capital One breach via server-side request forgery to the instance metadata service
- Field Notes; an application request-forgery flaw becomes a data breach through a broadly permissioned workload role
- HOWTO; instance metadata credentials are reachable through server-side request forgery and open proxies
- https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service/
Supports
- Timeline; 2019 release of IMDSv2 with session-authenticated requests and a low response hop limit
- Field Notes; pre-2019 assumptions that stealing instance credentials required code execution on the host
- HOWTO; an instance's role credentials must be treated as compromised once the host is
- https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity
Supports
- Timeline; 2021 US Executive Order 14028 directing federal adoption of zero trust, multi-factor authentication, and secure cloud services
- https://docs.aws.amazon.com/guardduty/latest/ug/compromised-creds.html
Supports
- HOWTO; identifying the compromised IAM entity and API call, reviewing effective permissions, and confirming whether use was legitimate
- HOWTO; distinguishing long-term AKIA keys from short-term ASIA session credentials
- https://github.com/aws-samples/aws-customer-playbook-framework/blob/main/docs/Compromised_IAM_Credentials.md
Supports
- HOWTO; detection, analysis, containment, eradication, and recovery sequence for compromised AWS credentials
- HOWTO; deactivate rather than delete a key, rotate through a second key, revoke IAM role sessions, revoke IAM Identity Center sessions with an aws:TokenIssueTime deny
- HOWTO; enumerating attacker-created IAM users, roles, access keys, policy versions, SAML/OIDC providers, and resources across all regions
- HOWTO; CloudTrail search terms and API actions indicating persistence and log tampering
- https://docs.cloud.google.com/docs/security/compromised-credentials
Supports
- HOWTO; reissue by generating a new credential, pushing it to consumers, then revoking the old one
- HOWTO; deleting a service account key does not revoke already-issued short-lived tokens; disable or delete the service account and wait about 60 minutes
- HOWTO; reviewing Cloud Audit Logs and removing unexpected attacker-created resources
- https://learn.microsoft.com/en-us/security/operations/incident-response-playbook-compromised-malicious-app
Supports
- HOWTO; disabling a compromised service principal by setting accountEnabled to false
- HOWTO; recording keyIds then removing every added passwordCredential and keyCredential from the application and service principal
- HOWTO; auditing "Update Application - Certificates and secrets management", consent grants, added app roles, and redirect URIs for persistence
- https://www.microsoft.com/en-us/security/blog/2023/12/05/microsoft-incident-response-lessons-on-preventing-cloud-identity-compromise/
Supports
- Field Notes; post-authentication trust changes (new credentials on an app or service principal, new MFA method, new federation, new device registration) are the consistent early signal of account takeover
- Field Notes; workload identities receive higher privileges than needed and their malicious use is missed because detection focuses on user identities
- https://csrc.nist.gov/pubs/sp/800/61/r2/final
Supports
- HOWTO; the preparation, detection and analysis, containment and eradication, recovery, and post-incident lifecycle both procedures follow
- https://docs.aws.amazon.com/guardduty/latest/ug/compromised-ec2.html
Supports
- HOWTO; isolate a compromised instance with a dedicated isolation security group that removes 0.0.0.0/0 rules
- HOWTO; a security group change does not terminate existing tracked connections; block further traffic with network ACLs on known indicators
- HOWTO; terminate and replace the instance when unauthorized activity cannot be identified and stopped
- https://github.com/aws-samples/aws-customer-playbook-framework/blob/main/docs/EC2_Forensics.md
Supports
- HOWTO; capture memory before isolation or shutdown; acquire instance metadata; snapshot every attached volume and tag it
- HOWTO; set shutdown behavior to Stop, disable DeleteOnTermination, detach from Auto Scaling and load balancers, attach a block-all security group
- HOWTO; work only from read-only evidence copies, keep chain-of-custody notes, perform the investigation in the same region
- https://docs.cloud.google.com/kubernetes-engine/docs/how-to/security-mitigations
Supports
- HOWTO; snapshot the boot disk, isolate with restrictive firewall rules targeting the service account or network tags rather than shutting the instance down, remove the external IP, then delete the compromised node
- https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use_revoke-sessions.html
Supports
- HOWTO; the Revoke active sessions action attaches an inline AWSRevokeOlderSessions policy that denies calls with an earlier aws:TokenIssueTime
- https://learn.microsoft.com/en-us/azure/security/fundamentals/incident-response-overview
Supports
- HOWTO; Azure containment equivalents: create VM snapshots before remediation, modify NSG rules to isolate a VM while preserving investigation access, disable accounts and terminate sessions, revoke privileged assignments in PIM, block compromised accounts with Conditional Access
- HOWTO; align cloud incident response with the NIST SP 800-61 preparation, detection and analysis, containment and recovery, and post-incident phases
