Recent cloud security incidents reported in the press such as unsecured aws storage services or the deloitte email compromise would most likely have been avoided if the cloud consumers had used security tools such as correctly configured access control encryption of data at rest and multi factor authentication offered by the csps.
Public cloud security standards.
Cloud security guidelines and recommendations described in open source literature such as nist or fedramp that address known or theorized cloud security concerns or considerations that have the potential to impact cloud data security.
While aspects of these characteristics have been.
Cloud security guidelines and recommendations found in public private sources such as.
Cloud security standards and their support by prospective cloud service providers and within the enterprise is a critical area of focus for cloud service customers.
The csa has released a set of security standards specific to the cloud available for both cloud customers and service providers.
With corporate members including amazon web services.
The cloud security alliance csa is a leader in cloud security standard creation and implementation.
It is intended to be used in conjunction with the information security objectives and controls found in iso iec 27002 2013 for creating a common set of security categories and controls for implementation by a public cloud computing service provider.
The landscape has matured with new cloud specific security standards like iso iec 27017 and iso iec 27018 for cloud computing security and privacy being adopted.
Cloud computing can and does mean different things to different people.
In this instance the public cloud service provider acts as the pii processor or the privacy.
This publication by the national institute of standards and technology provides an overview of the security and privacy challenges pertinent to public cloud computing and points out considerations organizations should take when outsourcing data applications and infrastructure to a public cloud environment.
The primary purpose of this report is to provide an overview of public cloud computing and the security and privacy considerations involved.
More specifically this document describes the threats technology risks and safeguards surrounding public cloud environments and their treatment.