The cloud security alliance csa is a leader in cloud security standard creation and implementation.
Public cloud security standards.
Cloud security standards and their support by prospective cloud service providers and within the enterprise is a critical area of focus for cloud service customers.
This set of standards is referred to as the cloud controls matrix ccm and consists of about 100 controls and.
It is intended to be used in conjunction with the information security objectives and controls found in iso iec 27002 2013 for creating a common set of security categories and controls for implementation by a public cloud computing service provider.
More specifically this document describes the threats technology risks and safeguards surrounding public cloud environments and their treatment.
The common characteristics most interpretations share are on demand scalability of highly available and reliable pooled computing resources secure access to metered services from nearly anywhere and displacement of data and services from inside to outside the organization.
Cloud computing can and does mean different things to different people.
Cloud security guidelines and recommendations described in open source literature such as nist or fedramp that address known or theorized cloud security concerns or considerations that have the potential to impact cloud data security.
This publication by the national institute of standards and technology provides an overview of the security and privacy challenges pertinent to public cloud computing and points out considerations organizations should take when outsourcing data applications and infrastructure to a public cloud environment.
Cloud security guidelines and recommendations found in public private sources such as.
Recent cloud security incidents reported in the press such as unsecured aws storage services or the deloitte email compromise would most likely have been avoided if the cloud consumers had used security tools such as correctly configured access control encryption of data at rest and multi factor authentication offered by the csps.
While aspects of these characteristics have been.
The csa has released a set of security standards specific to the cloud available for both cloud customers and service providers.
The landscape has matured with new cloud specific security standards like iso iec 27017 and iso iec 27018 for cloud computing security and privacy being adopted.
The largest and arguably most comprehensive player in cloud security standards is the csa or cloud security alliance.