Cloud Security
Cloud Security
Cloud computing means using computing resources over a network, usually the Internet, instead of owning and operating all the hardware and software locally.
Cloud resources can include:
Servers
Storage
Databases
Networking
Applications
Development platforms
Security services
NIST describes cloud computing as on-demand access to a shared pool of configurable resources that can be rapidly provided and released. Its three primary service models are SaaS, PaaS, and IaaS.
Plain Text
Your device
|
Internet
|
Cloud provider
|
Applications, servers, storage and databases
Common Cloud Characteristics
Cloud computing normally provides:
On-demand access: Resources can be created when needed.
Broad network access: Services are available over a network.
Resource pooling: Infrastructure serves multiple customers.
Rapid elasticity: Resources can scale up or down.
Measured service: Usage can be monitored and billed.
These are the five essential cloud characteristics identified by NIST.
SaaS: Software as a Service
With SaaS, the provider manages the application and the underlying infrastructure. You simply use the software, usually through a web browser or application.
Plain Text
You manage:
Your data, users and settings
Provider manages:
Application, servers, storage, networking and updates
Examples
Microsoft 365
Gmail
Salesforce
Zoom
Simple example
Using web-based email is SaaS. You do not install or maintain the email servers.
Memory tip: SaaS = use the software.
PaaS: Platform as a Service
With PaaS, the provider supplies a platform on which developers can build, test, deploy, and manage applications.
The developer focuses primarily on:
Application code
Application data
Configuration
The provider generally manages the operating system, runtime, servers, storage, and networking.
Plain Text
Developer → Writes application code
PaaS → Runs and hosts the application
Examples
Azure App Service
Google App Engine
AWS Elastic Beanstalk
Heroku
Memory tip: PaaS = build applications on a platform.
IaaS: Infrastructure as a Service
With IaaS, the provider supplies fundamental computing resources such as virtual machines, storage, and networking.
The customer usually manages:
Operating system
Applications
Data
Security configurations inside the virtual machine
The provider manages:
Physical servers
Data-center facilities
Physical storage
Underlying networking
Virtualization infrastructure
Examples
Azure Virtual Machines
Amazon EC2
Google Compute Engine
Plain Text
Cloud provider → Physical infrastructure
Customer → Virtual server, OS, applications and data
Memory tip: IaaS = rent IT infrastructure.
SaaS vs PaaS vs IaaS
Model What you receive Your main responsibility Simple exampleSaaS Finished application Users, settings and data Use web-based email
PaaS Application development platform Code and application data Build a web application
IaaS Virtual infrastructure OS, applications and data Create a virtual server
Responsibility comparison
Plain Text
More provider management
SaaS
↓
PaaS
↓
IaaS
More customer management
Different cloud service models require different forms of access management, and each model has a distinct security focus.
Cloud Deployment Models
Public cloud
Services run on a cloud provider's shared infrastructure.
Private cloud
Cloud infrastructure is dedicated to one organization.
Hybrid cloud
Combines private infrastructure with public cloud resources.
Community cloud
Infrastructure is shared by organizations with common requirements.
NIST identifies public, private, hybrid, and community clouds as the four cloud deployment models.
What Is Cloud Security?
Cloud security is the collection of technologies, policies, configurations, and practices used to protect cloud-based identities, applications, data, networks, and infrastructure.
Its main objectives are:
Confidentiality: Only authorized users can access information.
Integrity: Information is accurate and protected from unauthorized changes.
Availability: Systems and data remain accessible when needed.
Important Areas of Cloud Security
Identity and access management
Controls who can access cloud resources and what they can do.
Common protections include:
Multifactor authentication
Role-based access control
Least privilege
Strong authentication policies
Removal of unused accounts and permissions
Access control requirements differ across IaaS, PaaS, and SaaS because each service model exposes different components to the customer.
Data protection
Cloud data should be protected:
At rest: Stored in databases, drives, or backups
In transit: Moving across a network
In use: Being processed by an application
Common controls include encryption, backups, data classification, and data-loss prevention.
Network security
Cloud networks may be protected with:
Firewalls
Network security rules
Private network segments
VPNs
Web application firewalls
Intrusion detection and prevention
Configuration security
Misconfiguration is a major concern. Examples include:
Publicly exposed storage
Open administrative ports
Excessive permissions
Default passwords
Unrestricted firewall rules
Monitoring and incident response
Organizations should monitor:
Sign-in attempts
Administrative changes
Suspicious network traffic
File access
Security alerts
Logs help security teams investigate and respond to incidents.
Shared Responsibility Model
Cloud security is a shared responsibility between the provider and customer.
Plain Text
Cloud provider:
Security of the cloud
Customer:
Security of data, identities, access and configurations in the cloud
The exact division depends on the service model:
SaaS: The provider manages most of the technology, but the customer still manages users, access, settings, and data.
PaaS: The customer protects application code, application configurations, identities, and data.
IaaS: The customer has more responsibility, including the guest operating system, installed applications, accounts, and security configurations.
Quick Exam Summary
Plain Text
SaaS = Use software
PaaS = Develop applications
IaaS = Rent infrastructure
Cloud security protects cloud identities, data, applications, networks, and infrastructure through controls such as MFA, least privilege, encryption, firewalls, secure configuration, backups, monitoring, and incident response.
Subscribe to our newsletter
Sign up with your email address to receive news and updates.