Cloud Governance
What is Cloud Governance?
Policies, processes, and controls for managing cloud adoption, usage, security, and compliance across an organization's cloud environments.
Terms that appear alongside cloud governance
Each of these is named in at least one of the same controls as cloud governance. The number is how many controls name both.
- governance 29 shared controls
- cloud security 11 shared controls
- risk assessment 7 shared controls
- compliance 7 shared controls
- nist 7 shared controls
- shared responsibility model 6 shared controls
- policy 6 shared controls
- iso 27017 5 shared controls
Frameworks that govern cloud governance
What the standards actually require on cloud governance
Requirements naming cloud governance across 6 standards, quoted from the control text.
ISMAP Cloud Governance establishes the management framework for Cloud Service Providers operating under ISMAP. (1) Information Security Management System (ISMS): based on ISO/IEC 27001:2022 + JIS Q 27001 (Japanese Industrial Standard equivalent) + ISMS-AC Info...
ISMAP-CloudGovernance-ISMS-RiskAssessment-SharedResponsibility-Policy-RegulatoryCompliance-RolesResponsibilities · ISMAP Cloud Governance - ISMS per ISO 27001/JIS Q 27001 + Risk Assessment + Shared Responsibility Model + Cloud Security Policy + Regulatory Compliance + Roles and Responsibilities →Apply NIST SP 800-144 Guidelines on Security and Privacy in Public Cloud Computing published December 2011 + companion to NIST SP 800-145 + NIST SP 800-146 + FedRAMP + DoD Cloud Security Requirements Guide.
NISTSP144-1 · Cloud Governance, Risk Assessment, and Provider Trust Evaluation →Cloud risk assessment. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Cloud Governance.
NIST190-03 · Cloud risk assessment →RBI AA Framework imposes strict IT and data protection controls reflecting the elevated trust and sensitivity of consolidating financial information.
RBI-AA-IT-DataProtection-Transience-NoStorage-E2EE-DataLocalisation-IS-PolicyFramework · RBI AA IT + Data Protection - Data Transience + No Storage at AA + End-to-End Encryption + Data Localisation in India + Information Security Policy + RBI IT Framework for NBFC-AA →Apply NIST SP 800-146 Section 9.1 (Performance Considerations) + Section 9.2 (Reliability and Availability Considerations) + Section 9.3 (Service Level Recommendations) + interoperability and portability recommendations.
NISTSP146-7 · Service Level, Performance, Reliability, Interoperability, and Portability →Operate third-party risk management per OSFI B-13 Domain 4 + complementary OSFI Guideline B-10 Outsourcing of Business Activities and Functions.
OSFIB13-4 · Third-Party Risk Management and Cloud →Questions people ask about cloud governance
What is Cloud Governance?
Why is Cloud Governance important for compliance?
Which compliance frameworks address Cloud Governance?
Where can I learn more about Cloud Governance?
See how Cloud Governance applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.