Skip to content

Cloud Security

What is Cloud Security?

The set of policies, controls, procedures, and technologies that protect cloud-based systems, data, and infrastructure. Governed by the shared responsibility model between cloud provider and customer.

Cloud

Each of these is named in at least one of the same controls as cloud security. The number is how many controls name both.

What the standards actually require on cloud security

Requirements naming cloud security across 6 standards, quoted from the control text.

ISMAP (Japan)5 controls

ISMAP Cloud Governance establishes the management framework for Cloud Service Providers operating under ISMAP. (1) Information Security Management System (ISMS): based on ISO/IEC 27001:2022 + JIS Q 27001 (Japanese Industrial Standard equivalent) + ISMS-AC Info...

ISMAP-CloudGovernance-ISMS-RiskAssessment-SharedResponsibility-Policy-RegulatoryCompliance-RolesResponsibilities · ISMAP Cloud Governance - ISMS per ISO 27001/JIS Q 27001 + Risk Assessment + Shared Responsibility Model + Cloud Security Policy + Regulatory Compliance + Roles and Responsibilities

HKMA C-RAF 2024-2025 pipeline + emerging risks + sectoral cybersecurity evolution. KEY 2024-2025 INITIATIVES: (1) AI + MACHINE LEARNING + GENERATIVE AI CYBER GOVERNANCE - AIs deploying AI/ML for fraud detection + AML + customer service + lending + risk managem...

HKMA-CRAF-2024-2025-AI-Quantum-Cloud-Ransomware-DORA · HKMA C-RAF 2024-2025 Pipeline - AI, Quantum-Resistant Cryptography, Cloud Security, Ransomware, EU DORA Coordination
NIST SP 800-1903 controls

Cloud security policy and strategy. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Cloud Governance.

NIST190-02 · Cloud security policy and strategy

Per CSAP: security controls including admin + physical + technical + data classification + encryption + access control + monitoring.

KRCSAP-2 · Cloud Security Controls
BSIMM1 control

Software Environment. Cloud security controls are implemented so cloud-hosted applications inherit a secure configuration baseline.

SE1.3 · Implement cloud security controls

GC cloud security controls and assessment. CCCS cloud security assessment programme. Approved cloud service providers for GC data. Protected B cloud requirements.

CA-ITSG33-SC-03 · Cloud Security

Questions people ask about cloud security

What is Cloud Security?
The set of policies, controls, procedures, and technologies that protect cloud-based systems, data, and infrastructure. Governed by the shared responsibility model between cloud provider and customer.
Why is Cloud Security important for compliance?
Cloud Security is a key concept in Cloud. Understanding cloud security helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Cloud Security?
Cloud Security appears in the requirement text of ISMAP (Japan), HKMA Cyber Resilience Assessment Framework (C-RAF), NIST SP 800-190, South Korea Cloud Security Assurance Program (CSAP), BSIMM. Across these standards we have identified 16 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Cloud Security?
Explore our compliance framework pages to see how cloud security applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Cloud Security applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.