Skip to content

Serverless Security

What is Serverless Security?

The security practices and considerations specific to serverless computing architectures (Functions as a Service). Serverless security focuses on function permissions, input validation, dependency management, and event injection prevention.

Cloud

Each of these is named in at least one of the same controls as serverless security. The number is how many controls name both.

What the standards actually require on serverless security

Requirements naming serverless security across 4 standards, quoted from the control text.

ISMAP (Japan)1 control

ISMAP Cloud Infrastructure controls cover the underlying compute + network + storage + management plane. (1) Virtual Network Segmentation: VPC Virtual Private Cloud isolation + subnets + security groups + NACLs + microsegmentation + service mesh (Istio + Linke...

ISMAP-CloudInfrastructure-NetworkSegmentation-Container-Serverless-WorkloadProtection-Hardening-ConfigManagement · ISMAP Cloud Infrastructure - VPC Network Segmentation + Container/Serverless Security + Cloud Workload Protection (CWPP) + Image/Template Hardening + CIS Benchmarks + Configuration Management + IaC

Container and serverless security. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Cloud Infrastructure Security.

NIST190-17 · Container and serverless security

Implement Acquisition Development Maintenance + Supplier Relationships + Vulnerability Management per MTCS SS 584. Acquisition Development and Maintenance (ISO 27001 Annex A.14) - secure coding standards (OWASP Top 10 + OWASP ASVS + CWE Top 25 + CERT Secure Co...

MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container · MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA

Apply Section 7.5 cloud workload protection covering CWPP (Cloud Workload Protection Platform - CrowdStrike Falcon + Trend Micro Deep Security + Wiz + Lacework + Orca Security + Aqua + Sysdig + Prisma Cloud) + image and template hardening (Packer + Hashicorp +...

NISTSP144-7 · Cloud Workload Protection, Containers, Serverless, and Configuration

Questions people ask about serverless security

What is Serverless Security?
The security practices and considerations specific to serverless computing architectures (Functions as a Service). Serverless security focuses on function permissions, input validation, dependency management, and event injection prevention.
Why is Serverless Security important for compliance?
Serverless Security is a key concept in Cloud. Understanding serverless security helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Serverless Security?
Serverless Security appears in the requirement text of ISMAP (Japan), NIST SP 800-190, MTCS (Singapore), NIST SP 800-144. Across these standards we have identified 4 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Serverless Security?
Explore our compliance framework pages to see how serverless security applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Serverless Security applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.