Serverless Security
What is Serverless Security?
The security practices and considerations specific to serverless computing architectures (Functions as a Service). Serverless security focuses on function permissions, input validation, dependency management, and event injection prevention.
Terms that appear alongside serverless security
Each of these is named in at least one of the same controls as serverless security. The number is how many controls name both.
- cloud infrastructure security 5 shared controls
- infrastructure security 5 shared controls
- container security 3 shared controls
- cloud workload protection 3 shared controls
- security posture 3 shared controls
- remediation 2 shared controls
- vulnerability 2 shared controls
- software bill of materials 2 shared controls
Frameworks that govern serverless security
What the standards actually require on serverless security
Requirements naming serverless security across 4 standards, quoted from the control text.
ISMAP Cloud Infrastructure controls cover the underlying compute + network + storage + management plane. (1) Virtual Network Segmentation: VPC Virtual Private Cloud isolation + subnets + security groups + NACLs + microsegmentation + service mesh (Istio + Linke...
ISMAP-CloudInfrastructure-NetworkSegmentation-Container-Serverless-WorkloadProtection-Hardening-ConfigManagement · ISMAP Cloud Infrastructure - VPC Network Segmentation + Container/Serverless Security + Cloud Workload Protection (CWPP) + Image/Template Hardening + CIS Benchmarks + Configuration Management + IaC →Container and serverless security. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Cloud Infrastructure Security.
NIST190-17 · Container and serverless security →Implement Acquisition Development Maintenance + Supplier Relationships + Vulnerability Management per MTCS SS 584. Acquisition Development and Maintenance (ISO 27001 Annex A.14) - secure coding standards (OWASP Top 10 + OWASP ASVS + CWE Top 25 + CERT Secure Co...
MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container · MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA →Apply Section 7.5 cloud workload protection covering CWPP (Cloud Workload Protection Platform - CrowdStrike Falcon + Trend Micro Deep Security + Wiz + Lacework + Orca Security + Aqua + Sysdig + Prisma Cloud) + image and template hardening (Packer + Hashicorp +...
NISTSP144-7 · Cloud Workload Protection, Containers, Serverless, and Configuration →Questions people ask about serverless security
What is Serverless Security?
Why is Serverless Security important for compliance?
Which compliance frameworks address Serverless Security?
Where can I learn more about Serverless Security?
See how Serverless Security applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.