Cloud security guidance
Pages
Page 9 of 29
Using cloud services securely
Whenever you use a cloud service, you will always have some responsibility to configure and use that cloud in a way that meets your security needs. The amount of responsibility will vary depending on where your choice of service fits in the cloud security shared responsibility model, and how secure your cloud service is by design and by default. This guidance will help you meet that responsibility.
You will separately need to consider whether the cloud service itself meets your security needs, which we discuss in our guidance that explains how to choose a cloud provider.
Using Software as a Service well
Cloud applications (commonly known as Software as a Service or SaaS) are normally user-facing. Your configuration will need to be secure-enough while also considering how usability is impacted by that configuration. Getting this balance right will keep your users happy and safe, and reduce the spread of shadow IT in your organisation.
We describe the most important things that you will need to do to most of these services in our using Software as a Service securely guidance.
SaaS applications are available for many different purposes, so you may also need to apply extra configuration that is important for that type of application. Examples include configuring lobby features in video conferencing services or anti-spoofing measures on email services. We recommend referring to your vendor’s security good-practice guide to identify such features.
Using cloud platforms well
Cloud platforms are those that you build or host your own applications or services on. They will include services described as Infrastructure as a Service (IaaS) and Platform as a Service (PaaS). Your configuration should make it as easy as possible for developers and IT teams to use the components of the cloud that they need, deployed in a way that allows them to inherit good security settings. 'Guardrails' or security policies can also ensure that they are following good security practice.
We describe the most important things that you will need to do in our guidance on how to configure and operate your cloud platform securely.
You should get such security policies and initial configurations in place before you start building anything on the cloud platform. Note that security policies:
- can be disruptive when applied to existing workloads
- may not always be retroactively applied to existing workloads and data
The security features (including those that make securing your deployment easier) will vary depending on which cloud platform you are using. We recommend considering the availability of such features when choosing a cloud platform.
Architecting services in the cloud
Organisations building on a well-configured cloud platform will still need to architect their services with security in mind. We suggest referring to our cyber security design principles and our secure development and deployment guidance, as the same considerations will need to be made wherever that service is hosted.
The way you implement mitigations and security boundaries in the cloud may differ from your traditional approach. This is sometimes because cloud services implement security features in different ways, but also could be because there are opportunities that come from moving to cloud-native features that implement zero trust or because of optimising for cost-saving. We highlight some of these differences in security architecture anti-pattern 4: building an ‘on-prem’ solution in the cloud.
Cloud services usually include native security components that give you monitoring, insight and control of the cloud itself, and the services that you build on top of it. We recommend that your design makes use of these built-in services to allow you to gain the most advantages of a good cloud service.
Organisations should consider using good-practice architectures designed for the specific cloud being used. These are sometimes called templates, blueprints or landing zones. They can give you confidence that services are being used in a consistent way and connect into centralised functions run by your organisation such as identity and logging.
Platform guidance
Recommended configurations, component choices and architectures will vary depending on which cloud platform you are using. We’ve included guidance from the more common platforms below.
A cloud that meets the goals of cloud security principle 14.2: help customers meet their security responsibilities will highlight recommended security features and architectures and publish good-practice documentation and blueprints. These are often called “well-architected frameworks”