Cloud security guidance
Pages
Page 2 of 29
Introduction to cloud security
Outlining the NCSC's approach to cloud security.
There is some ambiguous terminology concerning cloud technology, so it’s worth taking a moment to define a few common terms. When we talk about ‘the cloud’, ‘cloud services’ or ‘cloud computing’ we mean:
‘An on-demand, massively scalable service, hosted on shared infrastructure, accessible via the internet. Typical services provide data storage, data processing, and pre-built functionality, such as logging.’
This follows the NIST definition of cloud computing in identifying common traits of cloud services.
Cloud services can be split into two main categories:
- pre-built cloud services, that solve a business problem; these are usually called Software-as-a-Service or SaaS
- cloud platforms which provide components used to build a service to solve a business problem; services that fall under this banner include Platform-as-a-Service (PaaS), Infrastructure-as-a-Service (IaaS) and serverless components
The section Understanding cloud services covers the various types of Cloud in more detail, along with information on their deployment, security and management models.
Security in the cloud
The scale of a public cloud service can bring many security advantages, as well as the numerous functional ones. However, the shared nature of most cloud services can make it difficult to get a clear picture of the risks you would be taking when adopting a service.
This guidance will help you:
- evaluate the security of public cloud services
- determine how suitable they are for your intended use
To do this, you must first develop an understanding of the separation measures which a service provides. You will also need a clear picture of the balance of responsibility (between you and the provider) for the secure operation of the service.
If you’re going to build services using a cloud platform, you’ll need to have a good idea of how cryptography is usually handled in this setting. Our guide to cryptography in the cloud covers all the terminology and techniques involved.
Most concepts apply equally well to hybrid cloud, multi-cloud and some larger private cloud deployments. The section on service deployment models covers some of the extra considerations for these less common cloud deployment types.
Our guides on using cloud services securely include some actions that you will need to take to harden cloud platforms prior to building on them, and to secure Software as a Service (SaaS) applications.
Working towards your cloud security
Cyber security works best when it’s considered from the start of a project. Attempting to add security as a last minute bolt-on can have unpredictable (and expensive) results.
The advice in this guidance will produce the best results when integrated fully into a suitable development processes. Our suggested approach involves the following four steps. Working through these in order, will help you to identify cloud services which are suitably secure for your intended use.
- 1
Know your business requirements
You should start by understanding your intended use of the cloud service, and the data that you’ll be storing and processing in it. We recommend referring to the NCSC’s risk management guidance when identifying and managing cyber security risk.
- 2
Choose a cloud provider that meets your needs
Our guide to choosing a cloud provider describes how to choose a suitable one using either:
If you are putting out a commercial tender for cloud services, we recommend that you require bids to include a response to the NCSC’s cloud security principles.
'Value for money' will always be a factor when choosing a service. Some cloud services have differently priced licences that come with different security features (such as single sign-on or mandated multi-factor authentication). You should make sure that you are quoted for the licence which includes the services that will meet your security needs.
- 3
Use the cloud service securely
Once you have picked a cloud provider, you should understand your security responsibilities when using the service, or platform. All cloud services will need you to apply some sort of configuration to secure it in line with your needs; it is unusual for a cloud service to be fully ‘secure by default’. We outline the most important actions you should take in our using cloud services securely guidance.
Designing your service architecture after choosing the cloud provider will allow you to make best use of the native security technologies built into the service.
Many public cloud services publish security good practice guides, sample architectures, and configuration baselines to get you started.
- 4
Continue to monitor and manage the risks
Once in use, periodically review whether the service - and the way that you are using it - still meets your business and security needs, which you should also review from time to time.