Skip to main content
Guidance

Cloud security guidance

How to choose, configure and use cloud services securely.

Page 13 of 29

The cloud security principles

Summary and context for the 14 Cloud Security Principles, including their goals and technical implementation.

The cloud security principles are designed to help you choose a cloud provider that meets your security needs. You will separately need to consider how you configure your cloud services securely.

These principles apply to both cloud platforms and to Software-as-a-Service.

For each of the principles, we describe:

  • the security goals that a good cloud service should meet
  • differentiators you should look out for that either give you more confidence in the cloud service, or make it easier for you to meet your own security responsibilities
  • some suggestions for how the cloud provider could have met the goals
  • any related considerations you will need to make when determining whether the service meets your needs

For each security principle listed below, you should analyse the cloud service and the company that runs it, to determine how effectively each of the goals laid out in that principle, is met. Different approaches will result in different risks for you to consider.

The service may meet a goal using one of the implementation approaches that we describe. However these are only suggestions - others that we haven’t mentioned may be just as effective.

You should also consider what evidence has been provided to give you enough confidence in the statements being made by the cloud provider. We have suggested some ways of finding how a cloud provider meets the goals of these principles, and how they might have evidenced them on the choosing a cloud provider page.

Some cloud services have written a response to the cloud security principles so that you can see how they believe meet the goals in one place.



Reviewed

Version

2.1