Cloud security guidance
Pages
Page 13 of 29
The cloud security principles
The cloud security principles are designed to help you choose a cloud provider that meets your security needs. You will separately need to consider how you configure your cloud services securely.
These principles apply to both cloud platforms and to Software-as-a-Service.
For each of the principles, we describe:
- the security goals that a good cloud service should meet
- differentiators you should look out for that either give you more confidence in the cloud service, or make it easier for you to meet your own security responsibilities
- some suggestions for how the cloud provider could have met the goals
- any related considerations you will need to make when determining whether the service meets your needs
For each security principle listed below, you should analyse the cloud service and the company that runs it, to determine how effectively each of the goals laid out in that principle, is met. Different approaches will result in different risks for you to consider.
The service may meet a goal using one of the implementation approaches that we describe. However these are only suggestions - others that we haven’t mentioned may be just as effective.
You should also consider what evidence has been provided to give you enough confidence in the statements being made by the cloud provider. We have suggested some ways of finding how a cloud provider meets the goals of these principles, and how they might have evidenced them on the choosing a cloud provider page.
Some cloud services have written a response to the cloud security principles so that you can see how they believe meet the goals in one place.
The principles
-
Principle 1: Data in transit protection
your data should be adequately protected against tampering and eavesdropping as it transits networks inside and external to the cloud. This should be achieved using a combination of encryption, service authentication and network-level protections.
Read Principle 1: Data in transit protection
-
Principle 2: Asset protection and resilience
your data, and the assets storing or processing it, should be protected against physical tampering, loss, damage or seizure. Protections should include cover for the legislation that your data is subject to, as well as mitigations such as encryption, data centre security, secure erasure and service resilience.
Read Principle 2: Asset protection and resilience
-
Principle 3: Separation between customers
a malicious or compromised customer of the service should not be able to access or affect the service or data of another. It will need to implement effective security boundaries in the way it runs code, stores data, and manages the network.
Read Principle 3: Separation between customers
-
Principle 4: Governance framework
the service provider should have a security governance framework which co-ordinates and directs its management of the service and information within it. This will give you confidence that other controls will continue to be effective through the lifetime of the service.
Read Principle 4: Governance framework
-
Principle 5: Operational security
the service needs to be operated and managed securely in order to impede, detect or prevent attacks. It will achieve this through a combination of effective vulnerability management, protective monitoring, configuration & change management, and incident management.
Read Principle 5: Operational security
-
Principle 6: Personnel security
where service provider personnel have access to your data and systems, you need a high degree of confidence in their trustworthiness and the technical measures in place that audit and constrain the actions of those personnel.
Read Principle 6: Personnel security
-
Principle 7: Secure development
cloud services should be designed, developed and deployed in a way that minimises and mitigates threats to their security. This will include a robust software development lifecycle that uses an automated and audited integration and deployment pipeline.
Read Principle 7: Secure development
-
Principle 8: Supply chain security
the service provider should ensure that its supply chain meets the same security standards that the organisation sets for itself. This includes where a third party has access to customer data or the service, and where the provider has dependencies on a third party such as when procuring hardware and software.
Read Principle 8: Supply chain security
-
Principle 9. Secure user management
your provider should make the tools available for you to securely manage your use of their service, preventing unauthorised access and alteration of your resources, applications and data. This will usually include an access model that allows you to implement role-based access controls across the service and the data held in it.
Read Principle 9: Secure user management
-
Principle 10: Identity and authentication
all access to service interfaces should be constrained to a securely authenticated and authorised identity, which may belong to either a human user or a machine.
Read Principle 10: Identity and authentication
-
Principle 11: External interface protection
all external or less-trusted interfaces of the service should be identified and defended appropriately. This includes external APIs, web consoles and command line interfaces.
Read Principle 11: External interface protection
-
Principle 12: Secure service administration
the design, implementation, and management of the cloud service provider’s administration systems should follow enterprise good practice, recognising their high value to attackers.
Read Principle 12: Secure service administration
-
Principle 13: Audit information and alerting for customers
you should be able to identify security incidents and should have the information necessary to find out how and when they occurred. The service will need to provide you with audit information, and issue security alerts when attempted attacks are detected.
Read Principle 13: Audit information and alerting for customers
-
Principle 14: Secure use of the service
your cloud provider should make it easy for you to meet your data protection responsibilities. Services should be secure by design and by default. Wherever this is not the case, the provider should help you meet your security responsibilities.
Read Principle 14: Secure use of the service