Skip to content
Menu
Cloud Gal 42
  • Home
Cloud Gal 42

QuickGuide: Cloud Security Recommendations

February 5, 2021May 13, 2021 by admin

Know the infrastructure security of your provider or platform:

  • In the shared security model, the provider (or whoever maintains the private cloud platform) has the burden of ensuring the underlying physical, abstraction, and orchestration layers of the cloud are secure.
  • Review compliance certifications and attestations.
  • Check industry-standard and industry-specific compliance certifications and attestations on a regular basis for having the assurance that your provider is following cloud infrastructure best-practices and regulations.

Network

  • Prefer SDN when available.
  • Use SDN capabilities for multiple virtual networks and multiple cloud accounts/segments to increase network isolation.
  • Separate accounts and virtual networks dramatically limit blast radius compared to traditional data centers.
  • Implement default deny with cloud firewalls.
  • Apply cloud firewalls on a per-workload basis as opposed to a per-network basis.
  • Always restrict traffic between workloads in the same virtual subnet using a cloud firewall (security group) policy whenever possible.
  • Minimize dependency on virtual appliances that restrict elasticity or cause performance bottlenecks.

Compute/workload

  • Leverage immutable workloads whenever possible.
  • Disable remote access.
  • Integrate security testing into image creation.
  • Alarm with file integrity monitoring.
  • Patch by updating images, not patching running instances.
  • Choose security agents that are cloud-aware and minimize performance impact, if needed.
  • Maintain security controls for long-running workloads, but use tools that are cloud aware.
  • Store logs external to workloads.
  • Understand and comply with cloud provider limitations on vulnerability assessments and penetration testing.

Related

1 thought on “QuickGuide: Cloud Security Recommendations”

  1. Pingback: Cloud Security – Cloud Gal 42

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Role of AI/ML in Cybersecurity
  • QuickGuide: Security on OCI
  • The Cloud Management Plane
  • Secure Installation and Configuration of Virtualized Cloud Datacenters
  • Cloud Datacenter: Hardware-specific Security Configuration Requirements

Recent Comments

  • Rafael on Installing Debian on OCI
  • Jorge on Installing Debian on OCI
  • admin on Installing Debian on OCI
  • Andreas on Installing Debian on OCI
  • admin on Installing Debian on OCI

Archives

  • December 2022
  • February 2022
  • September 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • February 2021
  • January 2021
  • November 2020
  • October 2020

Categories

  • aws
  • bcdr
  • cloud
  • cloudsecurity
  • compliance
  • informationsecurity
  • oracle
  • pci
  • QuickGuide
  • security
©2025 Cloud Gal 42 | Powered by WordPress and Superb Themes!