Public Cloud Security & Compliance
Major public cloud providers offer extensive security capabilities for protecting identities, applications, networks, workloads, and data. These capabilities can support highly secure environments, but cloud security is not automatic. Organizations remain responsible for selecting, configuring, monitoring, and operating cloud services according to their security, mission, contractual, and compliance requirements.
A&T Systems approaches cloud security as an integrated discipline encompassing identity, network security, data protection, vulnerability management, logging, monitoring, incident response, resilience, governance, and continuous improvement.
Understand Shared Responsibility
Cloud security operates under a shared-responsibility model. The cloud service provider is responsible for protecting the underlying cloud infrastructure, while customers retain security responsibilities associated with the services and configurations they use.
Customer responsibilities vary by service. Infrastructure services generally require customers to manage more operating-system, application, network, and configuration controls, while managed platform and software services shift additional infrastructure responsibilities to the cloud provider.
- Understand which controls are managed by the cloud provider
- Identify customer-controlled security responsibilities
- Document responsibilities assigned to managed-service and integration partners
- Verify responsibility boundaries for each cloud service being used
- Maintain governance over the complete customer control environment
Identity & Access Management
Identity is a foundational security control in cloud environments. Organizations should centrally manage authentication and authorization and apply least-privilege access according to job responsibilities and workload requirements.
Identity Controls
- Centralized identity integration
- Multi-factor authentication
- Role-based access control
- Least-privilege authorization
- Privileged-access management
- Workload and service identities
Access Governance
- Periodic access reviews
- Separation of duties
- Temporary and just-in-time access where appropriate
- Credential and key management
- Detection of excessive permissions
- Logging of privileged activity
Network Security
Cloud networking provides multiple layers of logical segmentation and traffic control. Security architecture should control inbound, outbound, east-west, administrative, and application traffic according to workload requirements.
- Virtual networks and private subnets
- Security groups and network-access controls
- Cloud-native firewall capabilities
- Web application firewall protection
- Distributed denial-of-service protection
- Private endpoints and service connectivity
- Encrypted VPN connections
- Dedicated private connectivity where required
- Network-flow logging and traffic monitoring
Data Protection & Encryption
Organizations should protect data according to its sensitivity, business value, contractual obligations, and applicable regulatory requirements.
Major cloud providers support encryption for data at rest and in transit, centralized key management, hardware security modules, secrets management, certificate management, and access-control mechanisms. Customers remain responsible for configuring these capabilities appropriately for their workloads.
- Encryption at rest
- Encryption in transit
- Centralized cryptographic-key management
- Hardware security modules where required
- Secrets and certificate management
- Data classification and discovery
- Data-loss-prevention controls where appropriate
- Backup and recovery protection
Security Logging & Monitoring
Cloud environments can provide detailed records of administrative activity, resource configuration, authentication events, network activity, application activity, and security findings.
Security-relevant logs should be centralized, protected from unauthorized modification, retained according to applicable requirements, and integrated with security-monitoring and incident-response processes.
- Administrative and API activity logging
- Authentication and identity-event monitoring
- Network-flow monitoring
- Configuration-change monitoring
- Security-event detection
- Centralized log collection and analysis
- Alerting and escalation
- Security information and event management integration
Threat Detection & Security Posture Management
Modern cloud platforms provide capabilities that can continuously evaluate security configurations, identify threats, discover exposed resources, assess vulnerabilities, and prioritize security findings.
For example, AWS provides services for threat detection, vulnerability management, sensitive-data discovery, configuration assessment, and centralized security-posture management. These services must still be configured and governed according to the customer’s requirements.
Preventive & Protective
- Security policies and guardrails
- Secure configuration standards
- Network-security controls
- Identity and authorization controls
- Encryption and data protection
- Workload protection
Detective & Responsive
- Threat detection
- Vulnerability assessment
- Security-posture management
- Sensitive-data discovery
- Incident investigation
- Automated and manual remediation
Configuration & Vulnerability Management
Cloud resources can be created and changed rapidly, making configuration and vulnerability management essential components of cloud security.
- Establish secure baseline configurations
- Continuously monitor configuration changes
- Identify publicly exposed or misconfigured resources
- Scan supported workloads and software for vulnerabilities
- Prioritize remediation according to risk
- Track exceptions and corrective actions
- Integrate findings with incident, change, and risk-management processes
Resilience, Backup & Recovery
Security also includes maintaining the availability and recoverability of systems and information. Cloud providers offer multiple availability zones, geographic regions, backup capabilities, replication, and disaster-recovery services, but customers remain responsible for designing and testing their required resilience strategy.
- Define availability objectives
- Establish Recovery Time Objectives (RTOs)
- Establish Recovery Point Objectives (RPOs)
- Implement protected backups
- Use redundancy and replication appropriately
- Test restoration and disaster-recovery procedures
Cloud Compliance & Assurance
Cloud providers participate in independent audits, assessments, certifications, and government authorization programs that can provide customers with assurance regarding portions of the provider’s control environment.
These provider certifications and reports do not automatically make a customer’s workload compliant. Customers must determine which cloud services are within the applicable assurance boundary and implement their own required controls under the shared-responsibility model.
Examples of Assurance Programs
- SOC 1, SOC 2, and SOC 3
- ISO/IEC 27001 and related ISO standards
- PCI DSS
- CSA STAR
- Independent security assessments
- Industry-specific assurance programs
Government Considerations
- FedRAMP-certified cloud service offerings
- DoD Cloud Computing SRG requirements
- NIST security controls and Risk Management Framework
- Applicable FIPS-validated cryptographic requirements
- Agency authorization requirements
- Export-control requirements where applicable
FedRAMP & Federal Workloads
Federal agencies should verify that the specific cloud service offering and individual services being considered meet the FedRAMP requirements applicable to the workload. FedRAMP certification provides standardized security-assessment information that agencies can use as part of their own risk and authorization processes.
Organizations should verify the current certification status and authorization boundary rather than assuming that every service offered by a cloud provider is automatically covered.
DoD Cloud Requirements
Department of Defense workloads may require cloud services authorized for the applicable DoD Cloud Computing Security Requirements Guide impact level, along with additional DFARS, cybersecurity, data-handling, and system-authorization requirements.
The appropriate cloud environment should be selected according to the classification, sensitivity, mission, and authorization requirements of the specific workload.
AWS GovCloud & Export-Controlled Workloads
AWS GovCloud (US) provides isolated U.S. regions designed to support eligible government and regulated workloads with additional requirements. AWS states that GovCloud can support customers subject to requirements such as ITAR when customers implement and maintain the controls required for their own compliance programs.
ITAR is a regulatory requirement rather than a cloud-provider certification. Organizations remain responsible for determining whether their information is export controlled and for implementing all applicable access, personnel, contractual, and data-handling requirements.
Healthcare & PCI Considerations
Organizations processing regulated healthcare or payment-card information should verify that the specific cloud services selected are eligible or in scope for the applicable program.
For example, AWS supports HIPAA-regulated workloads through eligible services and a Business Associate Addendum. AWS specifically notes that there is no general “HIPAA certification” for a cloud service provider. Similarly, PCI DSS responsibility remains shared between AWS and customers operating cardholder-data environments.
Verify the Service, Not Just the Provider
A cloud provider may support many compliance and assurance programs, but individual services, regions, configurations, and features may have different scope or eligibility.
Before deploying a regulated workload, organizations should verify:
- The cloud service offering being used
- The individual services within the applicable assurance boundary
- The regions in which those services are authorized or assessed
- The customer’s inherited and customer-operated controls
- Data-location and personnel-access requirements
- Required contractual agreements
- Agency or organizational authorization requirements
Security Requires Continuous Management
Cloud security is not a one-time implementation activity. Identities, resources, vulnerabilities, configurations, threats, services, and compliance requirements continually change.
Organizations should maintain an ongoing security-management program incorporating monitoring, vulnerability management, configuration management, incident response, access review, risk management, backup and recovery, compliance assessment, and continual improvement.
A&T’s Cloud Security Approach
A&T Systems integrates cybersecurity with cloud architecture, engineering, migration, service management, monitoring, governance, resilience, and managed operations.
Our approach is designed to help customers establish cloud environments with appropriate identity controls, network security, data protection, logging, vulnerability management, operational monitoring, resilience, compliance support, and continuous improvement based on customer and mission requirements.
For related information, see Implementing a Public Cloud Model, Protecting, Retaining & Returning Customer Data, and Cloud Computing & Datacenter Services.