8 results ·
● Live web index
O
orca.security
article
https://orca.security/resources/blog/cloud-security-architecture
Data security architecture requires encrypting data at rest and in transit and managing encryption keys so that a compromise of the cloud provider does not automatically compromise the data. AWS Key Management Service, Azure Key Vault, and Google Cloud KMS each support customer-managed encryption keys (CMEK), which ensure the cloud provider cannot decrypt customer data without explicit authorization. NIST SP 800-111 provides the standard for encryption of stored data; NIST SP 800-52 Rev 2 [...] ### Integrity
Integrity means that data and systems are not modified without authorization. In cloud architecture, this requires controls like object versioning on storage, immutable audit logs, code signing for container images, and infrastructure-as-code drift detection to catch unauthorized changes to deployed resources. [...] Cloud security architecture determines whether security controls form a coherent defense or function as isolated tools with no shared context. The architecture choices made at design time, around IAM scoping, encryption key management, network segmentation, and IaC security, determine how hard it is for an attacker to move laterally, escalate privileges, and reach sensitive data after initial access.
W
wiz.io
article
https://www.wiz.io/academy/cloud-security/cloud-security-architecture
## The principles behind cloud security architecture
Cloud security architecture is built on these four key principles:
Confidentiality
Integrity
Availability
Shared responsibility model
### Confidentiality
Sensitive data must remain accessible only to authorized users. In cloud environments, this requires encrypting data at rest and in transit, enforcing least privilege access policies, and implementing robust key management practices. [...] Cloud security architecture rests on four pillars: confidentiality (keeping data accessible only to authorized users), integrity (ensuring data isn't tampered with), availability (keeping resources accessible without interruption), and the shared responsibility model (splitting duties between provider and customer). [...] Cloud security architecture is a blueprint for controls that defines how identity, network boundaries, data protections, and monitoring fit together so teams can build and run cloud services with fewer surprises.
C
cloudaware.com
article
https://cloudaware.com/blog/cloud-security-architecture
Cloud security architecture is the blueprint for protecting identities, workloads, data, networks, and control planes across cloud environments. It encompasses policies, trust boundaries, telemetry, and enforcement paths that govern cloud computing security under the shared responsibility model.
Organizations use it to reduce risk, support digital transformation, and make zero trust practical as the threat landscape shifts from perimeter defense to users, assets, and resources. [...] The main cloud security architecture components and key elements in cloud security architecture are:
Identity and access management: Controls who gets access, how they authenticate, and what privileges they keep.
Network security: Segments traffic, reduces lateral movement, and protects cloud and hybrid connections.
Data encryption: Protects data at rest and in transit, with key management tied to risk.
Workload protection: Secures VMs, containers, serverless functions, and runtime behavior. [...] | SANS SEC549 | SEC549: Cloud Security Architecture focuses on designing secure, scalable cloud infrastructure through hands-on work in IAM, organization policy, network security, data security, and log aggregation. | Use it when the model is clear, but the implementation still feels fuzzy. |
D
darktrace.com
article
https://www.darktrace.com/cyber-ai-glossary/cloud-security-architecture
Creating a secure cloud architecture requires a comprehensive approach that combines proactive strategies, advanced technologies, and rigorous processes. By following established best practices, organizations can mitigate risks, enhance their security posture, and meet compliance requirements. Below are essential practices to implement when securing cloud environments.
#### 1. Implement robust access management
Principle: Control who can access cloud resources and how they use them. [...] Cloud security architecture is the framework of strategies, technologies, and practices designed to safeguard data, applications, and infrastructure in cloud environments. With the growing adoption of cloud computing, organizations must prioritize secure cloud computing architecture to protect sensitive assets. This involves integrating key elements like access management, network security, and multi-cloud security architecture to address diverse threats. A well-designed cloud security [...] cloud security architecture ensures robust defenses while enabling seamless cloud-native operations. By understanding the principles of securing cloud environments, businesses can create a resilient, scalable, and secure cloud architecture to support innovation and maintain trust.
S
salesforce.com
article
https://www.salesforce.com/eu/platform/cloud-data-security/what-is-cloud-secu…
A strong cloud computing security architecture consists of several components that work together to protect your assets. It must protect the confidentiality, integrity, and availability of the cloud – restricting access to authorised users, maintaining data accuracy, and ensuring it’s always available when you need it.
Here are some of the key components that make this happen: [...] When evaluating cloud security solutions, look for features that offer comprehensive protection, scalability, and ease of use. A strong cloud data security platform should include encryption, access controls, and continuous cloud security monitoring to safeguard data both at rest and in transit. [...] Think of cloud security architecture as the blueprint for protecting your cloud environment. This includes policies, procedures, and technologies designed to secure your data (whether it’s being stored or transmitted) and manage who can access what. In other words, it’s the foundation that supports comprehensive cloud security.
Salesforce mascot Astro standing on a tree log whilst presenting a slide.
F
fortinet.com
article
https://www.fortinet.com/resources/cyberglossary/cloud-security-architecture
Cloud security architecture is the strategic framework that defines how security controls, policies, and technologies protect cloud-based resources.
Unlike traditional security that focuses on network perimeters, cloud computing security architecture operates on the principle that security must be embedded throughout every layer of the cloud stack.
This approach differs from general cloud architecture because it prioritizes data protection and risk mitigation above all else. [...] Effective security architecture design starts with understanding business requirements, risk tolerance, and compliance obligations.
The design process must account for the dynamic nature of cloud environments where resources change frequently. [...] 13. Audit information and alerting: Customers should be able to identify security incidents and understand how they occurred. Services must provide audit information and security alerts when attacks are detected.
14. Secure use of service: Cloud providers should make it easy for customers to meet data protection responsibilities through secure-by-design and secure-by-default services, with guidance for meeting security responsibilities where needed.
S
sans.org
article
https://www.sans.org/cyber-security-courses/cloud-security-architecture
Responsible for ensuring that security requirements are adequately addressed in all aspects of enterprise architecture, including reference models, segment and solution architectures, and the resulting systems that protect and support organizational mission and business processes.
### Cloud Security Manager
Developing cloud security roadmaps, plans and procurement models to mature cloud security.
### Infrastructure Design (IFDN) [...] Section 5 teaches students how to enable SOC operations in the cloud, covering cloud data sources, log aggregation, and exporting to a central SIEM. Students design logging architectures that support threat detection, response, and recovery from cloud incidents.
#### Topics covered
#### Labs
## Things You Need To Know
### What Are The Laptop Requirements?
### Who Should Attend SEC549 Training?
### What Is The GIAC Cloud Security Architecture and Design (GCAD) Certification? [...] SEC549 prepares students to design secure, scalable cloud infrastructure. Through a representative case study, students threat model, analyze, and address real-world challenges in identity, access management, organization policy, network security, data security, and log aggregation. Across five days, students complete 15 hands-on labs, 25 security architecture reviews, and 10 CloudWars challenge rounds, giving them repeated practice applying centralized security controls to support fast, secure
C
cisa.gov
official
https://www.cisa.gov/sites/default/files/2023-02/cloud_security_technical_ref…
architecture would require. 5.1.1 CSPM provides agencies with access to and management of cloud resources, applications, and data. Agencies moving data and applications to the cloud offload physical access to these deployed resources and change how they manage governance and compliance requirements for their applications and data. As cloud deployments mature, they are becoming increasingly more complex, often involving multiple vendors and tools. In addition, recent cyber breaches have had [...] for cloud services. • Ensure applicable contracts appropriately require CSPs to comply with FedRAMP security authorization requirements. • Establish and implement an incident response and mitigation capability for security and privacy incidents for cloud services in accordance with DHS guidance. • Ensure that acquisition requirements address maintaining FedRAMP security authorization requirements and that relevant contract provisions related to contractor reviews and inspections are included [...] exist on-premises with the organization or off-premises with the cloud provider. 7 Cloud Security Technical Reference Architecture June 2022 Community: The cloud infrastructure is provisioned to a specific community of consumers that have shared concerns (e.g., mission, security requirements, policy, and compliance considerations). It may be owned, managed, and operated by one or more organizations, an authorized third party, or some combination of these entities. The infrastructure may exist