8 results ·
● Live web index
A
alibabacloud.com
article
https://www.alibabacloud.com/help/en/well-architected/latest/safety-design-pr…
Document Center
All Products
Document Center
Well-Architected Framework
Learn
Security
Security design principles
Document Center
# Well-Architected Framework:Security design principles
Last Updated:May 27, 2026
Security design for cloud workloads rests on four core principles: minimization, audit and traceability, data protection, and compliance. Together they form a layered defense that limits exposure, enables incident response, and satisfies regulatory requirements. [...] ## Principle of data security and protection
Goal: Protect data throughout its lifecycle—at rest, in transit, and in shared flows—by classifying it, controlling access, encrypting it, and auditing how it moves.
Under the shared responsibility model, data security is divided between you as the tenant and the cloud platform. When designing a data protection system, apply these principles: [...] Principle of data sharing: Identify all data sharing methods and paths, and establish protective measures for each. These methods can include online data access and sharing through APIs or software development kits (SDKs), and offline data sharing.
Principle of data compliance: Prioritize data compliance. Identify the technical and administrative controls required to meet compliance requirements, and incorporate them into your organization's data security system planning.
S
sentinelone.com
article
https://www.sentinelone.com/cybersecurity-101/cloud-security/cloud-security-p…
## Cloud Security Principles FAQs
Cloud security principles are guidelines that help keep data and services safe in the cloud. They cover how to protect access, ensure data privacy, and maintain service availability. You can think of them as guardrails: controlling who can see or change your resources, encrypting data in transit and at rest, and setting up backups. These principles help you stay organized and reduce the chance of breaches. [...] The next cloud security principle to follow is protecting data at rest. It is essential to guarantee that the data is not accessible to unauthorized persons with access to the infrastructure. Whatever the storage medium, user data must be protected. If the right safeguards aren’t implemented, accidental disclosure or data loss could be dangerous.
### #3 Asset Protection and Service Resilience [...] The first one in the list of cloud security principles is protecting data in transit. The networks that transfer user data must have strong anti-eavesdropping and anti-tampering safeguards. Organizations can accomplish this with the use of network protection and encryption. It enables them to stop the attacker’s access to data and data reading.
### #2 Protect Data at Rest.
R
radware.com
article
https://www.radware.com/cyberpedia/cloud-security/cloud-security-principles-s…
Security by design:Cloud architecture design should implement security controls that are not vulnerable to security misconfigurations. For example, if a cloud storage container holds sensitive data, external access should be locked, and there should be no way for an administrator to open access to the public Internet. [...] Among the key capabilities of cloud data security systems are central management of data encryption, governance, and permissions for sensitive data, as well as data loss prevention (DLP) to detect anomalous activity that could result in loss or exfiltration of sensitive data.
### Cloud Backup [...] Cloud data security software implements access controls and security policies for cloud-based storage services across multiple cloud providers. It can protect data stored in the cloud, or transferred to or from cloud-based resources.
N
ncsc.gov.uk
official
https://www.ncsc.gov.uk/collection/cloud/the-cloud-security-principles
## The principles
### Principle 1: Data in transit protection
your data should be adequately protected against tampering and eavesdropping as it transits networks inside and external to the cloud. This should be achieved using a combination of encryption, service authentication and network-level protections.
Read Principle 1: Data in transit protection
### Principle 2: Asset protection and resilience [...] Summary and context for the 14 Cloud Security Principles, including their goals and technical implementation.
The cloud security principles are designed to help you choose a cloud provider that meets your security needs. You will separately need to consider how you configure your cloud services securely.
These principles apply to both cloud platforms and to Software-as-a-Service.
For each of the principles, we describe: [...] your data, and the assets storing or processing it, should be protected against physical tampering, loss, damage or seizure. Protections should include cover for the legislation that your data is subject to, as well as mitigations such as encryption, data centre security, secure erasure and service resilience.
Read Principle 2: Asset protection and resilience
### Principle 3: Separation between customers
O
orca.security
article
https://orca.security/resources/blog/cloud-security-architecture
Cloud security architecture determines whether security controls form a coherent defense or function as isolated tools with no shared context. The architecture choices made at design time, around IAM scoping, encryption key management, network segmentation, and IaC security, determine how hard it is for an attacker to move laterally, escalate privileges, and reach sensitive data after initial access. [...] It covers the full stack: identity and access management, data encryption, network segmentation, workload security, compliance monitoring, and the division of security responsibilities between cloud providers and their customers. The goal is not a single tool or control, but a coherent design where each layer of the environment has defined security properties and each gap is accounted for before it becomes an exploitable condition. [...] Data security architecture requires encrypting data at rest and in transit and managing encryption keys so that a compromise of the cloud provider does not automatically compromise the data. AWS Key Management Service, Azure Key Vault, and Google Cloud KMS each support customer-managed encryption keys (CMEK), which ensure the cloud provider cannot decrypt customer data without explicit authorization. NIST SP 800-111 provides the standard for encryption of stored data; NIST SP 800-52 Rev 2
C
catonetworks.com
article
https://www.catonetworks.com/glossary/cloud-security-principles
Cloud security is a complex challenge, and overlooking critical details can undermine the security of an organization’s entire cloud environment. The following fourteen cloud security principles describe the core capabilities and security controls required to effectively protect a corporate cloud deployment.
### #1. Shared Responsibility [...] ### #11. Secure Data Management
Companies are increasingly moving sensitive data to cloud-based storage; however, sensitive data is routinely stored unencrypted in the cloud. Cloud storage also makes it easy to retain data when it’s no longer needed, potentially without the organization’s knowledge. Implementing data discovery, classification, encryption, and retention policies is essential to protecting data against unauthorized access and ensuring compliance with applicable regulations. [...] Clouds are multitenant environments where users share resources with others, both inside and outside the organization. This resource sharing is essential to cloud scalability and flexibility, but it also introduces the potential for data leakage, denial of service, and other attacks. The privacy of users’ cloud environments should be enforced via isolation, network segmentation, and access controls to protect against potential data leakage or unauthorized access.
G
geeksforgeeks.org
article
https://www.geeksforgeeks.org/system-design/systems-design-principles-for-clo…
In this article, we will explore essential principles guiding the design of cloud systems, from scalability and reliability to security and cost efficiency.
S
scribd.com
article
https://www.scribd.com/document/906579049/Security-Design-Principles-for-Clou…
Scribd
# Cloud Security Design Principles
Cloud Security Design Principles
## Uploaded by
AI-enhanced title
# Cloud Security Design Principles
# Cloud Security Design Principles
Cloud Security Design Principles
## Uploaded by
AI-enhanced title
## Share this document
## Footer menu
## About
## Support
## Legal
## Social
## Get our free apps
Scribd - Download on the App Store
Scribd - Get it on Google Play
## About
## Legal
## Support
## Social
## Get our free apps [...] Scribd - Download on the App Store
Scribd - Get it on Google Play