7 results ·
● Live web index
S
sentinelone.com
article
https://www.sentinelone.com/cybersecurity-101/cloud-security/cloud-security-s…
ISO/IEC 27017 adds cloud-specific controls on top of ISO 27002, defining who is responsible for tasks like virtual machine hardening, asset return at contract end, and cloud network separation. ISO/IEC 27018 focuses on protecting personally identifiable information (PII) in public clouds, extending ISO 27002 controls with guidance on consent, data deletion, and breach notification. Together, they guide both providers and customers through secure, privacy-aware cloud use. [...] The ISO/IEC 27017 standard acts as a guide focusing on information security relevant to cloud computing. It suggests security controls for both parties – the cloud service providers and the customers. This standard extends the reach of ISO/IEC 27002, adjusting it to cater to the specific needs of cloud services. When organizations incorporate ISO/IEC 27017, they can bolster their cloud services’ security, dependability, and compliance, aligning with international best practices. [...] Adhering to cloud security standards helps you prove compliance with laws such as GDPR, HIPAA, and PCI DSS by mapping controls directly to regulatory requirements. They lay out clear processes for handling personal data, consent, and breach reporting, reducing legal risk and potential fines.
When you follow these standards, you also demonstrate to auditors and clients that you take data privacy seriously and maintain a reliable audit trail.
O
orca.security
article
https://orca.security/resources/blog/cloud-security-standards-for-compliance
Cloud security standards and frameworks give organizations a shared language for controls, evidence, and assurance in cloud environments.
The most relevant mix depends on sector, geography, and customer contracts: ISO/IEC for management systems, NIST for detailed control catalogs, CIS for technical hardening, and sector rules such as PCI DSS or HIPAA. Implementation requires mapping controls to owners, automating evidence where possible, and revisiting scope when architecture changes. [...] Key Takeaways
What Are Cloud Security Standards?
The Importance of Cloud Security Standards
Top 10 Cloud Security Standards
+ 1. ISO/IEC Standards
+ 2. National Institute of Standards and Technology (NIST) Security Controls
+ 3. Cloud Security Alliance (CSA) Standards
+ 4. Center for Internet Security (CIS) Benchmarks
+ 5. FedRAMP (Federal Risk and Authorization Management Program)
+ 6. SOC 2 (Service Organization Control 2)
+ 7. HIPAA and HITECH [...] Key Takeaways
What Are Cloud Security Standards?
The Importance of Cloud Security Standards
Top 10 Cloud Security Standards
+ 1. ISO/IEC Standards
+ 2. National Institute of Standards and Technology (NIST) Security Controls
+ 3. Cloud Security Alliance (CSA) Standards
+ 4. Center for Internet Security (CIS) Benchmarks
+ 5. FedRAMP (Federal Risk and Authorization Management Program)
+ 6. SOC 2 (Service Organization Control 2)
+ 7. HIPAA and HITECH
D
datasunrise.com
article
https://www.datasunrise.com/knowledge-center/data-security-standards
ISO 27018 – Privacy controls for public cloud services
ISO 27031 – ICT readiness for business continuity
ISO 27037 – Guidelines for digital evidence handling
ISO 27040 – Storage security techniques
ISO 27799 – Security management in health informatics
### NIST SP 800 & SP 1800 Series
The National Institute of Standards and Technology (NIST) provides detailed publications for securing federal and commercial data environments. Highlights include: [...] Adhering to established standards is essential for businesses to meet compliance obligations and mitigate the risks of breaches. Standards like ISO 27001 and PCI DSS are globally recognized and often mandated by industry regulations. They provide structured guidance for implementing robust security controls, auditing data access, and responding to incidents. Compliance not only reduces the risk of legal penalties but also strengthens stakeholder confidence. [...] | GDPR (General Data Protection Regulation) | EU regulation enforcing strict data protection and privacy requirements for personal data. Affects organizations worldwide handling EU citizen data. |
| HITRUST CSF | Combines healthcare, finance, and third-party risk compliance into a unified security framework tailored for regulated industries. |
| COBIT | A governance and management framework aligning IT with business goals while supporting compliance and audit readiness. |
S
seagate.com
article
https://www.seagate.com/blog/cloud-storage-security-standards-and-maintenance
Seagate Lyve Cloud services enforce transport layer security protocol 1.2 by incorporating the 256-bit advanced encryption standard (AES). This encryption protocol establishes extremely secure communication between the Lyve Cloud and the client.
## Zero-Knowledge Authentication [...] There is a broad array of data storage security standards and compliance regulations. Some of these storage security standards are industry-specific, whereas others govern the actions of businesses operating within a particular region or nation. A few of the most notable data storage security standards include the following:
## GDPR [...] In order for a business to process debit and credit card transactions, it must comply with PCI-DSS provisions. Businesses must use anti-virus software, encrypt data transmissions, and deploy firewalls in order to demonstrate compliance.
These are only a few of the many provisions included in the PCI-DSS framework. Organizations that store credit card information, such as eCommerce stores, must take additional steps to achieve PCI-DSS compliance.
## Best Practices for Cloud Storage Security
I
intervision.com
article
https://intervision.com/blog-navigating-compliance-considerations-in-data-sto…
Compliance frameworks play a crucial role in data storage security. They provide guidelines and best practices for securing data and maintaining compliance. Frameworks such as the GDPR, HIPAA, and SOX outline specific requirements for data storage. These include data protection measures, data retention policies, and data access controls. [...] Cloud storage is becoming increasingly popular due to its scalability and cost-efficiency. However, it also introduces new compliance considerations. Organizations must ensure that their cloud providers meet the necessary compliance standards, and that data stored in the cloud is adequately protected. [...] Cloud storage is one such technology. It offers scalability and cost-efficiency, but also introduces new compliance considerations. Organizations must ensure that their cloud providers meet the necessary compliance standards.
Artificial Intelligence (AI) is another emerging technology with significant implications for data storage compliance. AI can automate compliance tasks and provide predictive insights, but its use also raises questions about data privacy and security.
M
media.defense.gov
official
https://media.defense.gov/2024/Mar/07/2003407862/-1/-1/0/CSI-CLOUDTOP10-SECUR…
Mar 7, 2024 — All interactions with cloud storage that include sensitive data should be encrypted using Commercial National Security Algorithm (CNSA) Suite 1 ...7 pages
C
cloud.google.com
article
https://cloud.google.com/learn/what-is-cloud-data-security
Being compliant in the context of the cloud requires that any services and systems protect data privacy according to legal standards and regulations for data protection, data sovereignty, or data localization laws. Certain industries, such as healthcare or financial services, will also have an additional set of laws that come with mandatory guidelines and security protocols that will need to be followed. [...] Databases
AlloyDB for PostgreSQL
Fully managed, PostgreSQL-compatible database for enterprise workloads.
Cloud SQL
Fully managed database for MySQL, PostgreSQL, and SQL Server.
Firestore
Highly scalable and serverless NoSQL document database, with MongoDB compatibility.
Spanner
Cloud-native relational database with unlimited scale and 99.999% availability.
Bigtable
Cloud-native wide-column database for large-scale, low-latency workloads.
Datastream [...] Datastream
Serverless change data capture and replication service.
Database Migration Service
Serverless, minimal downtime migrations to Cloud SQL.
Bare Metal Solution
Fully managed infrastructure for your Oracle workloads.
Memorystore
Fully managed Redis and Memcached for sub-millisecond data access.
Developer Tools
Artifact Registry
Universal package manager for build artifacts and dependencies.
Cloud Code