8 results · ● Live web index
csrc.nist.gov official

SP 500-299, NIST Cloud Computing Security Reference Architecture | CSRC

https://csrc.nist.gov/pubs/sp/500/299/ipd

The purpose of this document is to define a NIST Cloud Computing Security Reference Architecture (NCC-SRA)--a framework that: i) identifies a core set of Security Components that can be implemented in a Cloud Ecosystem to secure the environment, the operations, and the data migrated to the cloud; ii) provides, for each Cloud Actor, the core set of Security Components that fall under their responsibilities depending on the deployment and service models; iii) defines a security-centric formal [...] The purpose of this document is to define a NIST Cloud Computing Security Reference Architecture (NCC-SRA)--a framework that: i) identifies a core set of Security Components that can be implemented in a Cloud Ecosystem to secure the environment, the operations, and the data migrated to the cloud; ii) provides, for each Cloud Actor, the core set of Security Components that fall under their responsibilities depending on the deployment and service models; iii) defines a security-centric formal [...] formal architectural model that adds a security layer to the current NIST SP 500-292, "NIST Cloud Computing Reference Architecture"; and iv) provides several approaches for analyzing the collected and aggregated data.

Visit
wiz.io article

Top Cloud Security Standards & Frameworks: ISO/IEC, NIST, CIS

https://www.wiz.io/academy/compliance/cloud-security-standards

NIST SP 500-292 outlines a cloud security architecture that defines the roles, services, and activities of key cloud actors, including consumers, providers, auditors, brokers, and carriers. Each actor has specific responsibilities, as detailed below: [...] The National Institute of Standards and Technology (NIST) provides comprehensive frameworks to support secure cloud adoption, foster compliance with regulations such as HIPAA and PCI DSS, and enhance cybersecurity for federal agencies and organizations working with them. #### NIST Cloud Computing Security Reference Architecture (SP 500-292) [...] The CCM is an in-depth framework that organizes cloud security controls by service model (IaaS, PaaS, SaaS), provider, and user roles. It addresses key security areas such as cryptography, data protection, identity and access management, and vulnerability assessments, offering tailored control guidelines for various cloud use cases. By aligning with ISO/IEC and NIST cloud security frameworks, the CCM provides a strong foundation for implementing security practices that meet regulatory standards

Visit
cloudaware.com article

NIST Cloud Security: Framework, Controls & Checklist 2026

https://cloudaware.com/blog/nist-cloud-security

NIST cloud security is not a single framework. It is a collection of publications from the National Institute of Standards and Technology that define security outcomes, control requirements, and audit expectations for information systems, including cloud environments. [...] There is no single NIST cloud security standard. The useful model is a stack of documents, each answering a different question. The core set is:nist cloud security nist cloud security But don’t treat any of them as “the standard,” or you will miss parts of the model: ## The NIST Cloud Security Framework explained The NIST Cloud Security Framework most teams refer to is CSF 2.0. It organizes security work into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. [...] NIST CSF 2.0 defines security outcomes. It tells you what the program should achieve across Govern, Identify, Protect, Detect, Respond, and Recover. SP 800-53 defines specific controls such as AC-2, CM-6, AU-6, and CA-7. CSF is useful for structure and reporting. SP 800-53 is where implementation and audit evidence usually start. Which NIST publications are relevant for cloud security?

Visit
aquasec.com article

7 Cloud Security Frameworks and How to Choose

https://www.aquasec.com/cloud-native-academy/cspm/cloud-security-frameworks

#### 2. NIST Cybersecurity Framework The NIST Cybersecurity Framework offers a flexible approach to managing cybersecurity risk in cloud environments. It is structured around five core functions: Identify, Protect, Detect, Respond, and Recover. This framework guides organizations through the process of implementing effective cybersecurity measures, addressing both technological and procedural aspects. A new version of the framework, NIST CSF 2.0, was released in February 2024. [...] NIST’s approach is adaptable, allowing organizations to tailor the framework to their specific needs and risk profiles. It supports continuous improvement, encouraging organizations to evolve their security practices as the threat landscape changes. NIST’s framework is highly regarded for its comprehensiveness and versatility. Useful resources NIST CSF 2.0 quick start guide Full NIST CSF 2.0 framework (32 pages) #### 3. Cloud Security Alliance (CSA) [...] Organizational objectives and risk appetite: Align your chosen framework with your organization’s business objectives and the level of risk it’s willing to accept. Frameworks such as NIST are flexible and suitable for organizations that require adaptability, while ISO takes a more comprehensive approach to information security.

Visit
youtube.com video

All about Cloud Security Architecture - Security Frameworks - Risk Management - Standard (CIS/NIST)

https://www.youtube.com/watch?v=kQyeqRJxrJk

Cloud security Architects build secure high-performing resilient and efficient infrastructure for their applications and workloads the framework includes Hands-On labs and the AWS well architected tool the tool provides a mechanism for regularly evaluating your workloads identifying high risk issues and recording your improvements the Microsoft cloud adoption framework provides tools and guidance for implementing not only Cloud Technologies but also help you with organizational changes because [...] core implementation chairs and profiles the nist framework core provides a set of desired cyber security activities and outcomes using common language that's easy to understand the core guides organization in managing and reducing the cyber security risks in a way that complements an organization's existing security and risk management processes the nist framework implementation tiers assist organizations by providing context on how an organization views cyber security risk management chairs [...] you choose to use architecture implementation is about architecting appropriate security controls that protect confidentiality integrity and availability of information this can help mitigate threats to Cloud security controls can be delivered as a service by the cloud provider by the Enterprise or by the third party provider security architectural patterns are typically expressed from the point of the security controls both for the technology and the organizational processes these security

Visit
getastra.com article

NIST Cloud Security: Standards, Best Practices & Benefits

https://www.getastra.com/blog/compliance/nist/nist-cloud-security

The NIST (National Institute of Standards and Technology) Cyber Security Framework was introduced to help organizations manage and reduce cybersecurity risks. It does not provide specific security controls; however, they are done through special publications. It enables easy customization of cybersecurity practices based on individual company requirements. [...] NIST’s frameworks, guidelines, and security controls are ideal for all companies with cloud assets. Most companies today have multiple cloud assets, such as data, applications, or both; therefore, implementing the best cloud security measures is integral. [...] NIST SP 800 – 500 is a special publication document released by NIST that provides security controls for the successful implementation of cloud security measures based on the NIST cyber security framework. Relevant controls for organizations in the cloud include risk assessments, access control & configuration management. ### What are NIST’s five essential cloud computing characteristics?

Visit
nvlpubs.nist.gov official

NIST Cloud Computing Reference Architecture

https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication500-292.pdf

framework that can be used government-wide. This document presents the NIST Cloud Computing Reference Architecture (RA) and Taxonomy (Tax) that will accurately communicate the components and offerings of cloud computing. The guiding principles used to create the RA were 1) develop a vendor-neutral architecture that is consistent with the NIST definition and 2) develop a solution that does not stifle innovation by defining a prescribed technical solution. This solution will create a level [...] but also NIST SP 500-292 NIST Cloud Computing Reference Architecture 16 Cloud Consumers and other relevant actors. Cloud-based systems still need to address security requirements such as authentication, authorization, availability, confidentiality, identity management, integrity, audit, security monitoring, incident response, and security policy management. While these security requirements are not new, we discuss cloud specific perspectives to help discuss, analyze and implement security in a [...] Architecture”, www.juniper.net/us/en/local/pdf/reference-architectures/8030001-en.pdf Federal Information Security Management Act of 2002 (FISMA), NIST IR-7756, DRAFT “CAESARS Framework Extension: An Enterprise Continuous Monitoring Technical Reference Architecture”, NIST SP 500-292 NIST Cloud Computing Reference Architecture 28 NIST SP 800-61 Rev.1, “Computer Security Incident Handling Guide”, Federal Standard 1037C, The Open Group Architecture Framework (TOGAF), section 21.3,

Visit
aws.amazon.com article

Updated whitepaper available: Aligning to the NIST Cybersecurity Framework in the AWS Cloud | AWS Security Blog

https://aws.amazon.com/blogs/security/updated-whitepaper-available-aligning-t…

Today, we released an updated version of the Aligning to the NIST Cybersecurity Framework (CSF) in the AWS Cloud whitepaper to reflect the significant changes introduced in the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0, published in February 2024. This comprehensive update helps you understand how AWS services align with the enhanced framework and how you can use AWS capabilities to improve your cybersecurity posture. [...] The NIST CSF 2.0 provides guidance to industry, government agencies, and other organizations to manage cybersecurity risks. The updated version introduces important changes, including the following:

Visit