Cloud security is the discipline of protecting data, applications, identities and infrastructure hosted in cloud computing environments against unauthorised access, misconfiguration, data loss and service disruption. It applies controls across the shared-responsibility boundary between cloud providers and customers, spanning identity and access management, encryption, network segmentation, configuration governance and continuous monitoring. Cloud security extends established information-security principles to elastic, multi-tenant and API-driven platforms where infrastructure is provisioned programmatically.
Overview
- Cloud security adapts information-security practice to environments where infrastructure is software-defined, multi-tenant and provisioned through APIs. The shared-responsibility model divides obligations: providers secure the underlying platform, while customers secure their data, identities, configurations and code.
- Because misconfiguration rather than provider compromise is the dominant cause of cloud incidents, much of the discipline focuses on configuration governance, least-privilege identity and continuous posture monitoring.
Key aspects
- Shared responsibility: the division of security duties shifts with the service model from infrastructure to platform to software.
- Identity-centric control: fine-grained, least-privilege access management is the primary perimeter.
- Data protection: encryption at rest and in transit, key management and loss prevention safeguard information.
- Posture management: automated detection of misconfiguration and drift maintains a secure baseline.
Mechanisms
- Policy-as-code and configuration scanning enforce secure defaults across accounts and resources.
- Centralised logging, threat detection and anomaly analytics surface attacks in near real time.
- Network segmentation and zero-trust verification limit lateral movement.
Applications
- Securing SaaS, PaaS and IaaS deployments, regulated workloads, hybrid and multi-cloud estates and DevOps pipelines.