It applies to infrastructure, platform, and software services across public, private, hybrid, and multi-cloud environments. The required controls still serve familiar security objectives, but elastic resources, programmable infrastructure, provider-managed components, and internet-accessible control planes change how those controls are designed and operated.
Responsibility is shared rather than transferred. A cloud provider secures particular parts of the service, while the customer remains responsible for other matters such as identities, configuration, data handling, application code, and endpoint access. The exact boundary depends on the service and contract: a customer typically manages more in infrastructure as a service than in software as a service.
Key points
Govern the serviceClassify data, assess provider and concentration risk, define approved services, document ownership, and plan secure exit and recovery.
Protect the control planeUse strong authentication, least privilege, separate administrative paths, short-lived credentials where practical, and monitored changes.
Engineer secure configurationsEstablish tested baselines for networks, storage, encryption, logging, backups, exposed services, and provider-specific settings.
Maintain visibility and responseInventory resources, centralize useful logs, detect drift and suspicious activity, and rehearse cloud-specific containment and evidence collection.
Important limitationA compliant or well-secured provider does not make every customer deployment secure. Misconfiguration, excessive permissions, insecure code, exposed credentials, and misunderstood responsibility boundaries remain customer risks.