# What is Cloud Security?

> Cloud security is the discipline of protecting data, identities, applications, workloads, management interfaces, and supporting services used in cloud computing.

- Canonical URL: https://yellowcube.eu/glossary/cloud-security/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It applies to infrastructure, platform, and software services across public, private, hybrid, and multi-cloud environments. The required controls still serve familiar security objectives, but elastic resources, programmable infrastructure, provider-managed components, and internet-accessible control planes change how those controls are designed and operated.

Responsibility is shared rather than transferred. A cloud provider secures particular parts of the service, while the customer remains responsible for other matters such as identities, configuration, data handling, application code, and endpoint access. The exact boundary depends on the service and contract: a customer typically manages more in infrastructure as a service than in software as a service.

### Key points

- **Govern the service:** Classify data, assess provider and concentration risk, define approved services, document ownership, and plan secure exit and recovery.
- **Protect the control plane:** Use strong authentication, least privilege, separate administrative paths, short-lived credentials where practical, and monitored changes.
- **Engineer secure configurations:** Establish tested baselines for networks, storage, encryption, logging, backups, exposed services, and provider-specific settings.
- **Maintain visibility and response:** Inventory resources, centralize useful logs, detect drift and suspicious activity, and rehearse cloud-specific containment and evidence collection.
- **Important limitation:** A compliant or well-secured provider does not make every customer deployment secure. Misconfiguration, excessive permissions, insecure code, exposed credentials, and misunderstood responsibility boundaries remain customer risks.

### Related terms

[Shared responsibility model](<https://yellowcube.eu/glossary/shared-responsibility-model/>) · [Cloud-native application protection platform (CNAPP)](<https://yellowcube.eu/glossary/cloud-native-application-protection-platform/>) · [Cloud security posture management (CSPM)](<https://yellowcube.eu/glossary/cloud-security-posture-management/>) · [Cloud workload protection platform (CWPP)](<https://yellowcube.eu/glossary/cloud-workload-protection-platform/>) · [Cloud infrastructure entitlement management (CIEM)](<https://yellowcube.eu/glossary/cloud-infrastructure-entitlement-management/>) · [Zero trust architecture (ZTA)](<https://yellowcube.eu/glossary/zero-trust-architecture/>) · [Data center security](<https://yellowcube.eu/glossary/data-center-security/>)

### Sources

[NIST SP 800-144: Guidelines on Security and Privacy in Public Cloud Computing](https://csrc.nist.gov/pubs/sp/800/144/final) · [NIST SP 800-210: General Access Control Guidance for Cloud Systems](https://csrc.nist.gov/pubs/sp/800/210/final) · [CSA: Introductory Guidance to the Cloud Controls Matrix](https://cloudsecurityalliance.org/artifacts/introductory-guidance-to-ccm)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

