# What is Multi-Cloud Security?

> Multi-cloud security is an industry term for protecting an organization’s use of cloud services from more than one cloud provider.

- Canonical URL: https://yellowcube.eu/glossary/multi-cloud-security/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The services may be independent or connected and may span infrastructure, platform, and software delivery models. The defining issue is provider plurality: each provider has different identities, policies, APIs, logs, service limits, responsibility boundaries, and failure modes.

The objective is consistent security intent with provider-aware implementation, not identical controls. Organizations need an inventory, accountable owners, common data and identity governance, and protected cross-cloud trust, network, API, data, and delivery paths.

### Key points

- **Governance and inventory:** Record providers, accounts, services, regions, owners, data, dependencies, administrative identities, contracts, and approved connections; include unsanctioned and inherited services in discovery.
- **Policy and evidence:** Define common outcomes, implement them through provider-specific controls, normalize only the telemetry needed for review and response, and test whether equivalent-looking settings behave equivalently.
- **Resilience and portability:** Assess common identity, DNS, code, key, network, and monitoring dependencies; rehearse provider and integration failures; and verify that data, configurations, and recovery materials can be exported and restored.
- **Important limitation:** Using several providers does not automatically reduce concentration risk or create portability. A shared identity provider, deployment pipeline, library, telecom path, or security platform can still fail across clouds. Least-common-denominator policy may also discard stronger native protections while presenting an appearance of consistency.

### Related terms

[Hybrid cloud security](<https://yellowcube.eu/glossary/hybrid-cloud-security/>) · [Cloud security architecture](<https://yellowcube.eu/glossary/cloud-security-architecture/>) · [Cloud security posture management (CSPM)](<https://yellowcube.eu/glossary/cloud-security-posture-management/>) · [Cloud network security](<https://yellowcube.eu/glossary/cloud-network-security/>) · [Cloud security](<https://yellowcube.eu/glossary/cloud-security/>)

### Sources

[NIST SP 800-207A: Zero Trust Access Control in Multi-Cloud Applications](https://csrc.nist.gov/pubs/sp/800/207/a/final) · [NIST IR 8505: Data Protection for Cloud-Native Applications](https://csrc.nist.gov/pubs/ir/8505/final) · [NIST Multi-Cloud Security Public Working Group](https://csrc.nist.gov/Projects/mcspwg)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

