# What is Public Cloud Security?

> Public cloud security is the protection of data, identities, applications, configurations, and customer-controlled resources used in a public cloud deployment.

- Canonical URL: https://yellowcube.eu/glossary/public-cloud-security/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

In the NIST model, the cloud infrastructure is provisioned for open use by the general public, operated by a cloud provider, and located on the provider’s premises. “Public” describes who may subscribe, not whether each customer resource is internet-accessible.

The provider operates the service, but customer responsibility varies across infrastructure, platform, and software services. Customers must identify inherited, shared, configurable, and unavailable controls; protect tenant administration; and assess provider isolation, resilience, data handling, support, and incident obligations.

### Key points

- **Service selection:** Match data sensitivity, availability, location, portability, legal, and recovery needs to the provider, service model, contract, evidence, and controls.
- **Tenant operation:** Apply strong administrative authentication, least privilege, defaults, exposure controls, encryption and key decisions, configuration review, logging, backup, and incident procedures.
- **Data and resilience:** Track copies, subprocessors, regions, deletion behavior, quotas, dependencies, and exit formats; plan for account compromise, disruption, and provider incidents.
- **Important limitation:** Provider certification or secure infrastructure does not establish that a customer tenant, identity policy, application, or dataset is secure. Public cloud is not inherently public-facing or less isolated than private infrastructure. Private endpoints still depend on provider controls and customer configuration.

### Related terms

[Cloud security](<https://yellowcube.eu/glossary/cloud-security/>) · [Cloud security architecture](<https://yellowcube.eu/glossary/cloud-security-architecture/>) · [Cloud service models: IaaS, PaaS, and SaaS](<https://yellowcube.eu/glossary/cloud-service-models-iaas-paas-and-saas/>) · [Virtual private cloud (VPC)](<https://yellowcube.eu/glossary/virtual-private-cloud/>) · [Cloud security posture management (CSPM)](<https://yellowcube.eu/glossary/cloud-security-posture-management/>)

### Sources

[NIST SP 800-145: The NIST Definition of Cloud Computing](https://csrc.nist.gov/pubs/sp/800/145/final) · [NIST SP 800-144: Security and Privacy in Public Cloud Computing](https://csrc.nist.gov/pubs/sp/800/144/final) · [CISA Cloud Security Technical Reference Architecture v2](https://www.cisa.gov/sites/default/files/2023-02/cloud_security_technical_reference_architecture_2.pdf)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

