Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • What is Cloud Computing Security? current page
Link copied

What is Cloud Computing Security?

Sep 19, 2017
Author:
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor
Blog banner default
What is Cloud Computing Security?
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor

According to Wikipedia, cloud security is a broad set of policies, technologies, and controls deployed to protect data, applications, and the associated infrastructure of cloud computing.

It is undisputed that more and more organizations are moving computing power to the cloud. In fact, some IT organizations have adopted a “cloud first” strategy for all new deployments and will only consider new on-premise deployments when the technology, cost, or sensitivity warrants a deviation from a cloud deployment.

With this in mind, there are operational challenges – from automation (DevOps) to security – that every organization should consider as they move to the cloud. The security services we rely on today for on premise implementations do not necessarily translate to the cloud and there are other (new) risks we should consider. This is true for public, hybrid, and private cloud environments, and should involve more the than just the security team when key decisions are being made. The outcome will generally affect more of the implementation and services than was ever scoped for an on premise equivalent.

The simple reason why is rather obvious but often overlooked – you do not own, typically have access to, or control any of the physical aspects of a cloud environment. It is after all, someone else’s computer.

Managing Cloud Security

So how do you quantify and manage cloud security? Here are five basic premises to get you started.

1) Network Segmentation

Consider a strong zone approach to keep instances, containers, applications, and full systems isolated from each other when possible. This will stop lateral movement in an attack and inappropriate access between systems by any threat actor.

2) Cloud-based Access Controls

All aspects of computing in the cloud should have access control lists. Since services like a database can be instantiated separately, it is more important than it is for on premise to define and implement proper access controls. This includes any virtual infrastructure, operating systems, applications, and even tools used to monitor the environment. A least privilege, or fully closed, security model is a preferred approach. In addition, just because it is in the cloud does not mean that it should be publicly addressable. Only expose the resources you need to the Internet (if any) and secure the rest.

3) Multi-tenancy in Cloud Computing

While multi-tenancy provides scalability and segmentation benefits by design, there are also chances of data bleed and irregular boundaries (like reporting or data export) that might not be controllable in the cloud. Consider access controls in a multi-tenant environment and policy boundaries for any account that may have access across tenants.

4) Cloud Access Management

Remember, these are not your computers. Concepts like a crash cart do not necessarily apply. So, you need to manage privileged access to all cloud resources and also consider disaster recovery and any failures in your privileged access scope. We manage privileges today on premise with password management solutions and administrator accounts. We need the same concepts in the cloud but do not want cloud administrator rights to be everywhere. This would negate the previous concepts of zones and access control lists. Privileges need to be role based, appropriately delegated, and monitored for usage to ensure the access is appropriate.

5) Cloud Computing Threats and Vulnerabilities

This concept translates one for one from on premise implementations but may use agents and other integration technologies to determine the premise of vulnerabilities. Once identified, they need to be prioritized using threat intelligence and remediated in a timely fashion. This is old school low hanging fruit that regardless of the computing environment must be done like clockwork to ensure good cybersecurity hygiene.

Other Cloud Computing Security Considerations

Now that the basics are covered – and arguably there are more – what else do you need to consider? Cloud environments have traits like Hypervisors that are not present on premise unless you have your own virtual environment (and you probably do); but you have no access to manage it in the cloud. Consider the security tips above for the following disciplines:

  • Securing any and all access to virtualization technology and any access to the hypervisor your organization may have.
  • The data you store in the cloud, at rest and in motion, is just as valuable to a threat actor as on premise. Just because it is in the cloud does not degrade its potential value or risk. Consider how you safeguard it and how you monitor appropriate access.
  • Application Programming Interfaces are very common in cloud environments and used for everything from DevOps to monitoring solutions. Consider how these are accessed, locked down, and monitored for inappropriate access.

Finally, if you need help, there is plenty of it. Consider the Cloud Security Alliance and Critical Areas of Cloud Computing (noted below).

These resources cover everything from auditing to security management to ensure you identify all your potential weakness and have policies to mitigate the cloud’s unique risks.

If you need additional assistance, BeyondTrust is here to help as well. We have privileged access management and vulnerability management solutions that cover some of these recommendations to enforce security best practices. Contact us today to learn more about cloud security solutions.

Latest Posts
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
Related
  • Let's TalkTalk about data breaches. It's not so simple
    Oct 20, 2017 Let's TalkTalk about data breaches. It's not so simple
    Blog
    1m
  • Bomgar in the News: No Room for Complacency in Today’s Security Thread Landscape
    Nov 13, 2017 Bomgar in the News: No Room for Complacency in Today’s Security Thread Landscape
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.