The report analyzes information security risks associated with cloud services and defines controls organizations should implement to manage them. Cloud adoption is widespread, including both deliberate use for business transformation, agility, and cost reduction (e.g., email and CRM) and informal employee-driven use to “get the job done.” Cloud computing is framed as an alternative delivery method rather than a strategic question in itself; the central task is balancing risks and rewards for each business need.
Because cloud services place infrastructure and service control primarily with the Cloud Service Provider (CSP), risk and compliance conditions change, and responsibility becomes shared. Large CSPs often implement strong infrastructure security, making customer misunderstanding of shared responsibility and weak customer-side controls a common cause of breaches. Compliance is frequently more complex than security because customers may remain accountable even if a CSP fails, while contracts typically limit CSP liability. Regulated-data use therefore requires independent verification of compliance and, where needed, supplementary customer controls.
Risk and responsibility vary by service model (IaaS, PaaS, SaaS, plus BPaaS and cloud-delivered IT management services) and by deployment model (public, private, community, hybrid). The report recommends governance-based risk management rooted in business objectives, procurement discipline, and measurable security/compliance requirements. It emphasizes information-centric security: classify data and applications by sensitivity and business criticality, then select controls accordingly. Key risk areas include loss of governance, lock-in and data return, non-compliant processing and privacy obligations, ineffective identity and access management, business continuity disruptions, cyber threats (DDoS/malware), platform isolation failures, insider abuse, management-interface compromise, interception of data in transit, ineffective data deletion, media loss/data breach, loss of keys/passwords, backup and recovery gaps, and log/journal compromise.
See All Locations
See All Locations