Organizations are shifting from exclusively on-premises IT to hybrid delivery that mixes on-premises, hosting, and multiple cloud services to support digital transformation, increase flexibility, and reduce costs. This shift improves options for resilience, demand spikes, and compliance-driven placement of sensitive workloads, but it also increases management, security, and compliance complexity because control is no longer fully centralized within the organization’s data center.
Hybrid service delivery requires governing and securing five distinct planes: physical infrastructure; virtualization/abstraction (IaaS); middleware/tools (PaaS); business applications (SaaS); and the top plane of data governance and access control, including endpoint security. On premises, responsibility across planes is clear; in cloud services it is split between the customer and the cloud service provider (CSP) depending on the service model. This shared-responsibility split becomes especially difficult when a single business system spans delivery modes—for example, an on-premises application using public cloud storage, or a SaaS application accessing regulated data in a private cloud or on premises.
To manage these interdependencies, a consistent security architecture is required that defines components that must exist regardless of delivery model, while clarifying who implements each component. The customer remains accountable for meeting business needs: it must ensure controls it owns meet standards and must assure CSP-implemented components meet requirements. KuppingerCole’s Hybrid Cloud Security Reference Architecture provides a building-block foundation and blueprint organized around six common elements—governance, management processes, risk management, standards, controls, and audit—applied consistently across all service planes. Risk management should use scenarios, assess likelihood and impact against risk tolerance, document decisions and residual risk in a risk register, and drive control selection and assurance activities, including independent certifications and attestations.
See All Locations
See All Locations