Tutorials/Cloud Security Standard

Cloud Security Standard

Document control

Field Value
Document status Active policy document
Owner Security / Operations
Approver Management
Review frequency Annual or on material change
Classification Customer-shareable

Purpose

Define baseline security controls for cloud-hosted systems and managed services.

Account and environment governance

Cloud environments should have defined ownership, purpose, access model, logging, budget/cost owner, and security contact. Production, staging, and development resources should be separated where appropriate.

Identity and access

Cloud access must use named users or approved service identities, least privilege, MFA for privileged users where supported, periodic access review, and controlled key/secret handling.

Network and exposure

Public exposure must be limited to required services. Administrative access should be restricted. Security rules should be reviewed, justified, and removed when no longer needed.

Data protection

Sensitive data stores should use encryption, backup, retention, and access control. Secrets must be stored in approved secret mechanisms and not embedded in code or images.

Logging and monitoring

Security-relevant logs should be enabled where appropriate and protected from unauthorized modification. Alerts should be reviewed based on severity.

Backup and resilience

Critical services should have backup, restore, and recovery procedures aligned to business requirements.

Evidence to maintain

Cloud architecture diagram, access review, security rule export, encryption settings, backup settings, logging configuration, and change records.

Need help with your workflow setup?

If you're stuck or want help applying these guides to your setup, our team can assist with configuration, customization, and workflow implementation.