Cloud Security Standard
Document control
| Field | Value |
|---|---|
| Document status | Active policy document |
| Owner | Security / Operations |
| Approver | Management |
| Review frequency | Annual or on material change |
| Classification | Customer-shareable |
Purpose
Define baseline security controls for cloud-hosted systems and managed services.
Account and environment governance
Cloud environments should have defined ownership, purpose, access model, logging, budget/cost owner, and security contact. Production, staging, and development resources should be separated where appropriate.
Identity and access
Cloud access must use named users or approved service identities, least privilege, MFA for privileged users where supported, periodic access review, and controlled key/secret handling.
Network and exposure
Public exposure must be limited to required services. Administrative access should be restricted. Security rules should be reviewed, justified, and removed when no longer needed.
Data protection
Sensitive data stores should use encryption, backup, retention, and access control. Secrets must be stored in approved secret mechanisms and not embedded in code or images.
Logging and monitoring
Security-relevant logs should be enabled where appropriate and protected from unauthorized modification. Alerts should be reviewed based on severity.
Backup and resilience
Critical services should have backup, restore, and recovery procedures aligned to business requirements.
Evidence to maintain
Cloud architecture diagram, access review, security rule export, encryption settings, backup settings, logging configuration, and change records.