Advertisements

NSA researchers released cloud security mitigation strategies in an attempt to educate best security practices. Threat actors mostly target cloud users while they shift their data to cloud environments.
Advertisements
For six of the 10 strategies, the Cybersecurity and Infrastructure Security Agency collaborates with the National Security Agency.
- Uphold the cloud shared responsibility model
- Use secure cloud identity and access management practices
- Use secure cloud key management practices
- Implement network segmentation and encryption in cloud environments
- Secure data in the cloud
- Defending continuous integration/continuous delivery environments
- Enforce secure automated deployment practices through infrastructure such as code
- Account for complexities introduced by hybrid cloud and multi-cloud environments
- Mitigate risks from managed service providers in cloud environments
- Manage cloud logs for effective threat hunting