Cloud Security Best Practices Derived from Mission Thread Analysis

Abstract

This report presents four important security practices that are practical and effective for improving the cybersecurity posture of cloud-deployed information technology (IT) systems. These practices help to address the risks, threats, and vulnerabilities that organizations face in deploying or moving applications and systems to a cloud service provider (CSP).The practices address cloud security issues that consumers are experiencing, illustrated by several recent cloud security incidents. The report demonstrates the practices through examples using cloud services available from Amazon Web Service (AWS), Microsoft, and Google. The presented practices are geared toward small and medium-sized organizations; however, all organizations, independent of size, can use these practices to improve the security of their cloud usage. The focus here is on hybrid deployments where some IT applications deploy or move to a CSP while other IT applications remain in the organization's data center. Small and medium-sized organizations likely have limited resources; where possible, these practices describe implementation approaches that may be effective in limited-resource situations.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
May 01, 2021
Accession Number
AD1139951

Entities

People

  • Angel Hueca
  • Don Faatz
  • Nathaniel Richmond
  • Timothy Morrow
  • Vincent Lapiana

Organizations

  • Carnegie Mellon University

Tags

Communities of Interest

  • C4I
  • Cyber
  • Engineered Resilient Systems

DTIC Thesaurus Topics

  • Best Practices
  • Cloud Computing
  • Computer Access Control
  • Computer Programming
  • Computer Programs
  • Computers
  • Cybersecurity
  • Data Centers
  • Engineering
  • Information Security
  • Information Systems
  • Operating Systems
  • Security
  • Software Development
  • Standards
  • Vulnerability
  • Web Service

Fields of Study

  • Computer science

Readers

  • Cybersecurity.
  • Distributed Systems and Data Platform Development
  • Systems Analysis and Design

Technology Areas

  • Cyber