Cloud computing is the delivery of storage, applications, and compute resources over the internet instead of from local infrastructure. It lets organisations scale faster and shift operational responsibility, but it also introduces shared control boundaries that require stronger governance, access management, and monitoring than many on-premises environments.
What Cloud Computing Changes in the Security Model
Cloud computing changes where control lives. Instead of managing every layer locally, organisations consume infrastructure, platforms, and applications through a provider, which shifts responsibility but does not remove the need to govern access, configuration, and trust boundaries.
The practical consequence is that cloud security is partly about the service itself and partly about how customers configure and operate it. A secure cloud posture depends on understanding shared responsibility, tenant isolation, exposed management surfaces, and the blast radius of misconfiguration.
Shared Responsibility and Control Boundaries
Cloud security is defined by the split between provider-managed and customer-managed controls. Providers usually secure the underlying infrastructure, while customers remain accountable for identities, data, configuration, workload hardening, and the way services are exposed or interconnected.
That boundary is the source of many cloud failures. Teams often assume the platform is “secure by default,” but in practice the strongest risks come from what the customer leaves open, over-permits, or fails to monitor. This is why cloud governance is not just procurement oversight, it is an operating model.
For cloud control design, NIST Cybersecurity Framework 2.0 and NIST AI Risk Management Framework are useful reference points when cloud services also support AI-enabled workloads, because both emphasise governance, protection, detection, and recovery as ongoing responsibilities.
Cloud Security Controls That Matter Most
The most important cloud controls are the ones that reduce exposure across accounts, workloads, APIs, storage, and administrative planes. That typically includes identity and access control, encryption, logging, network segmentation, secure configuration, asset inventory, and continuous review of permissions and service exposure.
Cloud environments also magnify the effect of weak defaults. A single overbroad role, public storage bucket, exposed management API, or unmonitored temporary credential can create organisation-wide exposure faster than in traditional infrastructure because cloud services are easy to scale, copy, and connect.
For practitioners, this is why prescriptive control baselines matter. NIST SP 800-53 Rev 5 Security and Privacy Controls gives a broad control catalogue for access control, audit, configuration management, and system integrity, while CIS Benchmarks provide hardening guidance for common cloud-adjacent platforms and services.
Why Cloud Computing Becomes a Risk Concentrator
Cloud introduces concentration risk because a small number of accounts, identities, templates, and service controls can govern very large estates. If those control points fail, the impact can be systemic, not local. Multi-tenant design also means isolation assumptions must hold under heavy scale and frequent change.
Cloud also changes incident response. Visibility depends on telemetry from provider services, logs, APIs, and orchestration layers, which means detection quality is tied to how well the organisation instruments the platform. Where services are rapidly created and destroyed, weak inventory and poor configuration drift control can hide exposure for long periods.
That makes zero trust thinking valuable in cloud architectures. NIST SP 800-207 Zero Trust Architecture helps frame cloud access as continuously verified, not implicitly trusted, and NIST Privacy Framework is relevant where cloud services process sensitive personal or regulated data.
Risk and Threat Considerations
Cloud computing concentrates risk around exposed management interfaces, excessive permissions, weak tenant configuration, and dependency on provider-side availability and isolation. The most damaging failures usually come from misconfiguration, stolen credentials, or an attacker pivoting through over-privileged control planes rather than from the cloud model itself.
Failure mechanism: Attackers or careless operators exploit shared control planes, overly broad access, public services, and weak logging to reach data, workloads, or orchestration layers that were assumed to be protected by the provider.
Impact: The result can be data exposure, service outage, large-scale privilege abuse, lateral movement across cloud resources, or recovery difficulty when the organisation lacks sufficient telemetry and configuration control.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 — Organizational Context | Cloud computing changes operating responsibility and governance boundaries. |
| PR.AA-05 — Asset is Protected by Least Privilege Access | Cloud security depends on controlling access to accounts, workloads, and management planes. | |
| PR.DS-01 — Data-at-Rest is Protected | Cloud services commonly store sensitive data in provider-managed storage. | |
| Recommendation — Define cloud ownership and responsibility boundaries before service adoption. Enforce least privilege across cloud identities and administrative paths. Apply encryption and access controls to cloud-stored data. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Cloud environments rely on governed accounts, roles, and service access. |
| AU-2 — Event Logging | Cloud detection depends on telemetry from APIs, logs, and orchestration layers. | |
| CM-2 — Baseline Configuration | Cloud risk often stems from drift and insecure default configurations. | |
| Recommendation — Review and revoke cloud accounts and roles on a defined lifecycle. Log cloud control-plane and workload events for detection and response. Standardise secure cloud baselines and monitor for configuration drift. | ||
| NIST Zero Trust (SP 800-207) | Zero Trust Architecture | Cloud access works best when trust is continuously verified across services. |
| Recommendation — Design cloud access paths around continuous verification and least privilege. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Cloud exposure is heavily shaped by permission sprawl and account governance. |
| CIS-4 — Secure Configuration of Enterprise Assets and Software | Cloud services fail often through insecure configuration and exposed defaults. | |
| Recommendation — Continuously inventory, review, and remove excessive cloud access. Harden cloud services and monitor configuration against approved baselines. | ||
Practitioner Guidance
Governance implication: Cloud must be owned as a continuous security operating model, not a one-time migration project. The control question is not whether the provider is secure, but whether your organisation can prove who can access what, what is exposed, and how quickly drift is detected.
What to watch for: Public-facing storage, long-lived credentials, unreviewed admin roles, unmanaged service sprawl, and inconsistent logging are early signs that cloud risk is accumulating faster than the governance process can absorb it.
Practitioner takeaway: Treat cloud as a shared-control environment where configuration discipline, access governance, and telemetry quality determine the real security outcome.
Related resources from NHI Mgmt Group
- Why do cloud desktop environments need tighter identity and access controls than traditional end-user computing setups?
- What is the difference between scalability and elasticity in cloud computing?
- How should security teams use confidential computing to process encrypted data in cloud environments without weakening end-to-end encryption?
- What is the difference between confidential computing and ordinary cloud processing for sensitive security workloads?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 25, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org