The controls that protect workloads, data, and access inside a customer’s cloud environment. This includes user permissions, application security, data handling policies, and other settings the customer must configure and govern. It becomes more detailed as the customer moves from SaaS toward PaaS and IaaS.
How Security In The Cloud Differs Across SaaS, PaaS, and IaaS
Security in the cloud is best understood as a shared-responsibility problem that shifts with the service model. In SaaS, the provider secures most of the stack, while the customer focuses on access, data handling, and configuration. In PaaS and IaaS, the customer inherits more control and more security responsibility, including how applications, identities, network paths, and secrets are governed.
That shift matters because the same cloud service can be configured safely or dangerously without changing the product itself. Misconfiguration is often the real failure point, especially when teams assume the provider has secured settings, permissions, or data use on their behalf. The practical question is not whether the cloud is secure in general, but which layer the customer must actively secure.
Core Control Areas That Shape Cloud Security
Cloud security usually comes down to a small set of control domains: access control, workload hardening, data protection, logging, and policy enforcement. The strongest programmes make these controls explicit across accounts, projects, subscriptions, and workloads instead of treating each cloud service as a one-off exception.
Identity and permissions are especially important because cloud compromise often starts with excessive access rather than a software exploit. Data protection also needs attention at rest, in transit, and in use, with clear rules for classification, encryption, retention, and sharing. For broader cloud control mapping, the CSA Cloud Controls Matrix is one of the most direct reference points, while ISO/IEC 27001:2022 Information Security Management provides a governance-oriented control structure that includes cloud, access, and authentication requirements.
Common Failure Modes And Why They Matter
Most cloud incidents are not caused by the cloud model itself, but by weak configuration, weak governance, or weak segregation between tenants, accounts, and workloads. Public exposure, overbroad permissions, insecure storage, and poor logging all create conditions where a small mistake can become broad data loss or unauthorized control.
Cloud environments also fail when teams move faster than their security process. Rapid provisioning is useful, but if it is not paired with guardrails, review, and lifecycle management, it creates drift and invisible risk. That is why cloud security is as much about continuous control verification as it is about initial design. A useful security mechanism for this pattern is the discipline captured by NIST Cybersecurity Framework 2.0, especially where organisations need a repeatable way to govern and protect cloud assets over time.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV — Govern | Cloud security needs ownership and governance for shared responsibility and configuration control. |
| PR.AC — Identity Management, Authentication, and Access Control | Cloud risk is often driven by permissions, access paths, and authorization settings. | |
| PR.DS — Data Security | Cloud security centers on protecting customer data across storage, transfer, and use. | |
| Recommendation — Define cloud control ownership and review it as part of your govern function. Apply access control rigor to cloud permissions, roles, and administrative paths. Classify and protect cloud data with encryption, retention, and handling rules. | ||
| CIS Controls v8 | 6 — Access Control Management | Cloud security relies on controlling who can reach accounts, workloads, and data. |
| 3 — Data Protection | Cloud environments must protect stored and transmitted data under customer control. | |
| 4 — Secure Configuration of Enterprise Assets and Software | Misconfiguration is a primary cloud failure mode across SaaS, PaaS, and IaaS. | |
| Recommendation — Restrict cloud access paths and remove unnecessary permissions promptly. Apply data protection controls to cloud-stored and cloud-shared information. Establish secure cloud baselines and monitor them for drift. | ||
| NIST SP 800-53 Rev 5 | AC — Access Control | Cloud security depends on limiting and enforcing access to workloads and data. |
| CM — Configuration Management | Cloud security often succeeds or fails on configuration governance and drift control. | |
| SC — System and Communications Protection | Cloud workloads require protections for network paths, boundaries, and data flows. | |
| Recommendation — Enforce least privilege across cloud identities and administrative functions. Control cloud configuration changes and track drift against approved baselines. Protect cloud communications and boundary controls with least-exposure design. | ||
Practitioner Guidance
Why practitioners should care: Cloud security decisions become more demanding as responsibility shifts from SaaS toward PaaS and IaaS. The earlier teams define who configures access, data, logging, and recovery, the less likely they are to leave critical controls implicit.
Common misunderstanding: “Cloud provider secured” does not mean “customer secure.” The provider may protect infrastructure, but customer-managed settings still decide whether workloads, data, and access are exposed or contained.
Practitioner takeaway: Treat cloud security as an operating model, not a product feature, and verify the controls that your team actually owns.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org