D5Protection of Information Assets

Cloud Security

What It Is and Why It Matters

Cloud security refers to the policies, technologies, controls, and practices that protect cloud-based systems, data, and infrastructure. As organizations increasingly migrate workloads to cloud environments, the CISA exam reflects this shift by testing candidates' understanding of cloud-specific risks, controls, and governance considerations.

Cloud computing introduces a fundamentally different security model compared to traditional on-premises environments. The most important concept for CISA candidates to understand is the shared responsibility model, which defines the division of security responsibilities between the cloud service provider (CSP) and the cloud customer. Misunderstanding this model is a common source of security gaps.

For IS auditors, cloud security presents unique challenges: limited visibility into provider operations, data stored in jurisdictions with different legal requirements, multi-tenant environments where resources are shared, and reliance on third-party controls that may be difficult to audit directly. Frameworks such as CSA Cloud Controls Matrix (CCM), ISO 27017 (cloud security), and NIST SP 800-144 provide guidance for addressing these challenges.

Key Concepts and Terminology

Cloud Service Models

  • Infrastructure as a Service (IaaS): The CSP provides virtualized computing resources (servers, storage, networking). The customer manages the operating system, applications, and data. Examples include Amazon EC2 and Microsoft Azure Virtual Machines. The customer has the most control and the most responsibility.
  • Platform as a Service (PaaS): The CSP provides the platform (operating system, runtime environment, development tools) on which the customer builds and deploys applications. The customer manages the application code and data. Examples include Google App Engine and Azure App Service.
  • Software as a Service (SaaS): The CSP provides complete applications delivered over the internet. The customer manages only their data and user access. Examples include Microsoft 365, Salesforce, and Google Workspace. The customer has the least control and the least operational responsibility.

Cloud Deployment Models

  • Public Cloud: Resources are owned and operated by the CSP and shared among multiple customers (tenants). Offers scalability and cost efficiency but requires trust in the provider's security controls.
  • Private Cloud: Resources are dedicated to a single organization, either hosted on-premises or by a provider. Offers greater control and customization but at higher cost.
  • Hybrid Cloud: Combines public and private cloud resources, with data and applications able to move between them. Requires careful management of data classification and security policies across environments.
  • Community Cloud: Shared by several organizations with common concerns (such as regulatory requirements or mission objectives). Costs are shared among the community members.

Shared Responsibility Model

The shared responsibility model is the cornerstone of cloud security governance. In IaaS, the customer is responsible for securing the operating system, applications, data, and network configurations. In PaaS, the CSP takes on more responsibility for the platform layer. In SaaS, the CSP is responsible for nearly everything except user access management and data classification. Regardless of the service model, the customer is always responsible for their own data and access management.

Key Cloud Security Risks

  • Data Breaches: Unauthorized access to data stored in cloud environments, potentially amplified by multi-tenant architectures.
  • Misconfigurations: Improperly configured cloud services (such as publicly accessible storage buckets or overly permissive access policies) are among the most common causes of cloud security incidents.
  • Vendor Lock-In: Difficulty migrating data and applications from one CSP to another due to proprietary technologies and formats.
  • Data Sovereignty and Residency: Legal and regulatory requirements about where data can be stored and processed. Cloud data may reside in multiple jurisdictions with differing privacy laws.
  • Insecure APIs: Cloud services are managed through APIs. Weak authentication, insufficient input validation, or inadequate logging of API calls can expose systems to attack.
  • Loss of Control: The customer relinquishes direct control over the physical infrastructure, making it essential to verify provider controls through audits, certifications, and SOC reports.

Cloud Security Controls

  • Identity and Access Management: Implementing strong authentication (including MFA), role-based access control, and regular access reviews for cloud resources.
  • Data Encryption: Encrypting data at rest and in transit. Understanding who manages the encryption keys (the customer or the provider) is a critical audit consideration.
  • Logging and Monitoring: Enabling comprehensive logging of cloud resource activity and integrating cloud logs with the organization's SIEM for centralized monitoring.
  • Configuration Management: Using automated tools to detect and remediate misconfigurations in cloud environments. Cloud security posture management (CSPM) tools are designed for this purpose.

How This Appears on the CISA Exam

Cloud security questions on the CISA exam commonly focus on:

  • Understanding the shared responsibility model and correctly assigning security responsibilities based on the service model (IaaS, PaaS, SaaS).
  • Identifying cloud-specific risks such as data sovereignty, multi-tenancy, and vendor lock-in.
  • Evaluating what controls the customer can implement versus what must be verified through the provider's certifications or SOC reports.
  • Recognizing the importance of contract provisions (right-to-audit, data location, breach notification) in cloud agreements.
  • Understanding cloud deployment models and their respective risk profiles.

Study Tips

  • Master the shared responsibility model; know exactly what the customer is responsible for in each service model.
  • Remember that the customer is always responsible for data classification and user access management, regardless of service model.
  • Understand the differences between IaaS, PaaS, and SaaS from both a technical and a security responsibility perspective.
  • Review common cloud misconfigurations and their potential consequences.
  • Know how SOC 2 reports and the CSA STAR program help organizations evaluate cloud provider security.

Related Subtopics

  • Cloud compliance and regulatory considerations
  • Container and serverless security
  • Cloud access security brokers (CASBs)
  • Data loss prevention in cloud environments
  • Vendor management for cloud service providers
  • Cloud migration security planning

Ready to Test Your Knowledge?

Practice exam questions on Cloud Security and other Protection of Information Assets topics.

Start Practicing Free