Data security and risk management in cloud span the shared responsibility model, encryption in transit and at rest, IAM, key management, and regulatory compliance.
6.3 Cloud Data Security and Risk Management
The shared responsibility model
Encryption everywhere
Layer
Standard
In transit
TLS 1.2+ between every hop
At rest
AES-256 on disks; provider or customer keys
In use
Confidential computing (SGX, SEV)
Field-level
Tokenisation for PII
IAM patterns
Practice
Why
Least privilege everywhere
Limit blast radius
No long-lived credentials
Use OIDC federation, IAM roles
MFA for humans
Reduce credential theft impact
Workload identity for services
Eliminate service-account secrets
JIT elevation
Time-bound privileged access
Quarterly access review
Catch drift
Compliance frameworks to map
Framework
Scope
ISO 27001
General security controls
SOC 2 Type II
Annual operating report
PCI DSS
Payment cards
HIPAA
US health data
RA 10173
Philippine Data Privacy Act
BSP circulars
Philippine banking sector
Mentor’s tip: Shared responsibility means most breaches are customer misconfigurations. Encrypt everywhere, kill long-lived credentials, classify data once and apply controls across every workload. Treat compliance as a side-effect of doing security well.
Discussion
Loading…