Cloud security encompasses a set of procedures, policies and technologies that harden cloud computing environments against potential cyber security threats. The main purpose of cloud security is to protect the confidentiality, integrity and accessibility of information stored, processed and transferred in cloud computing environments. At the same time, cloud security is seen as a shared responsibility between the cloud provider and the customer.
Cloud providers offer a range of security services to protect cloud environments. These services can be listed as follows:
1. Infrastructure security:
- Security services used to protect cloud infrastructure, physical and virtual resources.
2. Data security:
- Security services used to protect data stored, processed and transferred in cloud environments.
3. Application security:
- Security services used to protect applications running in cloud environments.
4. Identity and access management:
- Security services used to provide access control to cloud environments.
5. Security monitoring and incident response:
- Security services used in the detection, analysis and response to security incidents occurring in cloud environments.
Cloud customers are also responsible for taking their own cloud security measures. These measures can be listed as follows:
Risk assessment: It is an assessment to identify the security risks of cloud environments and to take necessary measures against these risks.
- Asset management:It is a process for identifying, classifying, protecting and determining the necessary controls for information assets in cloud environments.
- Cloud security is critical to protect corporate information assets. Cloud customers should work with their cloud providers to take the necessary measures to protect their cloud environments against potential cyber security threats. As HAVELSAN, we design and implement cloud security architecture for cloud providers and cloud customers in accordance with international standards such as CSA CCM, ISO 27001, ISO 27017 and ISO 27018.