CyberzSOC

Publication detail
← Back to advisories & guidance

CSI: Uphold the Cloud Shared Responsibility Model ↗ source

March 7, 2024 NSA Guidance

Summary

The threat landscape of the cloud differs from that of a traditional on-premises environment. An increasing reliance on the cloud brings new complexities and security challenges, and as a result, adversaries are increasingly targeting these environments. Customers often incorrectly assume that the cloud service provider (CSP) manages important aspects of safeguarding resources in the cloud that are not the CSP’s responsibility. CSPs provide highly automated, software-defined, and application programming interface (API)-driven platforms that “do what they’re told” by customers without any human oversight on the CSP side. Misconfiguration and lack of security controls are significant risks in cloud environments. Both the customer and the CSP are accountable for securing cloud environments.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.