Sekit CSF · Familia
Cloud Security
24 controles en 8 temas, cada uno visto a través de las lentes de política, proceso y técnica.
Política
RCF-0334Cloud IAMsin mapeos aúnAccess to cloud environments is formally governed by policies defining who can access what and under what conditionsRCF-0343Cloud loggingsin mapeos aúnThe company formally requires that all significant cloud activity is logged and retainedRCF-0337CSPM posturesin mapeos aúnThe company formally requires continuous assessment of cloud environment configurations against security standardsRCF-0340KMS & HSMsin mapeos aúnThe company formally governs how encryption keys are created, stored, rotated and retiredRCF-0349Multi-tenancy controlssin mapeos aúnThe company formally addresses the risk of data leakage between tenants in shared cloud environmentsRCF-0352SaaS security configurationsin mapeos aúnSecurity configuration requirements for all software-as-a-service applications are formally definedRCF-0331Shared responsibility modelsin mapeos aúnSecurity responsibilities between the company and its cloud providers are formally understood and documentedRCF-0346Workload protectionsin mapeos aúnSecurity standards for protecting workloads running in cloud environments are formally defined
Proceso
RCF-0335Cloud IAMsin mapeos aúnCloud access rights are consistently reviewed and aligned with the principle of least privilegeRCF-0344Cloud loggingsin mapeos aúnCloud audit logs are consistently enabled across all accounts and services and reviewed regularlyRCF-0338CSPM posturesin mapeos aúnCloud security posture is consistently monitored and misconfigurations are remediated within agreed timelinesRCF-0341KMS & HSMsin mapeos aúnEncryption key management procedures are consistently followed and key material is never exposed in plain textRCF-0350Multi-tenancy controlssin mapeos aúnMulti-tenant boundaries are consistently verified and configurations that could enable cross-tenant access are avoidedRCF-0353SaaS security configurationsin mapeos aúnSaaS applications are consistently configured to meet security standards and reviewed when settings changeRCF-0332Shared responsibility modelsin mapeos aúnTeams consistently apply the correct security controls for their side of the cloud shared responsibility modelRCF-0347Workload protectionsin mapeos aúnCloud workloads are consistently assessed against security standards and anomalies are investigated
Técnica
RCF-0336Cloud IAMsin mapeos aúnTechnical controls enforce identity-based access policies across all cloud environments and servicesRCF-0345Cloud loggingsin mapeos aúnTechnical controls ensure cloud activity logs are centralised, tamper-proof and available for investigationRCF-0339CSPM posturesin mapeos aúnCloud security posture management tools continuously scan for and alert on misconfigured cloud resourcesRCF-0342KMS & HSMsin mapeos aúnTechnical key management systems and hardware security modules protect cryptographic material at rest and in useRCF-0351Multi-tenancy controlssin mapeos aúnTechnical controls enforce strict tenant isolation to prevent unauthorised access to other customers' dataRCF-0354SaaS security configurationsin mapeos aúnTechnical tools assess SaaS application configurations and alert on deviations from security baselinesRCF-0333Shared responsibility modelsin mapeos aúnTechnical controls fill the security gaps that fall on the company's side of the cloud shared responsibility boundaryRCF-0348Workload protectionsin mapeos aúnTechnical tools monitor cloud workloads for threats and enforce security policies at the workload level
Pregúntale a Sekura: «¿Qué evidencia demuestra Cloud Security?»
Conecta tu IA · MCP gratis
https://staging.sekit.ai/api/mcp/crosswalk- En Claude o ChatGPT, añade un conector personalizado y pega esta URL.
- Inicia sesión con tu correo para terminar. Gratis, de solo lectura, sin necesidad de organización.