<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <copyright>Copyright TechTarget - All rights reserved</copyright>
        <description></description>
        <docs>https://cyber.law.harvard.edu/rss/rss.html</docs>
        <generator>Techtarget Feed Generator</generator>
        <language>en</language>
        <lastBuildDate>Sun, 06 Sep 2026 13:13:18 GMT</lastBuildDate>
        <link>https://searchcloudsecurity.techtarget.com</link>
        <managingEditor>editor@techtarget.com</managingEditor>
        <item>
            <body>&lt;p&gt;The RSAC 2026 Conference theme was "The Power of Community." In a tech landscape where the letters A and I are inescapable, this year's RSAC homed in on the importance of people in cybersecurity -- namely, their ability to forge relationships, collaborate strategically and create a unified front to protect an ever-expanding attack surface from a barrage of threats, vulnerabilities and attacks.&lt;/p&gt; 
&lt;p&gt;What better place for CISOs and security professionals to gather as a community than at the world's premier cybersecurity conference, along with 44,000 of their peers?&lt;/p&gt; 
&lt;p&gt;Now in its 35th year, RSAC was held March 23-26, 2026, at the Moscone Center in San Francisco. With 700-plus vendors, 500-plus sessions across 25-plus tracks, and more than 600 exhibitors and vendors on the RSAC Expo Floor, RSAC 2026 was the place for security pros to coordinate efforts, share information and learn from one another.&lt;/p&gt; 
&lt;p&gt;Informa TechTarget's editorial team was on-site, reporting from the conference floor. This guide gathers articles from SearchSecurity, Dark Reading and Cybersecurity Dive on the cybersecurity industry's biggest show.&lt;/p&gt;</body>
            <description>Check out SearchSecurity's RSAC 2026 guide for reports on notable presentations and breaking news at the world's biggest infosec event.</description>
            <link>https://www.techtarget.com/cybersecurity/conference/RSAC-2026-Conference-Key-news-and-industry-analysis</link>
            <pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate>
            <title>RSAC 2026 Conference: Key news and industry analysis</title>
        </item>
        <item>
            <body>&lt;p&gt;An incident response plan, sometimes called an &lt;i&gt;incident management plan&lt;/i&gt; or &lt;i&gt;emergency management plan&lt;/i&gt;,&lt;i&gt; &lt;/i&gt;is a set of instructions to detect, respond to and limit the effects of an &lt;a href="https://www.techtarget.com/searchsecurity/feature/10-types-of-security-incidents-and-how-to-handle-them"&gt;information security event&lt;/a&gt;. It provides clear guidelines for a variety of cyberattacks, such as data breaches, DDoS attacks, firewall breaches, ransomware and malware, &lt;a href="https://www.techtarget.com/searchsecurity/definition/insider-threat"&gt;insider threats&lt;/a&gt;, data loss and other disruptive security incidents.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Why is having an incident response plan important?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Why is having an incident response plan important?&lt;/h2&gt;
 &lt;p&gt;Incident response plans help mitigate the effects of security events and, therefore, limit operational, financial and reputational damage. They lay out incident definitions, escalation requirements, personnel responsibilities, key steps to follow and people to contact in the event of an incident. They are typically based on established cybersecurity policies and &lt;a href="https://www.techtarget.com/searchsecurity/tip/Incident-response-frameworks-for-enterprise-security-teams"&gt;incident response frameworks&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;An incident response plan establishes the recommended actions and procedures needed to do the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Ensure systems and services are in place to identify and respond to cyberthreats as they occur.&lt;/li&gt; 
  &lt;li&gt;Describe the various cybersecurity tools in use and how they prevent cyberattacks.&lt;/li&gt; 
  &lt;li&gt;Recognize and respond to a cyberincident.&lt;/li&gt; 
  &lt;li&gt;Assess an incident quickly and effectively.&lt;/li&gt; 
  &lt;li&gt;Isolate malware so that it can be analyzed and prevented from doing further damage.&lt;/li&gt; 
  &lt;li&gt;Notify the appropriate individuals and organizations of the incident.&lt;/li&gt; 
  &lt;li&gt;Organize and launch the company's response.&lt;/li&gt; 
  &lt;li&gt;Escalate the company's response efforts based on the severity of the incident.&lt;/li&gt; 
  &lt;li&gt;Support business recovery in the aftermath of the incident.&lt;/li&gt; 
  &lt;li&gt;Facilitate post-event activities to determine and report on how well the company responded to the attack and if the technology used was sufficient.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;Download now: Incident response plan template&lt;/h3&gt; 
   &lt;p&gt;Informa TechTarget's free, &lt;a target="_blank" href="https://www.techtarget.com/searchdisasterrecovery/pro/Incident-Response-Plan-Template?Offer=Content_OTHR-Edit_OTHR-Template_11/24/2020_IRPlanTemplate" rel="noopener"&gt;editable incident response plan template&lt;/a&gt; can help organizations develop a customized approach to detect and respond to security incidents.&lt;/p&gt;
  &lt;/div&gt;
 &lt;/div&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="Incident response steps"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Incident response steps&lt;/h2&gt;
 &lt;p&gt;Organizations don't need to develop their incident response plans from scratch. Several &lt;a href="https://www.techtarget.com/searchsecurity/tip/Incident-response-frameworks-for-enterprise-security-teams"&gt;incident response frameworks&lt;/a&gt; have been developed by thought leaders in the field.&lt;/p&gt;
 &lt;p&gt;The NIST "Computer Security Incident Handling Guide" is widely considered to be the authoritative source for incident response planning efforts. It outlines the following four-step incident response cycle:&lt;/p&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;Preparation.&lt;/li&gt; 
  &lt;li&gt;Detection and analysis.&lt;/li&gt; 
  &lt;li&gt;Containment, eradication and recovery.&lt;/li&gt; 
  &lt;li&gt;Post-incident activity.&lt;/li&gt; 
 &lt;/ol&gt;
 &lt;p&gt;The SANS Institute's "Incident Management 101" guide suggests the following six steps:&lt;/p&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;Preparation.&lt;/li&gt; 
  &lt;li&gt;Identification.&lt;/li&gt; 
  &lt;li&gt;Containment.&lt;/li&gt; 
  &lt;li&gt;Eradication.&lt;/li&gt; 
  &lt;li&gt;Recovery.&lt;/li&gt; 
  &lt;li&gt;Lessons learned.&lt;/li&gt; 
 &lt;/ol&gt;
 &lt;p&gt;Working within these and other frameworks can help organizations create policies and procedures that guide their incident response actions.&lt;/p&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="How to create an incident response plan"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;How to create an incident response plan&lt;/h2&gt;
 &lt;p&gt;A well-designed incident response plan can be the crucial differentiator that enables an organization to quickly contain the damage from an incident and rapidly recover normal business operations.&lt;/p&gt;
 &lt;p&gt;As a starting point, review documents that provide guidance and structure for creating an incident response plan. These could include ISO/IEC 27035:2023 and ISO/IEC 22320:2018, NIST Special Publication 800-61, Rev. 3 and NIST Cybersecurity Framework 2.0, SANS Incident Response Framework and CERT Incident Management Capability. Cybersecurity vendors might also offer their own incident response frameworks.&lt;/p&gt;
 &lt;p&gt;Once the initial data gathering and review have been completed, prepare the incident response plan using the following steps.&lt;/p&gt;
 &lt;h3&gt;Step 1. Create a policy&lt;/h3&gt;
 &lt;p&gt;Develop or update an incident remediation and response policy. This foundational document serves as the basis for all incident handling activities and provides incident responders with the authority needed to make crucial decisions. The policy should be approved by senior executives and outline high-level priorities for &lt;a href="https://www.techtarget.com/searchsecurity/definition/incident-response"&gt;incident response&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;Designate a senior leader as the primary authority with responsibility for incident handling. This person might delegate some or all authority to others involved in the incident handling process, but the policy should clearly designate a specific position as having primary responsibility for incident response.&lt;/p&gt;
 &lt;p&gt;When creating a policy, keep the language high-level and general. The policy should serve as a guiding force for incident response but not dive into granular details -- procedures and playbooks fill out those details. The objective is to develop a long-lasting policy.&lt;/p&gt;
 &lt;h3&gt;Step 2. Form an incident response team and define responsibilities&lt;/h3&gt;
 &lt;p&gt;While a single leader should bear primary responsibility for the incident response process, this person leads a &lt;a href="https://www.techtarget.com/searchsecurity/feature/How-to-become-an-incident-responder-Requirements-and-more"&gt;team of experts who carry out the many tasks&lt;/a&gt; required to effectively handle a security incident. The &lt;a href="https://www.techtarget.com/searchsecurity/feature/How-to-build-an-incident-response-team-for-your-organization"&gt;size and structure of an organization's incident response team&lt;/a&gt; vary based on the nature of the organization and the number of incidents. A large global company, for example, could have different incident response teams that handle specific geographic areas using dedicated personnel. A smaller organization, on the other hand, might use a single centralized team that draws on members from elsewhere in the organization on a part-time basis. Other organizations might choose to outsource some or all of their incident response efforts. A business with a security operations center (SOC) should train all team members in incident response activities.&lt;/p&gt;
 &lt;p&gt;Whatever team model is chosen, train team members on their responsibilities at the various stages of incident handling and conduct regular exercises to ensure they are ready to respond to future incidents.&lt;/p&gt;
 &lt;p&gt;An incident response plan typically requires the formation of a computer security incident response team (&lt;a href="https://www.techtarget.com/whatis/definition/Computer-Security-Incident-Response-Team-CSIRT"&gt;CSIRT&lt;/a&gt;), which is responsible for maintaining the plan. CSIRT members must be knowledgeable about the plan and ensure it is regularly tested and approved by senior management. Response teams should include technical staff with platform and application expertise, as well as infrastructure and networking experts, systems administrators and people with a range of security expertise.&lt;/p&gt;
 &lt;p&gt;On the management side, the team should include an incident coordinator who is adept at selecting team members with different perspectives, agendas and objectives to work toward common goals. Task a team member with handling communication to and from management. This role requires someone skilled at translating technical issues into business terms and vice versa.&lt;/p&gt;
 &lt;p&gt;Data owners and business process managers throughout the organization should be part of the CSIRT or work closely with it. They will provide essential business-related input into the incident response plan. Representatives from customer-facing parts of the business, such as sales and customer service, should also be part of the CSIRT. Depending on the company's regulatory and compliance obligations, legal and PR teams should also be included.&lt;/p&gt;
 &lt;h3&gt;Step 3. Develop playbooks&lt;/h3&gt;
 &lt;p&gt;Playbooks are the lifeblood of a mature incident response team. While every security incident differs, most types of incidents follow standard patterns of activity and can benefit from standardized responses. For example, when an employee's company-owned phone is stolen, an organization can follow these standard steps:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Issue a remote wipe command to the device.&lt;/li&gt; 
  &lt;li&gt;Verify the device was encrypted.&lt;/li&gt; 
  &lt;li&gt;File a stolen device report with law enforcement and the service provider.&lt;/li&gt; 
  &lt;li&gt;Issue the employee a replacement device.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;This sequence of steps forms a basic procedure template for responding to a lost or stolen device -- a playbook for handling device theft. The incident response team, therefore, does not need to figure out what steps to take every time a device is lost or stolen. It can simply refer to the playbook.&lt;/p&gt;
 &lt;p&gt;As organizations build out their incident response teams, they should develop a series of &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-create-an-incident-response-playbook"&gt;playbooks to address their most common incident types&lt;/a&gt;.&lt;/p&gt;
 &lt;figure class="main-article-image full-col" data-img-fullsize="https://searchcloudsecurity.techtarget.com/rms/onlineImages/disaster_recovery-incident_response.jpg"&gt;
  &lt;img data-src="https://searchcloudsecurity.techtarget.com/rms/onlineImages/disaster_recovery-incident_response_mobile.jpg" class="lazy" data-srcset="https://searchcloudsecurity.techtarget.com/rms/onlineImages/disaster_recovery-incident_response_mobile.jpg 960w,https://searchcloudsecurity.techtarget.com/rms/onlineImages/disaster_recovery-incident_response.jpg 1280w" alt="Graphic of a typical timeline from a security incident to business continuity" height="224" width="560"&gt;
  &lt;figcaption&gt;
   &lt;i class="icon pictures" data-icon="z"&gt;&lt;/i&gt;A security incident might need to be elevated from incident management to emergency management or disaster recovery.
  &lt;/figcaption&gt;
  &lt;div class="main-article-image-enlarge"&gt;
   &lt;i class="icon" data-icon="w"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/figure&gt;
 &lt;h3&gt;Step 4. Create a communication plan&lt;/h3&gt;
 &lt;p&gt;Incident response efforts involve significant communication among different groups within an organization and with external stakeholders. An &lt;a href="https://www.techtarget.com/searchsecurity/tip/Incident-response-How-to-implement-a-communication-plan"&gt;incident response communication plan&lt;/a&gt; should outline how these groups work together during an active incident and the types of information they should produce and share with internal and external responders.&lt;/p&gt;
 &lt;p&gt;The communication plan must also address law enforcement involvement. It should outline who in the organization is authorized to call in law enforcement and when it is appropriate to do so. Involving law enforcement can generate adverse publicity, so organizations should make this decision deliberately.&lt;/p&gt;
 &lt;h3&gt;Step 5. Test the plan&lt;/h3&gt;
 &lt;p&gt;&lt;a href="https://www.techtarget.com/searchsecurity/tip/CISOs-guide-How-to-test-an-incident-response-plan%20"&gt;Testing the processes&lt;/a&gt; outlined in an incident response plan is important. Don't wait until an incident to find out if the plan works. Run simulations to ensure teams are up to date on the plan and understand their roles and responsibilities in response processes. Testing should include a &lt;a href="https://www.techtarget.com/searchsecurity/feature/Top-10-types-of-information-security-threats-for-IT-teams"&gt;variety of threat scenarios&lt;/a&gt;, including ransomware, DDoS attacks, insider data theft and system misconfigurations.&lt;/p&gt;
 &lt;p&gt;One frequently used testing approach is discussion-based&amp;nbsp;&lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-conduct-incident-response-tabletop-exercises"&gt;incident response tabletop exercises&lt;/a&gt;. During an exercise, teams talk through the procedures they would apply and issues that might arise during a specific security event. A more in-depth testing approach involves hands-on operational exercises that put functional processes and procedures in the incident response plan through their paces. A combination of these two testing approaches is recommended.&lt;/p&gt;
 &lt;h3&gt;Step 6. Identify lessons learned&lt;/h3&gt;
 &lt;p&gt;Each incident that occurs is a learning opportunity. Incident response plans should require a formal lessons-learned session at the end of every test and real-world security incident. These sessions should include all team members who played a role in the response and provide an opportunity to identify security control gaps that contributed to the incident, as well as places where the incident response plan should be adjusted. This enables an organization to reduce the likelihood of future incidents and improve its ability to handle incidents that do occur.&lt;/p&gt;
 &lt;h3&gt;Step 7. Keep testing and updating the plan&lt;/h3&gt;
 &lt;p&gt;After creating the plan, conduct testing regularly as processes and threats evolve. Reassess and validate incident response plans annually, at a minimum. Revise plans whenever changes occur to the company's IT infrastructure or its business, regulatory or compliance structure. Establish a continuous improvement process for incident response.&lt;/p&gt;
&lt;/section&gt;                              
&lt;section class="section main-article-chapter" data-menu-title="What are the benefits of having an incident response plan?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What are the benefits of having an incident response plan?&lt;/h2&gt;
 &lt;p&gt;Benefits of a well-crafted and regularly reviewed and tested incident response plan include the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Faster incident response.&lt;/b&gt; A formal plan ensures an organization uses its risk assessment and response activities to spot early signs of an incident or attack. It also helps organizations follow proper protocols to contain and recover from the event.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Early threat mitigation.&lt;/b&gt; A well-organized&amp;nbsp;&lt;a href="https://www.techtarget.com/searchsecurity/definition/incident-response-team"&gt;incident response team&lt;/a&gt;&amp;nbsp;with a detailed plan can mitigate the potential effects of unplanned events. An incident response plan can speed up forensic analyses, such as penetration testing and threat hunting, minimizing the duration of a security event and shortening recovery time.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Disaster recovery (DR) plan launch prevention.&lt;/b&gt; Quick incident handling could save an organization from invoking more complex and costly business continuity (BC) and DR plans.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Strong BC and resilience.&lt;/b&gt; Organizations such as the Business Continuity Institute and Disaster Recovery Institute International include incident response planning as a key part of the &lt;a href="https://www.techtarget.com/searchdisasterrecovery/feature/Using-a-business-continuity-plan-template-A-free-business-continuity-template-and-guide"&gt;overall BC management process&lt;/a&gt;. It is also essential as organizations &lt;a href="https://www.techtarget.com/searchsecurity/tip/CISOs-guide-to-demonstrating-cyber-resilience"&gt;improve their resilience&lt;/a&gt; from unplanned events.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Better communication for faster action.&lt;/b&gt; Situations exist where the severity of an incident exceeds the capabilities of an incident response team. In these scenarios, incident response teams relay the information they have to emergency management teams and first responder organizations to try and resolve the incident.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Regulatory compliance.&lt;/b&gt; Many regulatory and certification bodies require organizations to have an incident response plan. To remain compliant with certain regulations, such as PCI DSS and ISO/IEC 27001, having an incident response plan is critical.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Incident response plan examples and templates"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Incident response plan examples and templates&lt;/h2&gt;
 &lt;p&gt;An incident response plan template can help organizations outline clear instructions to detect, respond to and limit the effects of security incidents.&lt;/p&gt;
 &lt;p&gt;&lt;a href="https://www.techtarget.com/searchdisasterrecovery/pro/Incident-Response-Plan-Template?Offer=Content_OTHR-Edit_OTHR-Template_11/24/2020_IRPlanTemplate"&gt;Click to download our free, editable incident response plan template&lt;/a&gt;. It is a useful starting point for developing a plan customized to your company's needs. Review it with internal departments, including facilities management, legal, risk management, HR and key operational units. If possible, have local first responder organizations review the plan. Their suggestions could prove valuable and increase the plan's success if implemented.&lt;/p&gt;
 &lt;p&gt;For further assistance, review the following incident response plan examples:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;National Cyber Incident Response Plan from the &lt;a target="_blank" href="https://www.cisa.gov/uscert/sites/default/files/ncirp/National_Cyber_Incident_Response_Plan.pdf" rel="noopener"&gt;U.S. Department of Homeland Security&lt;/a&gt;. CISA released a &lt;a target="_blank" href="https://www.cisa.gov/sites/default/files/2025-01/NCIRP%20Update%20Public%20Comment%20Draft%20508c__0.pdf" rel="noopener"&gt;draft&lt;/a&gt; of its updated plan in 2024.&lt;/li&gt; 
  &lt;li&gt;Incident Response Plan for Agricultural Chemicals from the &lt;a target="_blank" href="https://www.mda.state.mn.us/sites/default/files/2018-06/Incident%20Response%20Plan%20Template.pdf" rel="noopener"&gt;Minnesota Department of Agriculture&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;Emergency Response and Crisis Management Plan from &lt;a target="_blank" href="https://www.bennett.edu/wp-content/uploads/2019/09/emergency_response_plan_2019_v1.pdf" rel="noopener"&gt;Bennett College&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;Computer Security Incident Response Plan from &lt;a target="_blank" href="https://www.cmu.edu/iso/governance/procedures/incidentresponseplanv1.6.pdf" rel="noopener"&gt;Carnegie Mellon University&lt;/a&gt;.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Editor's note:&lt;i&gt; This article was updated in February 2026 to improve the reader experience.&lt;/i&gt;&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Paul Kirvan is an independent consultant, IT auditor and technical writer. He has more than 35 years of experience in business continuity, disaster recovery, resilience, security, enterprise risk management, networking and IT auditing.&lt;/i&gt;&lt;/p&gt;
 &lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Threats from cyberattacks continue to grow in frequency and severity. Considering the potential disruptions from such events, an organization needs an incident response plan.</description>
            <image>https://cdn.ttgtmedia.com/visuals/searchSAP/ERP_management/sap_article_011.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/feature/How-to-build-an-incident-response-plan-with-examples-template</link>
            <pubDate>Fri, 20 Feb 2026 11:00:00 GMT</pubDate>
            <title>How to build an incident response plan, with examples, template</title>
        </item>
        <item>
            <body>&lt;p&gt;Incident response plans enable organizations to quickly and efficiently handle cyberattacks. The lack of such a plan increases the likelihood that an attack will cause significant operational damage to IT systems, networks and data.&lt;/p&gt; 
&lt;p&gt;When developing an effective incident response strategy, a framework is essential. Industry frameworks can help an organization formulate an effective incident response initiative or update its existing initiatives.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="What are frameworks and why are they important?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What are frameworks and why are they important?&lt;/h2&gt;
 &lt;p&gt;An incident response framework is the foundation for building an incident response program. An ideal framework provides structure and guidance for addressing all incident response activities.&lt;/p&gt;
 &lt;p&gt;For existing incident response programs, frameworks can ensure teams address relevant issues, such as staffing, administration, response playbooks, awareness and training, testing and resource identification.&lt;/p&gt;
 &lt;p&gt;CISOs and cybersecurity teams responsible for developing a new incident plan and associated activities will quickly recognize the benefits of using a framework, especially when ensuring all the right boxes are checked.&lt;/p&gt;
 &lt;p&gt;Properly used, a framework can be adapted into a variety of formal documents, including incident response programs, policies and individual plans. Organizations required to demonstrate compliance with both domestic and international standards and regulations should use specific frameworks when developing incident response programs and plans. From legal, operational and audit perspectives, using frameworks helps demonstrate compliance with these important requirements.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="Key elements of an IR framework"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Key elements of an IR framework&lt;/h2&gt;
 &lt;p&gt;Regardless of its source, an incident framework should include at least five specific components. Each standard and framework has its own nomenclature for these components, which generally follows the five-Rs structure.&lt;/p&gt;
 &lt;h3&gt;Research&lt;/h3&gt;
 &lt;p&gt;Before a cyberattack occurs, security teams should carefully examine all elements of the organization's IT infrastructure. A risk analysis determines which elements of the business are &lt;a href="https://www.techtarget.com/searchsecurity/feature/How-to-fix-the-top-5-cybersecurity-vulnerabilities"&gt;most susceptible to attack&lt;/a&gt;, the &lt;a href="https://www.techtarget.com/searchsecurity/feature/10-types-of-security-incidents-and-how-to-handle-them"&gt;types of security events&lt;/a&gt; most likely to occur and the effects those events would have on the business.&lt;/p&gt;
 &lt;p&gt;The research phase includes a review of measures to prepare for and respond to an actual attack. These include preparing policies and plans, deploying cybersecurity systems and software, training &lt;a href="https://www.techtarget.com/searchsecurity/definition/incident-response-team"&gt;incident response teams&lt;/a&gt;, performing threat hunting and penetration testing, patching software and testing cybersecurity plans.&lt;/p&gt;
 &lt;h3&gt;Recognition&lt;/h3&gt;
 &lt;p&gt;This stage occurs when an incident is identified. It could be an alert from an intrusion prevention or detection system, a firewall or an antimalware program, among others. Once an alert has sounded, the next stage is launched.&lt;/p&gt;
 &lt;h3&gt;Response&lt;/h3&gt;
 &lt;p&gt;In this stage,&lt;b&gt; &lt;/b&gt;cybersecurity teams identify the nature and source of the threat, isolate it, analyze its potential impacts and decide the most appropriate response.&lt;/p&gt;
 &lt;h3&gt;Resolution&lt;/h3&gt;
 &lt;p&gt;In this stage, &lt;a href="https://www.techtarget.com/searchsecurity/feature/How-to-become-an-incident-responder-Requirements-and-more"&gt;incident responders&lt;/a&gt; eliminate the threat or mitigate its severity so it no longer disrupts business operations. This is especially important in &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-recover-from-a-ransomware-attack"&gt;ransomware incident response&lt;/a&gt;, where a rapid resolution might save the organization thousands or even millions of dollars in costs associated with recovering compromised systems, networks, files and databases.&lt;/p&gt;
 &lt;h3&gt;Recap&lt;/h3&gt;
 &lt;p&gt;Once the event has been resolved, it is essential to document how the incident response team handled the event from initial awareness to final resolution. Assessing what worked and what did not enables teams to identify areas for improvement in the incident process and to refine the incident response framework and incident response plan.&lt;/p&gt;
&lt;/section&gt;             
&lt;section class="section main-article-chapter" data-menu-title="Incident response standards and frameworks"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Incident response standards and frameworks&lt;/h2&gt;
 &lt;p&gt;There are several well-known incident response standards and frameworks. Some have their roots in government service, while others were developed for the private sector. Each approach can help develop an incident framework for enterprise cybersecurity requirements.&lt;/p&gt;
 &lt;h3&gt;ISO/IEC 27035 series&lt;/h3&gt;
 &lt;p&gt;The ISO/IEC 27035 series has three parts:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;a target="_blank" href="https://www.iso.org/standard/78973.html" rel="noopener"&gt;ISO/IEC 27035-1&lt;/a&gt; introduces incident management principles.&lt;/li&gt; 
  &lt;li&gt;&lt;a target="_blank" href="https://www.iso.org/standard/78974.html" rel="noopener"&gt;ISO/IEC 27035-2&lt;/a&gt; focuses on incident management preparation and planning.&lt;/li&gt; 
  &lt;li&gt;&lt;a target="_blank" href="https://www.iso.org/standard/74033.html" rel="noopener"&gt;ISO/IEC 27035-3&lt;/a&gt; describes how to respond to cybersecurity incidents.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;The series breaks the incident response process into the following five phases:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Planning and preparation.&lt;/b&gt; Establish an incident management policy and create an incident response team.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Detection and reporting.&lt;/b&gt; Set up the processes, procedures and technologies required to detect and report the incident.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Assessment and decision.&lt;/b&gt; Create processes and procedures, and establish incident descriptions and criteria.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Response to incidents.&lt;/b&gt; Establish controls to prevent, respond to and recover from incidents.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Lessons learned.&lt;/b&gt; Learn from security incidents to improve overall incident management.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Collectively, the series provides a comprehensive framework for incident response and incident management.&lt;/p&gt;
 &lt;p&gt;"&lt;a target="_blank" href="https://webstore.ansi.org/standards/iso/iso223202018" rel="noopener"&gt;ISO 22320:2018&lt;/a&gt; Security and resilience -- Emergency management -- Guidelines for incident management" closely mirrors ISO 27035. It can serve as a standalone framework or as a complement to ISO 27035.&lt;/p&gt;
 &lt;h3&gt;NIST incident response framework&lt;/h3&gt;
 &lt;p&gt;&lt;a target="_blank" href="https://csrc.nist.gov/pubs/sp/800/61/r3/final" rel="noopener"&gt;NIST Special Publication 800-61&lt;/a&gt; Rev. 3 was updated in April 2025 to reflect the modern incident response landscape and align with the NIST Cybersecurity Framework 2.0.&lt;/p&gt;
 &lt;p&gt;The updated guidance identifies the incident response lifecycle in three sections:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Preparation.&lt;/b&gt; NIST wrote that this phase is not part of incident response itself but part of the broader ongoing risk management process. It includes risk assessment and analysis, policy creation, system monitoring and the implementation of security tools and technologies.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Incident response.&lt;/b&gt; This stage involves detecting, responding to and recovering from a cybersecurity event.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Lessons learned.&lt;/b&gt; This step involves gathering feedback from all activities in all steps to identify improvements and adjust policies, processes and plans.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;h3&gt;SANS incident response framework&lt;/h3&gt;
 &lt;p&gt;SANS Institute, a private cybersecurity training, certification and research organization, published an incident response framework that has the following phases:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Preparation.&lt;/b&gt; Review and codify security policies, perform a risk assessment, identify sensitive assets, define critical security incidents and build an incident response team.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Identification.&lt;/b&gt; Monitor IT systems, detect deviations from normal operations and determine whether they represent real security incidents. If an incident is discovered, collect additional evidence, establish its type and severity, and document everything.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Containment.&lt;/b&gt; Perform short-term containment, and then focus on long-term containment, which involves temporary fixes to enable systems to be used in production while rebuilding clean systems.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Eradication.&lt;/b&gt; Remove malware from affected systems, identify the root cause of the attack and take action to prevent similar attacks.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Recovery.&lt;/b&gt; Bring affected production systems back online cautiously to prevent further attacks. Test, verify and monitor affected systems to ensure they return to normal operation.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Lessons learned.&lt;/b&gt; Compile all relevant information about the incident and identify lessons that will help with future incident response activities.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;h3&gt;CERT Incident Management Capability&lt;/h3&gt;
 &lt;p&gt;Developed by Carnegie Mellon University's Software Engineering Institute and used by the U.S. Department of Homeland Security and U.S. Computer Emergency Readiness Team, the CERT incident management assessment addresses a broad spectrum of cybersecurity event response activities. Its incident response phases include the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Prepare. &lt;/b&gt;Establish a formal incident function, set up roles and responsibilities, develop procedures for incident response, and identify tools and key relationships for managing incident responses.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Protect. &lt;/b&gt;Establish measures to identify potential risks, threats and vulnerabilities; deploy upgrades, modifications and enhancements to security infrastructure assets, including firewalls, intrusion detection systems and antivirus; and develop a patch management process.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Detect. &lt;/b&gt;Balance proactive actions, such as monitoring and analysis, with reactive actions, such as event data gathering, to determine the nature of a suspicious activity.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Respond. &lt;/b&gt;Analyze the anomaly, launch mitigation and remediation activities, initiate event notification and begin post-event follow-up to determine how well the response activities performed.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Sustain.&lt;/b&gt; Maintain effective incident response activities, including program funding, training of response teams, reviewing and updating of controls, and post-event reviews to identify ways of improving incident response procedures.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;h3&gt;Additional incident response frameworks&lt;/h3&gt;
 &lt;p&gt;Consider the following incident response guidance:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;IEEE has research, guidance and frameworks, but no formal standards.&lt;/li&gt; 
  &lt;li&gt;IETF has standards and best practices for computer security incident response teams.&lt;/li&gt; 
  &lt;li&gt;The EU Agency for Cybersecurity developed incident response frameworks that are published via guidance documents, including "Good Practice Guide for Incident Management."&lt;/li&gt; 
  &lt;li&gt;"NIST SP 800-53 Rev. 3: Security and Privacy Controls for Information Systems and Organizations" is a key information security standard that includes requirements for incident response.&lt;/li&gt; 
  &lt;li&gt;Mitre ATT&amp;amp;CK is a knowledge base of cybersecurity threat activities that can contribute to the creation of an incident response framework with guidance on incident detection, analysis and reporting.&lt;/li&gt; 
  &lt;li&gt;CISA has operational procedures and playbooks for planning and conducting cybersecurity vulnerability and incident response activities.&lt;/li&gt; 
  &lt;li&gt;CISA established the National Cyber Incident Response Plan, a public sector-focused framework providing guidance on responding to cyberattacks.&lt;/li&gt; 
  &lt;li&gt;"ISO 27001: Information security, cybersecurity and privacy protection -- Information security management systems -- Requirements" is the global standard for information security management systems and aligns with ISO 27035 for incident response activities.&lt;/li&gt; 
  &lt;li&gt;The U.S. Incident Command System presents a structured approach to incident response and management. It is designed to enable collaboration among various federal, state and local government agencies.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;                      
&lt;section class="section main-article-chapter" data-menu-title="How to create an incident response framework"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;How to create an incident response framework&lt;/h2&gt;
 &lt;p&gt;Organizations that already have an incident response framework in place should compare it to the standards and frameworks outlined above to ensure it aligns with good-practice guidance. Review and update the framework periodically to ensure it remains aligned with the standards.&lt;/p&gt;
 &lt;p&gt;When developing an in-house incident response framework, consider the following steps:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Examine existing cybersecurity documentation, including policies, procedures, plans and reports.&lt;/li&gt; 
  &lt;li&gt;Establish a project plan and team to develop the framework.&lt;/li&gt; 
  &lt;li&gt;Gather and review existing frameworks. Select the document(s) that best fits the organization's requirements.&lt;/li&gt; 
  &lt;li&gt;If the framework is part of an enterprise cybersecurity initiative that needs to demonstrate compliance with a standard or regulation, use a framework that aligns with that standard or regulation.&lt;/li&gt; 
  &lt;li&gt;Prepare an initial draft framework for review.&lt;/li&gt; 
  &lt;li&gt;Carefully review the draft framework to ensure it aligns with existing cybersecurity policies, procedures and compliance requirements.&lt;/li&gt; 
  &lt;li&gt;Secure approval from senior management.&lt;/li&gt; 
  &lt;li&gt;Disseminate the framework to members of the cybersecurity team and the security operations center team.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Once the framework has been completed and approved, formulate incident response program documents based on the framework. Review and update existing incident response activities if necessary.&lt;/p&gt;
 &lt;p&gt;In situations where a formal incident response program needs to be developed, use the framework to do the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Initiate the incident response program.&lt;/li&gt; 
  &lt;li&gt;Create incident response policies and processes.&lt;/li&gt; 
  &lt;li&gt;Identify, secure and train &lt;a href="https://www.techtarget.com/searchsecurity/feature/How-to-build-an-incident-response-team-for-your-organization"&gt;incident response team members&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;Adopt tools and resources for incident response activities.&lt;/li&gt; 
  &lt;li&gt;Deploy systems for incident identification, event logging and tracking, and event response and reporting.&lt;/li&gt; 
  &lt;li&gt;Launch activities for threat hunting, pen testing and other forensic activities.&lt;/li&gt; 
  &lt;li&gt;Regularly patch critical software.&lt;/li&gt; 
  &lt;li&gt;Schedule and conduct incident response exercises and tests.&lt;/li&gt; 
  &lt;li&gt;Include incident response activities in weekly IT staff meetings.&lt;/li&gt; 
  &lt;li&gt;Establish a continuous improvement activity for incident response.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Whether an organization develops its own homegrown framework or uses one or more of the documents mentioned here, be sure it addresses domestic and international compliance requirements.&lt;/p&gt;
 &lt;p&gt;Most current standards and frameworks share a basic structure. Carefully review them to find one that best meets the organization's incident response requirements.&lt;/p&gt;
 &lt;p&gt;Also note that while frameworks help, it is the &lt;a href="https://www.techtarget.com/searchsecurity/feature/5-critical-steps-to-creating-an-effective-incident-response-plan"&gt;approved incident response plan&lt;/a&gt; that an organization uses to protect itself from cyberattacks.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Paul Kirvan, FBCI, CISA, is an independent consultant and technical writer with more than 35 years of experience in business continuity, disaster recovery, resilience, cybersecurity, GRC, telecom and technical writing.&lt;/i&gt;&lt;/p&gt;
 &lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Frameworks provide the structure for an effective incident response program. Here's where to turn for guidance on what to include.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/check_g1205300933.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/tip/How-to-build-an-incident-response-framework</link>
            <pubDate>Thu, 12 Feb 2026 09:00:00 GMT</pubDate>
            <title>How to build an incident response framework</title>
        </item>
        <item>
            <body>&lt;p&gt;Cybersecurity teams must be mindful at all times of the current threats their organization faces. While it's impossible to thwart every threat, stopping as many as possible and quickly detecting when they occur are both critical for reducing damage.&lt;/p&gt; 
&lt;p&gt;It is important to note that many cybersecurity incidents involve multiple types of threats. In a nutshell, a&amp;nbsp;&lt;i&gt;security threat&lt;/i&gt;&amp;nbsp;is a malicious act that aims to corrupt or steal data or disrupt an organization's systems or the entire organization. A&amp;nbsp;&lt;i&gt;security event&lt;/i&gt;&amp;nbsp;refers to an occurrence during which company data or its network might have been exposed. An event that results in a data or network breach is called a&amp;nbsp;&lt;i&gt;security incident&lt;/i&gt;.&lt;/p&gt; 
&lt;p&gt;Here are 10 types of threats that cybersecurity teams should focus on.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="1. Supply chain attacks"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;1. Supply chain attacks&lt;/h2&gt;
 &lt;p&gt;Supply chain attacks are challenging to identify because they usually involve a breach or other cybersecurity compromise affecting a trusted third party, such as a supplier, partner, contractor, vendor or service provider. In this attack, the third party does not realize it has been compromised and therefore spreads the threat to its customers, partners and vendors.&lt;/p&gt;
 &lt;p&gt;For example, a vendor's software might accidentally be infected with malware during manufacturing, or bad actors might add malicious code that steals sensitive data from organizations using a service provider's offering. Another form of supply chain attack involves counterfeit products and legitimate products that have been tampered with after manufacturing and packaging.&lt;/p&gt;
 &lt;h3&gt;How to prevent supply chain attacks&lt;/h3&gt;
 &lt;p&gt;To prevent supply chain attacks, only work with trusted third-party vendors, service providers, partners and contractors. Perform &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-build-an-effective-third-party-risk-assessment-framework"&gt;third-party risk assessments&lt;/a&gt;, conduct continuous vendor monitoring and keep an accurate inventory of all third parties and their dependencies.&lt;/p&gt;
 &lt;p&gt;In addition, only purchase technology products and services from reputable manufacturers and vendors. Examine any physical technology purchases for anything suspicious, especially on product packaging or the product surface itself.&lt;/p&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="2. Distributed denial-of-service attacks"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;2. Distributed denial-of-service attacks&lt;/h2&gt;
 &lt;p&gt;&lt;a href="https://www.techtarget.com/searchsecurity/definition/distributed-denial-of-service-attack"&gt;DDoS&lt;/a&gt; attacks occur when thousands or millions of compromised devices simultaneously overwhelm a server, network or other target. The compromised devices are typically part of a botnet, enabling attackers to easily coordinate all devices in performing DDoS attacks. The goal of a DDoS attack is to disrupt the target's operations, preventing legitimate use of resources.&lt;/p&gt;
 &lt;h3&gt;How to prevent DDoS attacks&lt;/h3&gt;
 &lt;p&gt;Preventing DDoS attacks is a unique challenge. No matter how much capacity enterprise systems and networks have, a large DDoS attack can still clog them.&lt;/p&gt;
 &lt;p&gt;Options for mitigating DDoS attacks include the following:&lt;/p&gt;
 &lt;ul type="disc" class="default-list"&gt; 
  &lt;li&gt;Partner with an MSP or other third party that specializes in DDoS attack monitoring and mitigation.&lt;/li&gt; 
  &lt;li&gt;Deploy and configure network security devices in front of systems and networks to &lt;a href="https://www.techtarget.com/searchsecurity/feature/Implement-API-rate-limiting-to-reduce-attack-surfaces"&gt;enforce rate limiting&lt;/a&gt; and stop traffic from known botnets.&lt;/li&gt; 
  &lt;li&gt;Design the organization's important applications with resilience in mind, such as duplicating key resources on other networks so that a DDoS attack against one network will not completely disrupt applications.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="3. Social engineering and phishing attacks"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;3. Social engineering and phishing attacks&lt;/h2&gt;
 &lt;p&gt;Social engineering comes in many forms, from someone pretending to be a delivery person in order to access a secure area to someone sending phishing emails, texts or other forms of messaging to deceive the recipient.&lt;/p&gt;
 &lt;p&gt;The goal of phishing, the most popular form of social engineering, is to get the recipient to divulge credentials, bank information or other sensitive data, or to install malware on the recipient's device.&lt;/p&gt;
 &lt;h3&gt;How to prevent social engineering and phishing attacks&lt;/h3&gt;
 &lt;p&gt;Some social engineering and phishing attacks can be stopped only by the intended victims. This requires that individual users be trained on &lt;a href="https://www.techtarget.com/searchsecurity/feature/How-to-avoid-phishing-hooks-A-checklist-for-your-end-users"&gt;how to identify attacks&lt;/a&gt; and what to do if an attack occurs. For example, they'll need to scrutinize links and email attachments for anything suspicious.&lt;/p&gt;
 &lt;p&gt;Many phishing attacks can be stopped through automated means, such as antispam and antimalware technologies, that are frequently updated with the latest threat intelligence. Some phishing attacks exploit software vulnerabilities, so keep all devices' software patched and up to date.&lt;/p&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="4. Attacks through look-alike content"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;4. Attacks through look-alike content&lt;/h2&gt;
 &lt;p&gt;Attackers often craft websites, social media accounts, advertisements and other online content to look just like the real thing. When visited, that content &lt;a href="https://www.techtarget.com/searchsecurity/tip/10-common-types-of-malware-attacks-and-how-to-prevent-them"&gt;installs malware on users' computers&lt;/a&gt;. Known as &lt;i&gt;drive-by download attacks&lt;/i&gt;, users have no idea that anything bad has happened.&lt;/p&gt;
 &lt;h3&gt;How to prevent attacks through look-alike content&lt;/h3&gt;
 &lt;p&gt;Educate users on how to verify that URLs, social media accounts and other content are legitimate to prevent these attacks. Tell users not to click on advertisements from work devices.&lt;/p&gt;
 &lt;p&gt;To stay on top of the latest threats, consider subscribing to near-real-time &lt;a href="https://www.techtarget.com/searchsecurity/tip/Top-open-source-and-commercial-threat-intelligence-feeds"&gt;threat intelligence feeds&lt;/a&gt;. These can be consumed by an organization's cybersecurity technologies to quickly stop access to look-alike content once others detect and report it. Organizations should also keep software patched and up to date to minimize the risk of malicious content exploiting vulnerabilities.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="5. Misinformation and disinformation"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;5. Misinformation and disinformation&lt;/h2&gt;
 &lt;p&gt;Misinformation is incorrect information, while disinformation is intentional misinformation designed to trick people -- another form of social engineering. Whether information is accidentally or intentionally wrong, the effect is the same: it convinces people that false statements are true and often triggers them to act on those false statements.&lt;/p&gt;
 &lt;p&gt;Misinformation and disinformation come in many forms. AI technologies are &lt;a href="https://www.techtarget.com/searchsecurity/tip/Real-world-AI-voice-cloning-attack-A-red-teaming-case-study"&gt;now widely used to create deepfake audio and video&lt;/a&gt; that often can't be distinguished from the real thing. Websites, emails and other content might also provide false instructions to users on how to improve security or functionality on their work computers. Rumors about the organization itself could also surface inside or outside the business.&lt;/p&gt;
 &lt;h3&gt;How to prevent misinformation and disinformation&lt;/h3&gt;
 &lt;p&gt;Misinformation and disinformation are often difficult to detect through automated means. Instead, rely on regularly scheduled &lt;a href="https://www.techtarget.com/searchsecurity/definition/security-awareness-training"&gt;security awareness training&lt;/a&gt; to teach employees how to spot misinformation and disinformation. Educate them on how to verify information pertaining to both internal and external matters. Also, provide a website where members of the public can verify the legitimacy of communications they receive from the organization, and provide a mechanism for the public to report misinformation and disinformation involving the organization.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="6. Credential compromise and account takeover"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;6. Credential compromise and account takeover&lt;/h2&gt;
 &lt;p&gt;Passwords, ID badges and other credentials are obvious targets for attackers. Passwords can be acquired in many ways, including social engineering and phishing, watching someone enter a password on their phone, guessing a password -- known as &lt;i&gt;brute-force attacking&lt;/i&gt; -- or reusing a previously compromised password that the person used for multiple accounts.&lt;/p&gt;
 &lt;p&gt;Possessing a password enables an attacker, in many cases, to access and control the user account. This is known as an &lt;i&gt;account takeover&lt;/i&gt;.&lt;/p&gt;
 &lt;h3&gt;How to prevent credential compromise and account takeover&lt;/h3&gt;
 &lt;p&gt;Avoid relying only on passwords for user authentication. Requiring MFA and switching from passwords to &lt;a href="https://www.techtarget.com/searchsecurity/definition/passwordless-authentication"&gt;passwordless authentication&lt;/a&gt; are two effective alternatives. If passwords are required, teach employees &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-create-a-strong-passphrase-with-examples"&gt;how to create strong passphrases&lt;/a&gt;, which are a more secure alternative to passwords.&lt;/p&gt;
 &lt;p&gt;In addition, train users on how to safeguard their credentials and what to do if they think one of their credentials has been compromised. Another helpful measure is to use cybersecurity technologies that monitor authentication attempts. Use these tools to identify anomalies, such as the same user connecting to email from different geographic locations at the same time, which could indicate someone masquerading as the user.&lt;/p&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="7. Ransomware"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;7. Ransomware&lt;/h2&gt;
 &lt;p&gt;Ransomware uses encryption to make computers or files inaccessible or extortion to get victims to pay a ransom to get their stolen data back. While most ransomware attacks result from phishing or other forms of social engineering, some ransomware campaigns target exploitable software vulnerabilities.&lt;/p&gt;
 &lt;h3&gt;How to prevent ransomware&lt;/h3&gt;
 &lt;p&gt;Train users to avoid social engineering attacks, and teach them &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-effectively-respond-to-a-ransomware-attack"&gt;what to do if a ransomware infection occurs&lt;/a&gt;. Seconds can make a difference between a single computer being infected and an infection spreading throughout an organization.&lt;/p&gt;
 &lt;p&gt;To minimize vulnerabilities that ransomware can exploit, organizations should keep all software current with the latest patches and updates. It's also critical to use antimalware technologies that detect and stop ransomware, along with cyberthreat intelligence feeds that provide near-real-time updates on the latest ransomware threats.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="8. Persistence threats"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;8. Persistence threats&lt;/h2&gt;
 &lt;p&gt;Persistence refers to an attacker's ability to gain and then maintain access to a system without being detected. Known as &lt;i&gt;advanced persistent threats&lt;/i&gt; (&lt;a href="https://www.techtarget.com/searchsecurity/definition/advanced-persistent-threat-APT"&gt;APTs&lt;/a&gt;), attackers can persist unnoticed in compromised systems for days, weeks or months. During this time, they could access and exfiltrate sensitive data, compromise additional systems and monitor conditions until they are ready to launch a more devastating attack.&lt;/p&gt;
 &lt;h3&gt;How to prevent persistence&lt;/h3&gt;
 &lt;p&gt;Use firewalls and other network security tools, along with threat intelligence feeds, to block access to and from known malicious domains, IP addresses and websites. This denies APTs by disrupting the command-and-control channels they rely upon.&lt;/p&gt;
 &lt;p&gt;Monitor network traffic to look for signs of unauthorized access to internal systems. Use antimalware and antiphishing technologies to detect and stop attacks in transit. Also, scan the organization's devices regularly for signs of bots, exploit kits and other attack tools. Act swiftly whenever any such unauthorized tools are detected.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="9. Insider threats"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;9. Insider threats&lt;/h2&gt;
 &lt;p&gt;An insider threat is when an employee, contractor or other person within an organization misuses their technology privileges in ways that violate and harm the organization's cybersecurity. For example, an employee emailing sensitive data to external email addresses for the purposes of selling the data. A more complex example is two employees in different roles colluding to steal from the organization.&lt;/p&gt;
 &lt;h3&gt;How to prevent insider threats&lt;/h3&gt;
 &lt;p&gt;Follow the &lt;a href="https://www.techtarget.com/searchsecurity/definition/principle-of-least-privilege-POLP"&gt;principle of least privilege&lt;/a&gt; to ensure each user has the minimal access needed to do their job. Train all users, including contractors and vendors, on acceptable use policies and the potential consequences of violating them. Monitor all user activity for signs of suspicious behavior. Promptly investigate potentially malicious behavior.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="10. Accidental data leaks"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;10. Accidental data leaks&lt;/h2&gt;
 &lt;p&gt;Accidental data leaks occur when an organization's sensitive data is inadvertently made available to unauthorized parties or systems. Examples include choosing the wrong recipient for an email, uploading the wrong file to a website or shared storage, or posting data for public access that has not yet been approved for release.&lt;/p&gt;
 &lt;p&gt;Data leaks can also occur when old or broken technologies are disposed of without first sanitizing or physically destroying their data storage. Printouts are also mechanisms for data leaks.&lt;/p&gt;
 &lt;h3&gt;How to prevent accidental data leaks&lt;/h3&gt;
 &lt;p&gt;Teach users to double-check recipients, attachments and other components of emails and other messages before sending them. Use &lt;a href="https://www.techtarget.com/searchsecurity/tip/Top-7-data-loss-prevention-tools"&gt;data loss prevention technologies&lt;/a&gt; to examine outbound emails and other applications for potential signs of data leaks. Carefully control physical access to printed sensitive data so that printouts are not left unattended and are shredded when no longer needed.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Karen Kent is the co-founder of Trusted Cyber Annex. She provides cybersecurity research and publication services to organizations and was formerly a senior computer scientist for NIST.&lt;/i&gt;&lt;/p&gt;
 &lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Know thine enemy -- and the common security threats that can bring an unprepared organization to its knees. Learn what these threats are and how to prevent them.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/security_a303249453.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/feature/10-types-of-information-security-threats-for-IT-teams</link>
            <pubDate>Thu, 05 Feb 2026 09:00:00 GMT</pubDate>
            <title>10 types of information security threats for IT teams</title>
        </item>
        <item>
            <body>&lt;p&gt;Cloud containers are a hot topic, especially in security. Technology giants Microsoft, Google and Facebook all use them. Google uses containers for everything it runs, totaling several billion each week.&lt;/p&gt; 
&lt;p&gt;The past decade has seen containers anchoring a growing number of production environments. This shift reflects the modularization of &lt;a href="https://www.techtarget.com/searchitoperations/definition/DevOps"&gt;DevOps&lt;/a&gt;, enabling developers to adjust separate features without affecting the entire application. Containers promise a streamlined, easy-to-deploy and secure method to implement specific infrastructure requirements and are a lightweight alternative to VMs.&lt;/p&gt; 
&lt;p&gt;Let's examine the evolution of containers and discuss why cloud container security can't be overlooked.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="How do cloud containers work?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;How do cloud containers work?&lt;/h2&gt;
 &lt;p&gt;Container technology's roots were based on partitioning and chroot process isolation developed as part of Linux. Modern containers are expressed in &lt;a href="https://www.techtarget.com/searchitoperations/definition/application-containerization-app-containerization"&gt;application containerization&lt;/a&gt;, such as &lt;a href="https://www.techtarget.com/searchitoperations/definition/Docker"&gt;Docker&lt;/a&gt;, and in system containerization, such as Linux containers (LXC). Both enable IT teams to abstract application code from the underlying infrastructure as they work to simplify version management and enable portability across various deployment environments.&lt;/p&gt;
 &lt;p&gt;Containers rely on virtual isolation to deploy and run applications that access a shared OS kernel without the need for VMs. Because they hold all the necessary components -- files, libraries and environment variables -- containers run desired software without worrying about platform compatibility. The host OS constrains the container's access to physical resources, so a single container cannot consume all of a host's physical resources.&lt;/p&gt;
 &lt;p&gt;The key thing to recognize with cloud containers is they are designed to virtualize a single application. Consider a MySQL container. It provides a virtual instance of that application and that is all it does. Containers create an isolation boundary at the application level rather than at the server level. If anything goes wrong in that single container -- for example, excessive resource consumption by a process -- it only affects that individual container, not the whole VM or whole server. It also eliminates compatibility problems between containerized applications that reside on the same OS.&lt;/p&gt;
 &lt;p&gt;Major cloud vendors offer &lt;a href="https://www.techtarget.com/searchitoperations/definition/Containers-as-a-Service-CaaS"&gt;containers as a service&lt;/a&gt;, such as Amazon Elastic Container Service, AWS Fargate, Google Kubernetes Engine, Microsoft Azure Container Instances, Azure Kubernetes Service and Oracle Cloud Infrastructure Kubernetes Engine. Containers can also be deployed on public or private cloud infrastructure without the use of dedicated products from a cloud vendor.&lt;/p&gt;
 &lt;p&gt;Containers are deployed in two ways: by creating an image to run in a container, or by downloading a pre-created image, such as those available on Docker Hub. Docker -- originally built on LXC -- is by far the largest and most popular container platform. Although alternatives exist, Docker has become synonymous with containerization.&lt;/p&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="Cloud container use cases"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Cloud container use cases&lt;/h2&gt;
 &lt;p&gt;Enterprises use containers in a variety of ways to reduce costs and improve the reliability of software. Among the most common and beneficial are the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Microservices architecture.&lt;/b&gt; Containers are ideal for microservices-based application development, where apps are broken into smaller, independently deployable services. This improves scalability and simplifies development cycles. Kubernetes &lt;a href="https://www.techtarget.com/searchitoperations/tip/Kubernetes-automation-Use-cases-and-tools-to-know"&gt;orchestrates the deployment, scaling, and management&lt;/a&gt; of these services, enabling enterprises to deploy updates with minimal downtime.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Hybrid and multi-cloud deployments.&lt;/b&gt; Containers enable cloud-agnostic portability, letting enterprises run the same workloads across AWS, Azure, Google Cloud Platform or on-premises without changes to the application. This supports disaster recovery, cost optimization and vendor neutrality strategies.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;DevOps and continuous integration/continuous delivery automation.&lt;/b&gt; Enterprises use containers in CI/CD pipelines to ensure consistency from development to production. Containers enable developers to test in isolated environments that mirror production, reducing bugs and streamlining integration and deployment workflows.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Legacy application modernization.&lt;/b&gt; Many enterprises use containers to refactor legacy monolithic applications into more agile and maintainable services. By containerizing older apps, organizations can incrementally modernize their infrastructure without full rewrites.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Edge and IoT deployments.&lt;/b&gt; Containers can be deployed at the edge for use cases such as IoT, manufacturing and retail. Container runtimes such as K3s (lightweight Kubernetes) help IT staff support orchestration at the edge with limited resources.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Security and policy enforcement.&lt;/b&gt; By containerizing applications, enterprises can enforce &lt;a href="https://www.techtarget.com/searchitoperations/tip/Apply-policy-as-code-best-practices-to-reap-benefits"&gt;policy as code&lt;/a&gt; using services like Open Policy Agent and manage runtime security through integrations with cloud workload protection platforms (&lt;a href="https://www.techtarget.com/searchsecurity/definition/cloud-workload-protection-platform-CWPP"&gt;CWPPs&lt;/a&gt;) and cloud-native application protection program (CNAPP) tools.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Cloud containers vs. VMs"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Cloud containers vs. VMs&lt;/h2&gt;
 &lt;p&gt;&lt;a href="https://www.techtarget.com/searchcloudcomputing/tip/Why-should-I-use-Docker-containers-vs-VMs-for-my-cloud-apps"&gt;Compared with VMs&lt;/a&gt;, container deployments consume only a minimal amount of resources. Unlike VMs, they don't need a full OS to be installed within the container, and they don't need a virtual copy of the host server's hardware.&lt;/p&gt;
 &lt;p&gt;Containers need only minimal resources to perform the task they were designed for -- a few pieces of software, libraries and the basics of an OS. As a result, enterprises can deploy two to three times as many containers on a server as VMs, and they can be spun up much faster than VMs.&lt;/p&gt;
 &lt;figure class="main-article-image full-col" data-img-fullsize="https://www.techtarget.com/rms/onlineImages/windows_server-virtual_machines_vs_containers.png"&gt;
  &lt;img data-src="https://www.techtarget.com/rms/onlineImages/windows_server-virtual_machines_vs_containers_mobile.png" class="lazy" data-srcset="https://www.techtarget.com/rms/onlineImages/windows_server-virtual_machines_vs_containers_mobile.png 960w,https://www.techtarget.com/rms/onlineImages/windows_server-virtual_machines_vs_containers.png 1280w" alt="Graphic explaining the differences between cloud containers and VMs" height="380" width="560"&gt;
  &lt;div class="main-article-image-enlarge"&gt;
   &lt;i class="icon" data-icon="w"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/figure&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Benefits of containers"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Benefits of containers&lt;/h2&gt;
 &lt;p&gt;Cloud containers are portable. Once a container has been created, it can easily be deployed to different servers. From a software lifecycle perspective, this enables enterprises to quickly copy containers to create environments for development, testing, integration and production. From a software and security testing perspective, this ensures the underlying OS is not causing a difference in the test results.&lt;/p&gt;
 &lt;p&gt;Containers also offer a more dynamic environment. IT can scale up and down more quickly based on demand, keeping resources in check.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Challenges of containers"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Challenges of containers&lt;/h2&gt;
 &lt;p&gt;One downside of containers is the issue of splitting the virtualization into a lot of smaller chunks. When there are just a few containers involved, it's an advantage because the team knows exactly what configuration it is deploying and where. If, however, the organization fully invests in containers, it's quite possible to have so many containers that they become difficult to manage. Imagine &lt;a href="https://www.techtarget.com/searchenterprisedesktop/tip/Use-this-10-step-patch-management-process-to-ensure-success"&gt;deploying patches&lt;/a&gt; to hundreds of different containers. Without an easy process, updating a specific library or package inside a container image due to a security vulnerability can be difficult.&lt;/p&gt;
 &lt;p&gt;Container management is often a constant headache, even using systems such as Docker that aim to provide IT with easier orchestration.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Cloud container security risks"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Cloud container security risks&lt;/h2&gt;
 &lt;p&gt;While containers offer many advantages, they also introduce unique security risks that enterprises must address. The ephemeral and dynamic nature of containers demands a modern security approach that is proactive, automated and integrated into DevOps workflows. The following are some of the key risks that organizations should prioritize with cloud containers:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Vulnerable images.&lt;/b&gt; Containers are built from images, which often include system libraries, runtime dependencies and custom code. Many enterprises use public base images from registries such as Docker Hub, which could contain unpatched vulnerabilities or malware. Organizations should scan images continuously, use signed and verified sources, and establish image allowlists to ensure all builds are secure.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Container escape.&lt;/b&gt; Containers are isolated, but not impenetrable. A container breakout occurs when a malicious actor escapes the container runtime to access the host OS. This risk is elevated if containers run with &lt;a href="https://www.techtarget.com/searchsecurity/tip/6-ways-to-prevent-privilege-escalation-attacks"&gt;privileged access&lt;/a&gt; or root permissions. Mitigations include running containers as non-root users, using kernel security modules, such as AppArmor and SELinux, and deploying sandboxed runtimes, such as gVisor or Kata Containers. In cloud environments, some of these mitigation options might be difficult or impossible due to client lack of control and configuration.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Secrets exposure.&lt;/b&gt; Storing credentials, API keys or tokens inside containers or environment variables poses significant risk. If compromised, attackers could gain access to databases, cloud resources or internal assets and services. Best practices include using secret management tools, such as HashiCorp Vault or AWS Secrets Manager, and avoiding hardcoded secrets in images or Git repositories.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Supply chain attacks.&lt;/b&gt; Containers are part of a broader software supply chain that includes code, images, pipelines, registries and CI/CD tooling. Attackers can exploit vulnerabilities in this chain to inject malicious code or compromise deployments. Mitigation requires enforcing code signing and image integrity, using software bills of materials where possible to track dependencies, and monitoring for anomalies in build pipelines.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Runtime threats.&lt;/b&gt; Once deployed, containers remain vulnerable to attacks, including reverse shells, cryptomining malware and lateral movement in Kubernetes clusters. Security teams should deploy runtime protection tools -- most CNAPP and CWPP platforms prioritize this functionality -- to monitor system calls, container behavior, and network activity to detect and stop threats in real time.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Misconfigured orchestration.&lt;/b&gt; Misconfigurations in Kubernetes or other orchestrators are among the top container security risks. Common mistakes include exposing Kubernetes dashboards and APIs to the internet, running default or weak authentication settings and granting broad cluster roles to service accounts.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Insufficient network segmentation.&lt;/b&gt; Containers often communicate across virtual networks in a cluster. Without proper network policies, any compromised container could potentially facilitate attackers moving laterally. Enforce least privilege using Kubernetes network policies, Calico or service meshes, such as Istio, to limit connectivity.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Cloud container security best practices"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Cloud container security best practices&lt;/h2&gt;
 &lt;p&gt;Once cloud containers became popular, the focus turned to how to keep them secure. Consider the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Set access privileges.&lt;/b&gt; Docker containers once had to run as a privileged user on the underlying OS. If key parts of the container were compromised, root or administrator access could potentially be obtained on the underlying OS, or vice versa. Today, Docker supports user namespaces, which enable containers to run as specific users.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Deploy rootless containers.&lt;/b&gt; These containers add an &lt;a href="https://www.techtarget.com/searchitoperations/tip/Dockers-rootless-mode-a-welcome-security-update"&gt;additional security layer&lt;/a&gt; because they do not require root privileges. Therefore, if a rootless container is compromised, the attacker will not gain root access. Another benefit of rootless containers is that different users can run containers on the same endpoint. Docker currently supports rootless containers, but Kubernetes does not.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Consider image security.&lt;/b&gt; Pay attention to the security of images downloaded from public repositories, such as Docker Hub. By downloading a community-developed image, the security of a container cannot necessarily be guaranteed. Images can be scanned for vulnerabilities. This step can provide some assurance, but its verification processes might not be thorough enough if you are using containers for particularly sensitive applications. In this case, it would be sensible to create the image yourself to ensure your security policies have been enforced and updates are made regularly. Note, however, that company-made images are only as secure as employees make them. Proper training for those creating images is critical.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Monitor containers. &lt;/b&gt;Treat containers for sensitive production applications in the same way as any other deployment when it comes to security. If a container starts acting oddly or consuming more resources than necessary, it's easy enough to shut it down and restart it. It's not quite a &lt;a href="https://www.techtarget.com/searchnetworking/tip/The-role-of-network-sandboxing-and-testing"&gt;sandbox&lt;/a&gt;, but containers provide a way to keep untrusted applications separate and unaware of other applications on the endpoint.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Prioritize security threats and vulnerabilities.&lt;/b&gt; Follow container and cloud container security best practices and be aware of container security vulnerabilities and attacks. Proper deployment and management are key. Regularly scan containers to ensure images and active containers remain updated and secure.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Do not forget the security of the server hosting the containers.&lt;/b&gt; If your organization is using a cloud container provider, that company is responsible for operating, patching and hardening the service.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;One final point: Although containers are a newer technology, this doesn't mean &lt;a href="https://www.techtarget.com/searchsecurity/tip/10-cybersecurity-best-practices-and-tips-for-businesses"&gt;traditional security policies and procedures&lt;/a&gt; shouldn't be applied.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Rob Shapland, Ben Cole and Kyle Johnson previously contributed to this article.&lt;/i&gt;&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Dave Shackleford is founder and principal consultant at Voodoo Security, as well as a SANS analyst, instructor and course author, and GIAC technical director.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Containers are an integral part of a growing number of production environments. But they can become security risks if not managed correctly.</description>
            <image>https://cdn.ttgtmedia.com/visuals/searchCloudSecurity/architecture/cloudsecurity_article_003.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/feature/Guide-to-cloud-container-security-risks-and-best-practices</link>
            <pubDate>Fri, 12 Dec 2025 09:00:00 GMT</pubDate>
            <title>Guide to cloud container security risks and best practices</title>
        </item>
        <item>
            <body>&lt;p&gt;Identity and access management, or IAM, is a framework of business processes, policies and technologies that facilitates the management of digital identities. With an IAM framework in place, IT security teams can control user access to critical information within their organizations.&lt;/p&gt; 
&lt;p&gt;Using methods such as single sign-on (&lt;a href="https://www.techtarget.com/searchsecurity/definition/single-sign-on"&gt;SSO&lt;/a&gt;), &lt;a href="https://www.techtarget.com/searchsecurity/definition/two-factor-authentication"&gt;two-factor authentication&lt;/a&gt; and &lt;a href="https://www.techtarget.com/searchsecurity/definition/privileged-access-management-PAM"&gt;privileged access management&lt;/a&gt;, IAM technologies securely store identity and profile data and manage data governance functions to ensure that only necessary and relevant data is shared.&lt;/p&gt; 
&lt;p&gt;IAM performs the following fundamental security actions:&lt;/p&gt; 
&lt;ul class="default-list"&gt; 
 &lt;li&gt;Identifies individuals in a system through &lt;a href="https://www.techtarget.com/searchsecurity/answer/Authentication-vs-digital-identity-Whats-the-difference"&gt;identity management and authentication&lt;/a&gt;.&lt;/li&gt; 
 &lt;li&gt;Identifies roles in a system and how roles are assigned to individuals.&lt;/li&gt; 
 &lt;li&gt;Adds, removes and updates individuals and their roles in a system.&lt;/li&gt; 
 &lt;li&gt;Assigns levels of access to individuals or groups of individuals.&lt;/li&gt; 
 &lt;li&gt;Protects sensitive data within the system and secures the system itself.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;An enterprise's ability to know who is accessing which data and which systems and from where is not only helpful but critical to data protection. Employees are in far-flung locales, sometimes in branch offices and sometimes working remotely from their homes. Traditional defenses built around a known perimeter are no longer adequate, which is one reason why cybersecurity experts now refer to identity as the new perimeter.&lt;/p&gt; 
&lt;p&gt;This comprehensive guide examines the many aspects of identity and access management, including its challenges, technologies and trends. Hyperlinks direct readers to related articles that provide additional insights and guidance about how to understand, implement and manage IAM.&lt;/p&gt; 
&lt;figure class="main-article-image full-col" data-img-fullsize="https://www.techtarget.com/rms/onlineImages/security-iam_risk_analytics-f.png"&gt;
 &lt;img data-src="https://www.techtarget.com/rms/onlineImages/security-iam_risk_analytics-f_mobile.png" class="lazy" data-srcset="https://www.techtarget.com/rms/onlineImages/security-iam_risk_analytics-f_mobile.png 960w,https://www.techtarget.com/rms/onlineImages/security-iam_risk_analytics-f.png 1280w" alt="Graphic showing how an IAM system analyzes user behavior." height="321" width="560"&gt;
 &lt;div class="main-article-image-enlarge"&gt;
  &lt;i class="icon" data-icon="w"&gt;&lt;/i&gt;
 &lt;/div&gt;
&lt;/figure&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Why is IAM important?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Why is IAM important?&lt;/h2&gt;
 &lt;p&gt;Business leaders and IT departments are under pressure to grant access to corporate resources while at the same time protecting those resources. It's a balancing act, and it's not a simple one. Security teams must assign and track user privileges so that users can work with the data and applications they need to be productive -- without being so lax that bad actors find their way into systems.&lt;/p&gt;
 &lt;p&gt;The increased adoption of cloud services and the growth in hybrid and remote workforces mean more users are accessing more applications from more locations. These conditions make proper identity management indispensable.&lt;/p&gt;
 &lt;p&gt;Cybersecurity relies on IAM and its ever-increasing list of features, including &lt;a href="https://www.techtarget.com/searchsecurity/definition/biometrics"&gt;biometrics&lt;/a&gt;, behavior analytics and AI. With its tight control of resource access in highly distributed and dynamic environments, IAM aligns with security's transition from using traditional firewalls and inherent-trust practices to more rigid control architectures.&lt;/p&gt;
 &lt;p&gt;The foremost of these stricter controls is the &lt;a href="https://www.techtarget.com/searchsecurity/definition/zero-trust-model-zero-trust-network"&gt;zero-trust model&lt;/a&gt;. An organization that implements zero trust authorizes and authenticates users continuously, not merely once at the perimeter. This inverts the idea that users who've been cleared can be fully trusted. The zero-trust architecture prevents unnecessary movement between applications and systems, which, in turn, limits the damage an intruder might do.&lt;/p&gt;
 &lt;p&gt;With IAM in place, an organization gives itself important capabilities for heightened control over managing users' access in an organized fashion. Automation features eliminate manual steps, which boosts efficiency and lowers the chance of human error.&lt;/p&gt;
 &lt;p&gt;Businesses that are inattentive to IAM run the risk of intrusion, data loss, ransom attacks and worse. Bad actors often use stolen credentials to impersonate valid users. Because this access appears legitimate, cybercriminals can misuse credentials to linger inside a network for extended periods. If the stolen credential can be used to gain administrator privileges, the data loss and potential damage can be considerable. Bad actors use a range of tactics, including phishing and vishing, to acquire credentials.&lt;/p&gt;
 &lt;p&gt;Research by Verizon found that, over the past decade, stolen credentials have played a role in nearly one-third of breaches. Credential theft is so effective that it is used by both run-of-the-mill cybercriminals and highly organized nation-state threat actors.&lt;/p&gt;
 &lt;div class="youtube-iframe-container"&gt;
  &lt;iframe id="ytplayer-0" src="https://www.youtube.com/embed/D6nql-FGAyk?autoplay=0&amp;amp;modestbranding=1&amp;amp;rel=0&amp;amp;widget_referrer=null&amp;amp;enablejsapi=1&amp;amp;origin=https://searchcloudsecurity.techtarget.com" type="text/html" height="360" width="640" frameborder="0"&gt;&lt;/iframe&gt;
 &lt;/div&gt;
&lt;/section&gt;         
&lt;section class="section main-article-chapter" data-menu-title="Basic components of IAM"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Basic components of IAM&lt;/h2&gt;
 &lt;p&gt;IAM products offer access control, which lets system administrators regulate access to systems or networks based on the roles of individual users within the enterprise.&lt;/p&gt;
 &lt;p&gt;In this context, &lt;i&gt;access&lt;/i&gt; is the ability of an individual user to perform a specific task, such as view, create or modify a file. Roles are defined according to job, authority and responsibility. &lt;a href="https://www.techtarget.com/searchsecurity/tip/Types-of-access-control"&gt;Key types of access control&lt;/a&gt; include the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Role-based access control.&lt;/li&gt; 
  &lt;li&gt;Discretionary access control.&lt;/li&gt; 
  &lt;li&gt;Attribute-based access control.&lt;/li&gt; 
  &lt;li&gt;Mandatory access control.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;To gain access to those authorized resources, users must prove they are who they say they are. This is a complicated but necessary component of IAM, typically involving passwords, &lt;a href="https://www.techtarget.com/searchsecurity/definition/challenge-response-system"&gt;challenge-response authentication&lt;/a&gt; and related methods.&lt;/p&gt;
 &lt;p&gt;IAM systems should capture and record user login information, manage the enterprise database of user identities and orchestrate the assignment and removal of access privileges. Tools used for IAM should provide a centralized directory service with oversight and visibility into all aspects of the company user base.&lt;/p&gt;
 &lt;p&gt;To ensure the effectiveness of their IAM efforts, security teams should look to various identity standards and protocols. These tried-and-true standards can help improve an organization's security posture, compliance efforts and even user experience. The &lt;a href="https://www.techtarget.com/searchsecurity/definition/authentication-authorization-and-accounting"&gt;authentication, authorization and accounting&lt;/a&gt; framework, for example, is a way for security teams to organize their IAM work. It provides structure for access control, policy enforcement and usage tracking.&lt;/p&gt;
 &lt;p&gt;Another way for a business to manage IAM is the use of &lt;a href="https://www.techtarget.com/searchsecurity/definition/identity-governance-and-administration-IGA"&gt;identity governance and administration&lt;/a&gt;, which is a collection of processes that help ensure proper installation, oversight, enforcement and auditing of IAM policies.&lt;/p&gt;
 &lt;p&gt;It's worth remembering that a &lt;a href="https://www.techtarget.com/whatis/definition/digital-identity"&gt;digital identity&lt;/a&gt; isn't just for a person. IAM can and should manage the digital identities of devices and applications -- what's often called &lt;i&gt;&lt;a href="https://www.techtarget.com/searchsecurity/definition/What-is-machine-identity-management"&gt;machine identity management&lt;/a&gt;&lt;/i&gt; or &lt;i&gt;nonhuman identity management&lt;/i&gt;. These can be APIs, servers and devices that access information and need to be managed. Security experts say organizations have begun to realize just how many of these identities are present in their environments. Working to secure them is one of the emerging trends in IAM.&lt;/p&gt;
&lt;/section&gt;         
&lt;section class="section main-article-chapter" data-menu-title="Benefits of IAM"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Benefits of IAM&lt;/h2&gt;
 &lt;p&gt;IAM technologies can be used to initiate, capture, record and manage user identities and their related access permissions in an automated manner. In an era when workforces are more geographically scattered than ever before, well-operated IAM takes on greater importance.&lt;/p&gt;
 &lt;p&gt;An organization with an effective IAM program should expect to see the following benefits, &lt;a href="https://www.techtarget.com/searchsecurity/answer/What-are-the-key-identify-and-access-management-benefits"&gt;among other advantages&lt;/a&gt;:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Access privileges being granted according to policy, with all individuals and services properly authenticated, authorized and audited.&lt;/li&gt; 
  &lt;li&gt;Control of user access, which reduces the risk of internal and external data breaches.&lt;/li&gt; 
  &lt;li&gt;Enforcement of policies around user &lt;a href="https://www.techtarget.com/searchsecurity/definition/authentication"&gt;authentication&lt;/a&gt;, validation and privileging.&lt;/li&gt; 
  &lt;li&gt;Better compliance with government regulations.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;IAM implementation is necessary for secure operations, but companies can also gain competitive advantages. For example, IAM technologies enable a business to give users outside the organization -- such as customers, partners, contractors and suppliers -- access to applications and data without compromising security.&lt;/p&gt;
 &lt;div class="youtube-iframe-container"&gt;
  &lt;iframe id="ytplayer-1" src="https://www.youtube.com/embed/TbTUw2oz0EM?autoplay=0&amp;amp;modestbranding=1&amp;amp;rel=0&amp;amp;widget_referrer=null&amp;amp;enablejsapi=1&amp;amp;origin=https://searchcloudsecurity.techtarget.com" type="text/html" height="360" width="640" frameborder="0"&gt;&lt;/iframe&gt;
 &lt;/div&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="IAM technologies and tools"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;IAM technologies and tools&lt;/h2&gt;
 &lt;p&gt;IAM technologies are designed to simplify the user provisioning and account setup process. These systems should reduce the time it takes to complete these processes with a controlled workflow that decreases errors and the potential for abuse while enabling automated account fulfillment. An IAM system should also allow administrators to instantly view and change evolving access roles and rights.&lt;/p&gt;
 &lt;p&gt;These systems should balance the speed and automation of their processes with the control that administrators need to monitor and modify access rights. Consequently, to manage access requests, the central directory needs an access rights system that automatically matches employee job titles, business unit identifiers and locations to their relevant privilege levels.&lt;/p&gt;
 &lt;p&gt;Multiple review levels can be included as workflows to enable the proper checking of individual requests. This simplifies setting up appropriate review processes for higher-level access. It also eases reviews of existing rights to prevent privilege creep, which is the gradual accumulation of access rights beyond what users need to do their jobs.&lt;/p&gt;
 &lt;p&gt;A good IAM tool will automate least-privilege provisioning, enable SSO across multiple apps and providers, provide broad access visibility into an organization's systems and deliver a reasonably smooth user experience, among other functions.&lt;/p&gt;
 &lt;p&gt;IAM systems should be used to provide flexibility to establish groups with specific privileges for specific roles so that access rights based on employee job functions can be uniformly assigned. The system should also provide request and approval processes for modifying privileges, as employees with the same title and job location might need customized or slightly different access.&lt;/p&gt;
 &lt;p&gt;With IAM, enterprises can &lt;a href="https://www.techtarget.com/searchsecurity/answer/What-are-the-most-common-digital-authentication-methods"&gt;implement a range of digital authentication methods&lt;/a&gt; to prove digital identity and authorize access to corporate resources.&lt;/p&gt;
 &lt;p&gt;&lt;b&gt;Unique passwords.&lt;/b&gt; The most common type of digital authentication continues to be the unique password. While not especially secure or convenient, passwords are typically how users access their accounts for shopping, banking, entertainment, email and work.&lt;/p&gt;
 &lt;p&gt;To make passwords more secure, some organizations require longer or more complex passwords that include a combination of letters, symbols and numbers. Users understandably find it onerous to remember which long and complex password will get them logged in to this app or that site. SSO entry points and &lt;a href="https://www.techtarget.com/searchsecurity/definition/password-manager"&gt;password managers&lt;/a&gt; can help alleviate that burden.&lt;/p&gt;
 &lt;p&gt;&lt;b&gt;Multifactor authentication.&lt;/b&gt; &lt;a href="https://www.techtarget.com/searchsecurity/definition/multifactor-authentication-MFA"&gt;MFA&lt;/a&gt; is an increasingly common type of authentication. An IAM system that requires a user to enter a code texted to their phone, for example, increases the likelihood that the access attempt is legitimate. Unless they've already gained access to -- or possession of -- the user's phone, bad actors with a stolen password won't be able to clear that second authentication hurdle.&lt;/p&gt;
 &lt;p&gt;The MFA movement is gaining momentum. Employers now routinely ask remote workers to use a second or third factor to prove their identity. Financial institutions and other security-minded organizations use MFA processes before granting a customer access to an account. In 2024, Google Cloud, AWS and Microsoft Azure all decided that they will require MFA for their customers to access cloud services.&lt;/p&gt;
 &lt;div class="youtube-iframe-container"&gt;
  &lt;iframe id="ytplayer-2" src="https://www.youtube.com/embed/_3rlQVXGKZc?autoplay=0&amp;amp;modestbranding=1&amp;amp;rel=0&amp;amp;widget_referrer=null&amp;amp;enablejsapi=1&amp;amp;origin=https://searchcloudsecurity.techtarget.com" type="text/html" height="360" width="640" frameborder="0"&gt;&lt;/iframe&gt;
 &lt;/div&gt;
 &lt;p&gt;&lt;b&gt;Adaptive authentication.&lt;/b&gt; When dealing with highly sensitive information and systems, organizations can use behavioral or adaptive authentication methods to assist in identity management. IAM tools, for example, are now more capable of noticing when someone who typically logs in from a certain place at a certain time is attempting to access systems from another location and at a time they are not normally working. These behaviors could signal that the user's credentials have been compromised.&lt;/p&gt;
 &lt;p&gt;By applying AI, organizations can more readily recognize if user or machine behavior falls outside of the norm; anomalies should trigger automatic lockdowns.&lt;/p&gt;
 &lt;p&gt;&lt;b&gt;Biometrics.&lt;/b&gt; Some IAM systems use biometrics as their method of authentication. Biometric characteristics, such as fingerprints, irises, faces, palms, gaits, voices and, in some cases, DNA, are seen as an easy and precise way to know exactly who is accessing what.&lt;/p&gt;
 &lt;p&gt;While the convenience of facial recognition or fingerprint scanning is hard to deny, the use of biometrics involves risks -- ones that are unlike other challenges in IT or security. Stolen fingerprint data, for example, can't be replaced the way a hacked password can be. Make sure to fully understand the &lt;a href="https://www.techtarget.com/searchsecurity/tip/Evaluate-biometric-authentication-pros-and-cons-implications"&gt;pros and cons of biometric authentication&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;When an organization collects a person's specific facial characteristics, it assumes the serious responsibility of safeguarding that data. Organizations with plans to adopt biometrics need to work through a &lt;a href="https://www.techtarget.com/searchsecurity/tip/In-biometrics-security-concerns-span-technical-legal-and-ethical"&gt;long list of privacy and legal questions&lt;/a&gt; before committing to this form of authentication.&lt;/p&gt;
 &lt;figure class="main-article-image full-col" data-img-fullsize="https://www.techtarget.com/rms/onlineimages/security-biometric_authentication_types.png"&gt;
  &lt;img data-src="https://www.techtarget.com/rms/onlineimages/security-biometric_authentication_types_mobile.png" class="lazy" data-srcset="https://www.techtarget.com/rms/onlineimages/security-biometric_authentication_types_mobile.png 960w,https://www.techtarget.com/rms/onlineimages/security-biometric_authentication_types.png 1280w" alt="An illustration of 16 types of biometric authentication." height="608" width="559"&gt;
  &lt;div class="main-article-image-enlarge"&gt;
   &lt;i class="icon" data-icon="w"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/figure&gt;
&lt;/section&gt;                  
&lt;section class="section main-article-chapter" data-menu-title="Implementing IAM in the enterprise"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Implementing IAM in the enterprise&lt;/h2&gt;
 &lt;p&gt;A key area of concern in IAM is &lt;a href="https://www.techtarget.com/searchsecurity/tip/User-provisioning-and-deprovisioning-Why-it-matters-for-IAM"&gt;how accounts are provisioned and deprovisioned&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;IT teams will sometimes grant privileges to a user beyond what's needed for that person to do a particular job. For an intruder, these overprivileged accounts are especially valuable targets because they allow access to many parts of an organization. A related risk is poor deprovisioning practices, or the removal of access when a specific employee changes roles or leaves the company. Strict provisioning also reduces the chances of an insider threat.&lt;/p&gt;
 &lt;p&gt;An organization needs to identify a team of people who will play a lead role in the enforcement of identity and access policies. IAM affects every department and every type of user -- employee, contractor, partner, supplier, customer and so on -- so it's essential the IAM team comprises a mix of corporate functions. An approach that pulls together various people and is organized around the same goals should improve the chances of success in identity security.&lt;/p&gt;
 &lt;p&gt;What's needed for an &lt;a href="https://www.techtarget.com/searchsecurity/feature/How-to-build-an-identity-and-access-management-architecture"&gt;effective IAM infrastructure&lt;/a&gt;? Key points to evaluate include how to handle authentication and &lt;a href="https://www.techtarget.com/searchsecurity/definition/federated-identity-management"&gt;federated identity management&lt;/a&gt;. These activities could involve a decision to use the &lt;a href="https://www.techtarget.com/whatis/definition/OpenID"&gt;OpenID Connect&lt;/a&gt; protocol or the &lt;a href="https://www.techtarget.com/searchsecurity/definition/SAML"&gt;SAML&lt;/a&gt; standard, which are similar but not the same.&lt;/p&gt;
 &lt;p&gt;Implementations should be carried out with &lt;a href="https://www.techtarget.com/searchsecurity/tip/Best-practices-for-a-bulletproof-IAM-strategy"&gt;IAM best practices&lt;/a&gt; in mind, which include the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Adoption of the zero-trust architecture.&lt;/li&gt; 
  &lt;li&gt;Use of MFA.&lt;/li&gt; 
  &lt;li&gt;Strong password policies.&lt;/li&gt; 
  &lt;li&gt;Promotion of security awareness training.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Businesses also should make sure to centralize security and critical systems around identity. Perhaps most importantly, organizations should create a process they can use to evaluate the efficacy of current IAM controls.&lt;/p&gt;
 &lt;p&gt;While IAM relies on a lot of technology, it is not about only the frameworks and tools. An IT security team needs people who possess &lt;a href="https://www.techtarget.com/searchsecurity/tip/What-skills-are-needed-for-a-successful-career-in-IAM"&gt;IAM skills and expertise&lt;/a&gt;. Those seeking jobs in the field should be ready to demonstrate their knowledge when it comes time for &lt;a href="https://www.techtarget.com/whatis/feature/IAM-Interview-Questions-and-Answers"&gt;the IAM job interview&lt;/a&gt;.&lt;/p&gt;
 &lt;figure class="main-article-image full-col" data-img-fullsize="https://www.techtarget.com/rms/onlineimages/mfa_sms_examples-f.png"&gt;
  &lt;img data-src="https://www.techtarget.com/rms/onlineimages/mfa_sms_examples-f_mobile.png" class="lazy" data-srcset="https://www.techtarget.com/rms/onlineimages/mfa_sms_examples-f_mobile.png 960w,https://www.techtarget.com/rms/onlineimages/mfa_sms_examples-f.png 1280w" alt="Graphic of two smartphones displaying examples of MFA messages. " height="353" width="560"&gt;
  &lt;div class="main-article-image-enlarge"&gt;
   &lt;i class="icon" data-icon="w"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/figure&gt;
&lt;/section&gt;          
&lt;section class="section main-article-chapter" data-menu-title="IAM risks"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;IAM risks&lt;/h2&gt;
 &lt;p&gt;While essential to security efforts, IAM is not without risks. Organizations can -- and do -- get things wrong when trying to manage identities and control access.&lt;/p&gt;
 &lt;p&gt;Access management can be of concern when the provisioning and deprovisioning of user accounts aren't handled correctly. Security teams need to be aware of vulnerable, inactive user accounts. When there is a sprawl in admin accounts, someone should notice and raise questions about why. Organizations need to ensure lifecycle control over all aspects of IAM to prevent malicious actors from gaining access to user identities and passwords.&lt;/p&gt;
 &lt;p&gt;Specific &lt;a href="https://www.techtarget.com/searchsecurity/answer/What-are-some-of-the-top-identity-and-access-management-risks"&gt;IAM risks to watch for&lt;/a&gt; include the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Irregular access reviews.&lt;/li&gt; 
  &lt;li&gt;Weak passwords and missing MFA.&lt;/li&gt; 
  &lt;li&gt;Overprivileged accounts.&lt;/li&gt; 
  &lt;li&gt;Poorly integrated IAM across systems and clouds.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Audit capabilities act as a check to ensure users' access changes accordingly when they switch roles or leave the organization.&lt;/p&gt;
 &lt;p&gt;To better assess their organization's security risks, IT professionals can pursue security certifications. Some certifications are &lt;a href="https://www.techtarget.com/searchsecurity/tip/Comparing-top-identity-and-access-management-certifications"&gt;specific to identity management&lt;/a&gt;.&lt;/p&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="IAM vendors and products"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;IAM vendors and products&lt;/h2&gt;
 &lt;p&gt;IAM vendors range from large companies -- such as IBM, Microsoft, Oracle and RSA -- to pure-play providers -- such as Okta, Ping Identity, SailPoint and OneLogin.&lt;/p&gt;
 &lt;p&gt;The dynamic nature of &lt;a href="https://www.techtarget.com/searchsecurity/feature/8-leading-identity-and-access-management-products-for-2020"&gt;the IAM tools market&lt;/a&gt; means that organizations have plenty of options. It also means security teams will need to do some legwork to identify the right mix of products that will address the needs of the business, such as centralized management, SSO, governance, compliance and risk analytics tools.&lt;/p&gt;
 &lt;p&gt;Some vendors are moving toward combining various products and tooling into IAM platforms. Having a suite of capabilities in a single platform could lessen the integration problems found with the currently fragmented market of IAM products.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="IAM and compliance"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;IAM and compliance&lt;/h2&gt;
 &lt;p&gt;Central to IAM is an adherence to the &lt;a href="https://www.techtarget.com/searchsecurity/definition/principle-of-least-privilege-POLP"&gt;principle of least privilege&lt;/a&gt;, where users are granted only the access rights necessary to fulfill their particular work duties. This predetermined and real-time access control is necessary for security as well as compliance.&lt;/p&gt;
 &lt;p&gt;With IAM controls in place, a business should be able to prove to outside entities that it takes its security responsibilities seriously and that data is protected. Organizations with effective IAM can &lt;a href="https://www.techtarget.com/searchsecurity/tip/Identity-management-compliance-How-IAM-systems-support-compliance"&gt;demonstrate compliance&lt;/a&gt; and adhere to applicable regulations, such as GDPR, HIPAA and the Sarbanes-Oxley Act.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="The IAM roadmap"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The IAM roadmap&lt;/h2&gt;
 &lt;p&gt;Innovation is plentiful around IAM, and enterprises are the beneficiaries of new strategies that are backed up by products and features. As has always been the case, however, security professionals must confront threats that are known -- and persistent because of their proven effectiveness -- and ones that are emerging and less defined.&lt;/p&gt;
 &lt;p&gt;One of the newer IAM-related defenses against cyberattacks is identity threat detection and response (&lt;a href="https://www.techtarget.com/searchsecurity/definition/What-is-identity-threat-detection-and-response-ITDR"&gt;ITDR&lt;/a&gt;). A combination of tools and best practices, ITDR is intended to stop bad actors from taking advantage of vulnerable identities, such as one associated with a legacy application that isn't compatible with a modern access management tool. ITDR can flag these weaknesses, giving an IT team the chance to address the vulnerabilities before they are exploited.&lt;/p&gt;
 &lt;p&gt;Advancements in AI have heightened concerns about identity security. Experts worry that &lt;a href="https://www.techtarget.com/searchsecurity/tip/Generative-AI-is-making-phishing-attacks-more-dangerous"&gt;AI could make phishing tactics more sophisticated&lt;/a&gt; and more believable. Effective phishing typically requires some morsel of information that lends at least a ring of truth to the message -- something that sounds reasonable enough to trick a recipient into action. AI can quickly and efficiently gather the bits of information that provide that veneer of legitimacy.&lt;/p&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    Longer, stronger passwords might improve identity management, but they won't satisfy those who would like to see every password permanently expire.
   &lt;/figure&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
 &lt;p&gt;When cybercriminals can induce their victims to click a link or reveal a password, even strong organizational defenses and IAM protections can be thwarted.&lt;/p&gt;
 &lt;p&gt;Even without AI's help, passwords have long been vulnerable. Cracking techniques make many passwords solvable. And the prospect of needing to create and remember yet another password is a common aggravation. It's fair to say passwords are about as popular with hackers as they are unpopular with users.&lt;/p&gt;
 &lt;p&gt;Despite being both risky and unloved, passwords endure. The shift to &lt;a href="https://www.techtarget.com/searchsecurity/definition/passwordless-authentication"&gt;passwordless authentication&lt;/a&gt; is tantalizing, but that passwordless future has yet to arrive.&lt;/p&gt;
 &lt;p&gt;In a September 2024 earnings call, Oracle's chairman and cofounder Larry Ellison lamented tech's continued reliance on passwords. Ellison argued that facial recognition tools should be the way forward. "Look at me and recognize me," Ellison said. "Don't ask me to type in some stupid 17-letter password."&lt;/p&gt;
 &lt;p&gt;Ellison's remarks came at roughly the same time that NIST, which sets the most widely accepted cybersecurity standards, proposed significant adjustments to its password guidelines. Recognizing that passwords are still widely used and likely will be for the foreseeable future, NIST is advocating for better passwords. The 2024 draft guidelines call for organizations to eliminate the common mandate for users to reset a password every 90 days; a password change, NIST suggested, should be made only when there's evidence or reasonable concern that a breach has compromised someone's credentials. The NIST proposal also recommended password length grow to between 15 and 64 characters.&lt;/p&gt;
 &lt;p&gt;Longer, stronger passwords might improve identity management, but they won't satisfy those who would like to see every password permanently expire. Promoters of passkeys, for example, argue that users should be able to access applications and websites with the same safe and simple methods they use to unlock a device. Once a passkey is created, password-manager technology matches a public key known only to the service being accessed with a private key known only to the device being used. This cryptographic key pair lets users authenticate themselves without needing to remember a password -- provided they have securely unlocked the device in use through a PIN or biometric method.&lt;/p&gt;
 &lt;p&gt;The FIDO Alliance, a nonprofit with backing from Google and others, is &lt;a href="https://www.passkeycentral.org/introduction-to-passkeys/the-passkey-experience" target="_blank" rel="noopener"&gt;pushing standards&lt;/a&gt; that would enable wider use of passkeys. The goal would be to effectively replace passwords. Whether businesses and individuals will embrace passkeys and password managers is far from certain. And it's worth remembering that the password's demise has been sought -- and predicted -- for a long time, which gives you something to think about the next time you stop to remember how to sign in to your account.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Phil Sweeney is an industry editor and writer focused on information security topics. Article was updated in 2025 to improve the reader's experience.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>No longer just a good idea, IAM is a crucial piece of the cybersecurity puzzle. It's how an organization regulates access to information and meets its compliance obligations.</description>
            <image>https://cdn.ttgtmedia.com/visuals/digdeeper/5.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/definition/What-is-identity-and-access-management-Guide-to-IAM</link>
            <pubDate>Fri, 21 Nov 2025 00:00:00 GMT</pubDate>
            <title>What is identity and access management? Guide to IAM</title>
        </item>
        <item>
            <body>&lt;p&gt;When it comes to &lt;a href="https://www.techtarget.com/searchsecurity/definition/ransomware"&gt;ransomware&lt;/a&gt;, prevention is key. But equally important is knowing how to detect ransomware if it infects a network -- before it encrypts and exfiltrates business-critical data. By the time a ransom demand arrives, the damage is done.&lt;/p&gt; 
&lt;p&gt;Early detection involves a mix of automation and malware analysis to discover malicious files early in the kill chain. But malware isn't always easy to find. To escape detection, adversaries often hide ransomware within legitimate software, such as PowerShell scripts, VBScript, Mimikatz and PsExec. Plus, sometimes detection is not just about the malware itself; it involves using clues from network activity to understand if an attack is about to happen.&lt;/p&gt; 
&lt;p&gt;Let's take a deeper look at four ransomware detection methods: signature-based, behavior-based, traffic-based and deception-based detection.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="1. Signature-based detection"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;1. Signature-based detection&lt;/h2&gt;
 &lt;p&gt;Signature-based ransomware detection compares a ransomware sample hash to known malware signatures. It provides quick static analysis of files in an environment. Security platforms, intrusion detection systems and antivirus software capture data from within an executable to determine the likelihood that it is ransomware rather than an authorized executable. Most antivirus software takes this step when scanning for malware.&lt;/p&gt;
 &lt;p&gt;Security teams can also use the Windows PowerShell cmdlet Get-FileHash or open source intelligence tools, such as VirusTotal, to get a file's hash. With current hashing algorithms, security professionals can compare a file's hash to known malware samples and ransomware threats. Security teams can then use antivirus and antimalware tools to blocklist specific file types. This prevents users from inadvertently downloading malware via email phishing attempts or suspicious websites.&lt;/p&gt;
 &lt;p&gt;Signature-based ransomware detection techniques are a first level of defense. While useful at finding known threats, signature-based detection methods cannot always identify newer or zero-day threats. For example, attackers update their malware files frequently to avoid detection. Adding a single byte to a file creates a new hash, decreasing the malware's detectability by signature alone.&lt;/p&gt;
 &lt;p&gt;Despite its issues, signature-based detection is still useful to identify older ransomware variants.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="2. Behavior-based detection"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;2. Behavior-based detection&lt;/h2&gt;
 &lt;p&gt;Behavior-based ransomware detection methods compare new behaviors against historical data to help security professionals and tools look for indicators of compromise. For example, these methods can detect if someone is accessing a company desktop remotely from another state when the employee logged in from the office that same day.&lt;/p&gt;
 &lt;p&gt;Behavior-based detection includes the following steps:&lt;/p&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Measuring file system changes.&lt;/b&gt; Security teams should look for abnormal file executions, such as an overabundance of file renames. A few happen in a normal workday, but hundreds within a short amount of time should raise a red flag. Ransomware can stay hidden in systems for a while before executing, so security teams should also look for the creation of a file with larger entropy than an original file, as well as the enumeration and encryption of files.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Examining API calls.&lt;/b&gt; Security teams should examine API calls to know what commands files execute and whether any are suspicious. For example, spyware and keyloggers use GetWindowDC to capture information from an entire window or IsDebuggerPresent to detect if a debugger is active on a system. Another ransomware ploy is to use GetTickCount to determine how long a system has been on, to the millisecond. A short period of time could indicate the ransomware is in a VM, and therefore, it won't execute any malicious actions.&lt;/li&gt; 
 &lt;/ol&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="3. Traffic-based detection"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;3. Traffic-based detection&lt;/h2&gt;
 &lt;p&gt;Traffic-based detection involves monitoring network traffic for suspicious activity or patterns, such as a sudden increase in outward volume. This might indicate a successful cyberattack is exfiltrating sensitive data, resulting in an increase in outgoing traffic.&lt;/p&gt;
 &lt;p&gt;Security teams should examine traffic for anomalies, such as if software is connecting to suspicious file-sharing sites, and the times of such actions. Teams should also check if traffic volume has recently increased and where that traffic going, as well as compare destinations with known suspicious IP addresses. Ransomware requires network connectivity to offsite servers to receive command-and-control instructions and to exchange decryption keys.&lt;/p&gt;
 &lt;p&gt;Note that, while useful, this detection method can yield false positives and requires analysis time. Attackers might also use legitimate file-sharing sites that have been allowlisted by the infected company, enabling them to fly under the radar.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="4. Deception-based detection"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;4. Deception-based detection&lt;/h2&gt;
 &lt;p&gt;Deception-based ransomware detection involves tricking adversaries while they search for data to encrypt or exfiltrate within the organization's system. Security teams use deception techniques to fool malicious attackers into interacting with fake assets in the network. Legitimate users would never touch these false assets, giving security teams a reliable indicator of suspicious activity.&lt;/p&gt;
 &lt;p&gt;To enable deception-based detection, security teams deploy decoys, such as &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-honey-tokens-support-cyber-deception-strategies"&gt;honeynets, honeypots and honey tokens&lt;/a&gt;, and ignore them unless an alert is logged. The following are some characteristics of these types of decoys:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Honeynets are networks of honeypots and honey tokens.&lt;/li&gt; 
  &lt;li&gt;Honeypots are any intentionally vulnerable network-attached systems, such as computers, VMs, applications, file repositories or servers.&lt;/li&gt; 
  &lt;li&gt;Honey tokens are individual files, email addresses or user accounts used to attract attackers.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;h3&gt;Take a layered anti-ransomware approach&lt;/h3&gt;
 &lt;p&gt;When it comes to ransomware detection, there's no one-size-fits-all technique. Using multiple methods together offers security teams a better chance to detect and monitor a ransomware attack, and isolate it before it does too much damage.&lt;/p&gt;
 &lt;p&gt;Organizations need to do more than just install and run antivirus software. Alongside a combination of the aforementioned ransomware detection techniques, security teams should also look for attacks entering through the front door. &lt;a href="https://www.techtarget.com/searchsecurity/definition/insider-threat"&gt;Insider threats&lt;/a&gt;, such as credential reuse and &lt;a href="https://www.techtarget.com/searchsecurity/definition/social-engineering"&gt;social engineering&lt;/a&gt;, can easily provide adversaries access to a system.&lt;/p&gt;
 &lt;p&gt;It's time to take ransomware seriously. While the number of payments dropped as some ransomware groups have folded, the overall average ransomware payment remains high. It was around $480,000 in the third quarter of 2024, up 23% from the second quarter, &lt;a target="_blank" href="https://www.coveware.com/blog/2024/11/1/law-enforcement-doxxing-raises-risk-profile-for-threat-actors" rel="noopener"&gt;according&lt;/a&gt; to incident response vendor Coveware.&lt;/p&gt;
 &lt;p&gt;Further ransomware prevention involves training employees about ransomware risks and teaching infosec professionals the &lt;a href="https://www.techtarget.com/searchsecurity/tip/Mitre-ATTCK-framework-use-cases"&gt;Mitre ATT&amp;amp;CK framework&lt;/a&gt;, which includes information on adversary tactics, techniques and procedures. With this knowledge, security teams can determine the organization's strengths and weaknesses and improve system security accordingly to boost ransomware protection.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Kyle Johnson is technology editor for Informa TechTarget's SearchSecurity site.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>While prevention is key, it's not enough to protect a company's systems from ransomware. Learn how early detection with these four methods helps reduce damage from attacks.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/ransom_g943330284.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/feature/4-ransomware-detection-techniques-to-catch-an-attack</link>
            <pubDate>Thu, 03 Apr 2025 09:00:00 GMT</pubDate>
            <title>4 ransomware detection techniques to catch an attack</title>
        </item>
        <item>
            <body>&lt;p&gt;Identity and access management, or &lt;a href="https://www.techtarget.com/searchsecurity/definition/identity-access-management-IAM-system"&gt;IAM&lt;/a&gt; -- the discipline of ensuring the right individuals have access to the right things at the right times -- sometimes falls into the category of things that are so foundational to enterprise security that we don't stop to think about them. Like many technologies that have reached a high level of maturity, IAM becomes plumbing; it goes unnoticed until there's a problem. That doesn't mean IT decision-makers should stop paying attention.&lt;/p&gt; 
&lt;p&gt;To devise the best IAM architecture for specific use cases, an organization must be clear about what it hopes to accomplish. Let's examine the key questions and decisions involved.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="3 key steps to selecting an IAM architecture"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;3 key steps to selecting an IAM architecture&lt;/h2&gt;
 &lt;p&gt;There are important starting points, including knowing who will be authenticated and why, determining which applications users employ and understanding where those users are located.&lt;/p&gt;
 &lt;p&gt;As these questions are answered, pay particular attention to these areas:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;SaaS applications hosted outside the enterprise environment.&lt;/li&gt; 
  &lt;li&gt;Identity requirements for nonhuman actors (e.g., machines, applications and containers), including potentially ephemeral identities.&lt;/li&gt; 
  &lt;li&gt;Usage that presupposes identities not belonging to the organization.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;The process for creating an effective IAM architecture can be broken down into three steps.&lt;/p&gt;
 &lt;h3&gt;Step 1&lt;/h3&gt;
 &lt;p&gt;Security teams should make a list of usage that they anticipate users will interact with, including applications, services, components and other elements. Consolidating this into a list helps validate with others in the organization that usage assumptions are correct. It can also be used as input into the product selection process when evaluating if IAM mechanisms provide the needed capabilities. As you do this and as outlined above, factor in nonhuman identities as well as human ones since you'll want to make sure to address both. Taking action to manage these nonhuman identities is becoming one of the &lt;a href="https://www.techtarget.com/searchsecurity/tip/Identity-and-access-management-trends-to-watch"&gt;major trends in IAM&lt;/a&gt; and cybersecurity.&lt;/p&gt;
 &lt;h3&gt;Step 2&lt;/h3&gt;
 &lt;p&gt;Think through how different environments -- for example, cloud SaaS applications and on-premises applications such as domain login -- will be linked together. There are times when different systems might be needed to accommodate different types of applications and usage. Understanding which other systems exist outside enterprise boundaries is useful because these systems might need to federate in specific ways. For example, Cloud Provider A might enable federation via Security Assertion Markup Language (&lt;a href="https://www.techtarget.com/searchsecurity/definition/SAML"&gt;SAML&lt;/a&gt;), while Provider B does so via &lt;a href="https://www.techtarget.com/whatis/definition/OpenID"&gt;OpenID Connect&lt;/a&gt;. Each of these needs to be accounted for.&lt;/p&gt;
 &lt;h3&gt;Step 3&lt;/h3&gt;
 &lt;p&gt;Consider carefully which specific areas of IAM are most important to the business. The following list of questions will help enterprises evaluate potential vendors and systems:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Is MFA necessary?&lt;/li&gt; 
  &lt;li&gt;Do customers and employees need to be supported in the same system?&lt;/li&gt; 
  &lt;li&gt;Are &lt;a href="https://www.techtarget.com/searchsecurity/tip/User-provisioning-and-deprovisioning-Why-it-matters-for-IAM"&gt;automated provisioning and deprovisioning required&lt;/a&gt;?&lt;/li&gt; 
  &lt;li&gt;Which standards need to be supported?&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;That said, there are many IAM architectural elements, approaches and design principles to consider when evaluating the best option for your &lt;a href="https://www.techtarget.com/searchsecurity/opinion/How-to-plan-an-IAM-program-strategy"&gt;organization's business needs&lt;/a&gt;.&lt;/p&gt;
&lt;/section&gt;             
&lt;section class="section main-article-chapter" data-menu-title="The evolving IAM architecture"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The evolving IAM architecture&lt;/h2&gt;
 &lt;p&gt;From an architectural point of view, the design of most IAM implementations is relatively straightforward at first glance. Complexities only arise when the implications are considered and extended to particular use cases.&lt;/p&gt;
 &lt;p&gt;Consider the Open Security Architecture (OSA) &lt;a href="http://www.opensecurityarchitecture.org/cms/library/patternlandscape/244-pattern-identity-management" target="_blank" rel="noopener"&gt;design pattern&lt;/a&gt; for Identity Management, SP-010 (Figure 1). OSA represents an open, collaborative repository for security architectural design patterns -- i.e., strategies that encapsulate systems in pictorial format for use by the community.&lt;/p&gt;
 &lt;figure class="main-article-image full-col" data-img-fullsize="https://searchcloudsecurity.techtarget.com/rms/onlineImages/IAM_architecture_figure1.jpg"&gt;
  &lt;img data-src="https://searchcloudsecurity.techtarget.com/rms/onlineImages/IAM_architecture_figure1_mobile.jpg" class="lazy" data-srcset="https://searchcloudsecurity.techtarget.com/rms/onlineImages/IAM_architecture_figure1_mobile.jpg 960w,https://searchcloudsecurity.techtarget.com/rms/onlineImages/IAM_architecture_figure1.jpg 1280w" alt="Screenshot of the OSA identity management design pattern." height="603" width="560"&gt;
  &lt;figcaption&gt;
   &lt;i class="icon pictures" data-icon="z"&gt;&lt;/i&gt;Figure 1. SP-010: Identity Management Pattern by OSA, licensed under CC BY-SA.
  &lt;/figcaption&gt;
  &lt;div class="main-article-image-enlarge"&gt;
   &lt;i class="icon" data-icon="w"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/figure&gt;
 &lt;p&gt;Figure 1 shows the diagram portion of the OSA IAM design pattern. Textual elements, which further explain the conceptual view, description and other salient notes, have been left out for the sake of brevity and because most of these details are implied in the diagram.&lt;/p&gt;
 &lt;p&gt;A few assumptions are implicit in the diagram. First, it addresses multiple roles that interact with IAM components, as well as systems and services that rely on it. Second, it separates policy enforcement -- in this diagram, enforced at the server/service level -- from policy decisions, which are handled via the combination of the directory and authentication service. Lastly, it is built around the assumption that the organization owns and manages user identity.&lt;/p&gt;
 &lt;p&gt;This is a traditional design pattern, and it is important to note that some of its underlying assumptions are in transition in a few ways. First, there is the question of federation to external service providers, which can require separate infrastructure to set up and maintain. Then, there is the question of extending identity into the cloud, which, depending on the model employed, can either use state transfer -- for example, SAML or OpenID Connect -- to &lt;a href="https://www.techtarget.com/searchcloudcomputing/tip/The-importance-of-identity-federation-in-the-cloud"&gt;federate between&lt;/a&gt; on-premises and cloud or can use cloud-native identity providers directly.&lt;/p&gt;
 &lt;p&gt;There is also the question of who is being authenticated and for what purpose. The OSA diagram is clearly targeted at employees. Organizations today must maintain multiple identities beyond their employees, such as customers, application users, system administrative users, machine identities and other types of users. An organization employing a model like this for internal user authentication and access control could very well also have a production application that contains customer user accounts. This might be as sophisticated as a &lt;a href="https://www.techtarget.com/searchsecurity/tip/CIAM-vs-IAM-The-key-differences-customer-makes"&gt;customer IAM platform&lt;/a&gt; (CIAM), or depending on the use, it could be as simple as a database table that contains application-specific user credentials.&lt;/p&gt;
 &lt;p&gt;While descriptive of how IAM has functioned historically, the OSA diagram is likely not particularly descriptive of how most organizations conduct IAM today. This is true because of changes in how IAM is used for employees. Also, it doesn't address customer identities or fully account for technology changes that complicate how IAM operates.&lt;/p&gt;
&lt;/section&gt;         
&lt;section class="section main-article-chapter" data-menu-title="Differences in IAM approaches"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Differences in IAM approaches&lt;/h2&gt;
 &lt;p&gt;If IAM methods are changing and &lt;a href="https://www.techtarget.com/searchsecurity/answer/What-are-some-of-the-top-identity-and-access-management-risks"&gt;legacy approaches are in a state of transition&lt;/a&gt;, how should enterprises select the best approach for their needs? There are a few things to consider:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;What is the organization looking to do?&lt;/li&gt; 
  &lt;li&gt;What is the scope?&lt;/li&gt; 
  &lt;li&gt;Where is the source?&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;It is important to remember that IAM is a huge discipline. It includes several subdisciplines, such as authentication, &lt;a href="https://www.techtarget.com/searchsecurity/feature/Weighing-privileged-identity-management-tools-pros-and-cons"&gt;privileged identity management&lt;/a&gt;, authorization and access control, federation, role-based access control (RBAC) and numerous others. There are also multiple different kinds of users, from customers and privileged accounts to service accounts, internal employees, business partners and more.&lt;/p&gt;
 &lt;p&gt;When selecting IAM architectures, organizations must also consider the intersection points with environments -- and, in particular, sources of identity and identity providers -- that they don't directly control. You'll want to make sure you account for cloud services and third parties, such as business partner environments, identity providers, as-a-service implementations and so on.&lt;/p&gt;
 &lt;p&gt;When all this is considered, enterprises might -- and, in fact, very likely will -- end up with a different design than the OSA model presented above. For example, take two completely different models: a CIAM application (i.e., focused on customer identities) versus an internal employee-centric one. The employee-centric one might closely mirror the OSA model. But in a CIAM context, there could be UI components residing at an IaaS provider or implemented in PaaS. There could also be RESTful APIs that implement specific and custom business logic. Within that context, a traditional authentication server and directory (Figure 1) might be employed, or cloud tools, such as an external identity as a service (IDaaS) provider, might be used (Figure 2).&lt;/p&gt;
 &lt;figure class="main-article-image full-col" data-img-fullsize="https://searchcloudsecurity.techtarget.com/rms/onlineImages/security-sample_ciam_arch_external_providers-f.png"&gt;
  &lt;img data-src="https://searchcloudsecurity.techtarget.com/rms/onlineImages/security-sample_ciam_arch_external_providers-f_mobile.png" class="lazy" data-srcset="https://searchcloudsecurity.techtarget.com/rms/onlineImages/security-sample_ciam_arch_external_providers-f_mobile.png 960w,https://searchcloudsecurity.techtarget.com/rms/onlineImages/security-sample_ciam_arch_external_providers-f.png 1280w" alt="Illustration of a CIAM architecture using external providers." height="367" width="558"&gt;
  &lt;figcaption&gt;
   &lt;i class="icon pictures" data-icon="z"&gt;&lt;/i&gt;Figure 2. Sample CIAM application using cloud tools
  &lt;/figcaption&gt;
  &lt;div class="main-article-image-enlarge"&gt;
   &lt;i class="icon" data-icon="w"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/figure&gt;
 &lt;p&gt;This approach, while using the same logical elements -- directory, policy enforcement points, policy decision points -- as the legacy on-premises model, employs them for a different purpose.&lt;/p&gt;
 &lt;p&gt;Despite how placid the waters of IAM might seem on the surface though, IAM has become more complicated than it used to be. Consider how innovations affect identity. With cloud transformation, for example, we've seen new IAM strategies emerge, from IDaaS to authentication as a service to native identity systems offered inside cloud environments. Likewise, service-oriented architectures have changed IAM as well, including the creation and rapid adoption of an entirely new authentication state transfer mechanism, &lt;a href="https://www.techtarget.com/searchapparchitecture/definition/OAuth"&gt;OAuth&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;Looking ahead, there's more transformation on the horizon. &lt;a href="https://www.techtarget.com/searchitoperations/definition/Infrastructure-as-Code-IAC"&gt;Infrastructure as code&lt;/a&gt; is transforming IAM workflows by enabling users to, for example, codify role assignments and IAM policies and permissions. At the same time, Kubernetes is introducing new IAM support structures, such as Kubernetes RBAC and service account management, and requiring adaptation of existing IAM to account for ephemeral instances and other orchestration-specific artifacts. That's just two examples of many; add to the mix continued proliferation of machine identities, &lt;a href="https://www.techtarget.com/searchsecurity/definition/passwordless-authentication"&gt;passwordless authentication&lt;/a&gt; and policy as code, and you have a landscape that is still very much in transition.&lt;/p&gt;
 &lt;p&gt;&lt;em&gt;Ed Moyle is a technical writer with more than 25 years of experience in information security. He is a partner at SecurityCurve, a consulting, research and education company.&lt;/em&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Identity and access management is changing and so must strategies for managing it. Read up on IAM architecture approaches and how to select the best for your organization.</description>
            <image>https://cdn.ttgtmedia.com/visuals/German/article/identity-anonymous-security-adobe.png</image>
            <link>https://www.techtarget.com/cybersecurity/feature/How-to-build-an-effective-IAM-architecture</link>
            <pubDate>Fri, 21 Feb 2025 00:00:00 GMT</pubDate>
            <title>How to build an effective IAM architecture</title>
        </item>
        <item>
            <body>&lt;p&gt;Just as washing your hands and brushing your teeth are important to personal hygiene, password updates and software patches are important to cybersecurity hygiene -- and critical to preventing data loss, breaches and identity theft.&lt;/p&gt; 
&lt;p&gt;It is important to note that cybersecurity hygiene is a shared responsibility -- it is not an activity solely for employees. Organizations and security teams, among other departments, must all play their parts.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Standard cybersecurity hygiene checklist"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Standard cybersecurity hygiene checklist&lt;/h2&gt;
 &lt;p&gt;The following practices should be woven into any cybersecurity hygiene checklist:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Patch, patch, patch. Keep company-owned devices &lt;a href="https://www.techtarget.com/searchsecurity/tip/5-enterprise-patch-management-best-practices"&gt;patched&lt;/a&gt; and up to date with the latest software versions. Unpatched vulnerabilities are an especially inviting entry point for cybercriminals. A &lt;a href="https://www.sophos.com/en-us/content/state-of-ransomware" target="_blank" rel="noopener"&gt;survey&lt;/a&gt; published by Sophos in 2024 found that 32% of ransomware attacks began with exactly that kind of vulnerability.&lt;/li&gt; 
  &lt;li&gt;Have a strong identity and access management program that does the following:&lt;/li&gt; 
  &lt;ul type="circle" class="default-list"&gt; 
   &lt;li&gt;Requires &lt;a href="https://www.techtarget.com/searchsecurity/tip/Top-5-password-hygiene-tips-and-best-practices"&gt;strong passwords&lt;/a&gt;.&lt;/li&gt; 
   &lt;li&gt;Uses &lt;a href="https://www.techtarget.com/searchsecurity/definition/multifactor-authentication-MFA"&gt;multifactor authentication&lt;/a&gt;.&lt;/li&gt; 
   &lt;li&gt;Prohibits credential reuse.&lt;/li&gt; 
   &lt;li&gt;Offers biometrics use.&lt;/li&gt; 
   &lt;li&gt;Employs the &lt;a href="https://www.techtarget.com/searchsecurity/definition/principle-of-least-privilege-POLP"&gt;principle of least privilege&lt;/a&gt;.&lt;/li&gt; 
  &lt;/ul&gt; 
  &lt;li&gt;Don't share credentials.&lt;/li&gt; 
  &lt;li&gt;Don't use public Wi-Fi.&lt;/li&gt; 
  &lt;li&gt;Segment networks.&lt;/li&gt; 
  &lt;li&gt;Manage and secure endpoints.&lt;/li&gt; 
  &lt;li&gt;Install antimalware and firewalls.&lt;/li&gt; 
  &lt;li&gt;Encrypt drives and devices by default.&lt;/li&gt; 
  &lt;li&gt;Perform regular data backups.&lt;/li&gt; 
  &lt;li&gt;Conduct and participate in &lt;a href="https://www.techtarget.com/searchsecurity/definition/security-awareness-training"&gt;security awareness training&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;Avoid social engineering scams.&lt;/li&gt; 
  &lt;li&gt;Perform asset discovery, inventory and management.&lt;/li&gt; 
  &lt;li&gt;Create, implement and maintain enterprise security policies.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Special considerations: Bring your own home cybersecurity hygiene"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Special considerations: Bring your own home cybersecurity hygiene&lt;/h2&gt;
 &lt;p&gt;In a new era of remote and hybrid work, organizations have had to grapple with how to keep corporate assets safe -- whether employees are working in the office or from home.&lt;/p&gt;
 &lt;p&gt;To avoid common &lt;a href="https://www.techtarget.com/searchsecurity/tip/Remote-work-cybersecurity-12-risks-and-how-to-prevent-them"&gt;remote and hybrid employee security issues&lt;/a&gt;, follow these security best practices:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;VPNs everywhere.&lt;/b&gt; Most enterprises have a VPN enabled by default for access to the corporate network. But, even in the absence of that, employees would do well to install a VPN client that enables encrypted connections to strengthen public Wi-Fi or poorly secured home connections. Companies should also be aware of VPNs that don't work in certain geographies. TunnelBear, for example, stopped doing business in India in 2022 and is no longer available in India because the company declined to comply with new government regulations. To further strengthen access controls, companies should consider adopting the &lt;a href="https://www.techtarget.com/searchsecurity/definition/zero-trust-model-zero-trust-network"&gt;zero-trust model&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Patch, patch, patch.&lt;/b&gt; Patching and updating company-owned devices have already been mentioned, but it's also critical end users understand the importance of patching their own devices -- especially as more and more workers use their own devices for work purposes. The patching of hidden devices, such as a smart microwave or thermostat, should also be periodically reviewed as smart home devices could be the source of lateral compromise on an enterprise.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Special considerations: Cloud cybersecurity hygiene"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Special considerations: Cloud cybersecurity hygiene&lt;/h2&gt;
 &lt;p&gt;While cloud computing helps improve productivity, accessibility and scalability, risks from a security perspective inevitably follow.&lt;/p&gt;
 &lt;p&gt;To keep employees and employers safe in the cloud, follow these key cloud cybersecurity hygiene best practices:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Create a &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-create-a-cloud-security-policy-step-by-step"&gt;cloud usage and security policy&lt;/a&gt;. Spell out the dos and don'ts of what is accepted cloud use and what is not. For instance, an enterprise might use Microsoft's OneDrive for document sharing, but certain users might prefer services from Google Drive or Box. Admins should acknowledge the importance of user preference but take a stance on cloud app use that aligns with the organization's &lt;a href="https://www.techtarget.com/searchsecurity/tip/5-ways-to-achieve-a-risk-based-security-strategy"&gt;risk-based security strategy&lt;/a&gt;. They should also provide short, engaging training on how to use the cloud for secure data sharing.&lt;/li&gt; 
  &lt;li&gt;Be mindful when giving document and shared folder access rights to co-workers, partners, etc.&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.techtarget.com/searchsecurity/answer/How-to-conduct-a-periodic-user-access-review-for-account-privileges"&gt;Revoke and delete permissions where appropriate&lt;/a&gt; and when disengagement happens -- for example, at project conclusion or employee resignation. When &lt;a href="https://www.techtarget.com/searchsecurity/tip/User-provisioning-and-deprovisioning-Why-it-matters-for-IAM"&gt;user provisioning and deprovisioning&lt;/a&gt; aren't handled carefully, an organization creates the types of overprivileged and orphaned user identities that cybercriminals so often exploit.&lt;/li&gt; 
  &lt;li&gt;Be mindful of account cross-pollination. Consider, for example, how many Google accounts many employees likely have. Making sure each uses the correct Google Drive account -- one for work purposes -- is critical to data security. Likewise, don't use a work Dropbox account to share family photos.&lt;/li&gt; 
  &lt;li&gt;Exercise privacy and confidentiality rights. While not top of mind for most individuals, these are top priorities for corporations. Legislation, such as GDPR and CCPA, call out specific privacy rights. For example, it is critical to ensure digital trails are obliterated when SaaS applications are no longer in use or to conduct periodic reviews of data collected by enterprise SaaS applications. These tasks require training and innovative incentives, such as &lt;a href="https://www.techtarget.com/searchsecurity/quiz/Quiz-Security-awareness-for-end-users"&gt;security gamification&lt;/a&gt;, to raise awareness among employees.&lt;/li&gt; 
  &lt;li&gt;Include cloud security in enterprise security awareness training sessions. If a public data store breach occurs, use it as an example to drive home the message of how it could have been avoided.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;&lt;i&gt;Ashwin Krishnan is the host and producer of StandOutIn90Sec, based in California. where he interviews tech leaders, employees and event speakers in short, high-impact conversations.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Enterprise cybersecurity hygiene must be a shared responsibility between employees and employers. Learn how both can get the job done with this checklist.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/check_g1268128622.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/tip/Enterprise-cybersecurity-hygiene-checklist-for-2025</link>
            <pubDate>Tue, 07 Jan 2025 09:00:00 GMT</pubDate>
            <title>Enterprise cybersecurity hygiene checklist for 2025</title>
        </item>
        <item>
            <body>&lt;p&gt;Many professionals seeking a career in cloud security turn to certifications to advance their learning and prove their knowledge to potential employers. The number of cloud security certifications has increased in recent years, however, making it difficult for students and practitioners to decide which ones to pursue.&lt;/p&gt; 
&lt;p&gt;Are you trying to parse the differences and figure out which certifications will most advance your knowledge and career? Get the lowdown on the best cloud security certifications here.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="The importance of certifications"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The importance of certifications&lt;/h2&gt;
 &lt;p&gt;Although the debate over the &lt;a href="https://www.techtarget.com/searchcio/feature/Tech-pros-favor-cybersecurity-AI-certifications"&gt;value of security certification programs&lt;/a&gt; is hotly contested, they are still one of the top ways employers screen job candidates and assess an interviewee's baseline knowledge. And the fact is that most certifications deliver more significant benefits to professionals than traditional self-study options.&lt;/p&gt;
 &lt;p&gt;A certification, for instance, covers broader topics than those of interest to the student, which requires learning more than just the minimum around a specific topic. Skipping a few dull but important chapters isn't a wise decision if an expensive exam is coming up.&lt;/p&gt;
 &lt;p&gt;Certification exams also force students to study the material, not just skim it. Exam dates provide a deadline to finish the material. Certificates also show employers that future employees have put significant time and money into obtaining the certificates and their associated skills.&lt;/p&gt;
 &lt;p&gt;The infosec industry has been around for decades and has some of the best-known certifications. ISC2's CISSP, for instance, was released in 1994, and ISACA's Certified Information Systems Auditor (CISA) certification dates to 1978.&lt;/p&gt;
 &lt;p&gt;These older, well-established certification providers have added cloud components to their material, but the depth of those add-ons can be limited -- sometimes, just a few pages in a book. Considering the importance of cloud technologies and the &lt;a href="https://www.techtarget.com/searchsecurity/tip/Top-11-cloud-security-challenges-and-how-to-combat-them"&gt;persistent threat of cloud-specific attacks&lt;/a&gt;, more focus is required.&lt;/p&gt;
 &lt;p&gt;Let's look at some certification providers that have introduced dedicated, in-depth cloud security certifications, as well as what cloud security pros can expect when pursuing them.&lt;/p&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="1. ISC2 Certified Cloud Security Professional (CCSP)"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;1. ISC2 Certified Cloud Security Professional (CCSP)&lt;/h2&gt;
 &lt;p&gt;The most well-known and established cloud security certification is ISC2's CCSP. Although ISC2's CISSP now contains more cloud material than in years past, the nonprofit's specialized CCSP &lt;a target="_blank" href="https://www.isc2.org/Certifications/CCSP" rel="noopener"&gt;program&lt;/a&gt; takes it to the next level and covers a broad range of cloud-related topics, from cloud application security to cloud platform security.&lt;/p&gt;
 &lt;p&gt;Students should expect to invest quite a bit of time to pass this exam; self-led or instructor-led training should be used to prepare for this certification.&lt;/p&gt;
 &lt;p&gt;Candidates must have a minimum of five years of paid work experience in IT before becoming certified. Three years must be in infosec, and one year must be in one or more of the six domains included in the CCSP Common Body of Knowledge (CBK):&lt;/p&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;Cloud Concepts, Architecture and Design (17% of exam).&lt;/li&gt; 
  &lt;li&gt;Cloud Data Security (20%).&lt;/li&gt; 
  &lt;li&gt;Cloud Platform &amp;amp; Infrastructure Security (17%).&lt;/li&gt; 
  &lt;li&gt;Cloud Application Security (17%).&lt;/li&gt; 
  &lt;li&gt;Cloud Security Operations (16%).&lt;/li&gt; 
  &lt;li&gt;Legal, Risk and Compliance (13%).&lt;/li&gt; 
 &lt;/ol&gt;
 &lt;p&gt;Cloud Security Alliance (CSA) Certificate of Cloud Security Knowledge can be substituted for one year of experience in one or more of the CCSP domains. Obtaining CISSP covers all prerequisites.&lt;/p&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="2. CSA Certificate of Cloud Security Knowledge (CCSK)"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;2. CSA Certificate of Cloud Security Knowledge (CCSK)&lt;/h2&gt;
 &lt;p&gt;CSA's CCSK is a lighter alternative to CCSP certification. Launched in 2010, this &lt;a target="_blank" href="https://cloudsecurityalliance.org/education/ccsk/" rel="noopener"&gt;certificate&lt;/a&gt; is dedicated to cloud security. Like CCSP, CCSK goes into technical details.&lt;/p&gt;
 &lt;p&gt;CCSK is a good alternative cloud security certification for an entry-level to midrange security professional with an interest in cloud data security.&lt;/p&gt;
 &lt;p&gt;Those studying for their CCSK can use the CSA's free Prep Kit to study and prepare for the exam. The kit includes an overview of the certificate, study and knowledge guides, a course outline, sample questions and additional resources.&lt;/p&gt;
 &lt;p&gt;CCSK v5 covers 12 domains, including Cloud Computing Concepts and Architecture, Infrastructure and Networking, Data Security and Security as a Service.&lt;/p&gt;
 &lt;p&gt;The CCSK v5 exam bundle can be purchased online. Training options include online self-paced, online instructor-led and in-person instruction.&lt;/p&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="3. ISACA and CSA Certificate of Cloud Auditing Knowledge (CCAK)"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;3. ISACA and CSA Certificate of Cloud Auditing Knowledge (CCAK)&lt;/h2&gt;
 &lt;p&gt;In March 2021, ISACA and CSA jointly released CCAK, which &lt;a target="_blank" href="https://cloudsecurityalliance.org/education/ccak/" rel="noopener"&gt;builds on&lt;/a&gt; and complements CCSK content. It also complements ISACA's CISA and Certified Information Security Manager certifications. Applicants are advised to achieve their CCSK prior to taking CCAK, though it is not a prerequisite.&lt;/p&gt;
 &lt;p&gt;Assessors and auditors, compliance managers, vendor and partner program managers, security and privacy consultants, security analysts and architects could benefit from the training, which covers the following domains:&lt;/p&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;Cloud Governance.&lt;/li&gt; 
  &lt;li&gt;Cloud Compliance Program.&lt;/li&gt; 
  &lt;li&gt;CCM and CAIQ: Goals, Objectives and Structure.&lt;/li&gt; 
  &lt;li&gt;A Threat Analysis Methodology for Cloud Using CCM.&lt;/li&gt; 
  &lt;li&gt;Evaluating a Cloud Compliance Program.&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.techtarget.com/searchcloudcomputing/definition/cloud-audit"&gt;Cloud Auditing&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;CCM: Auditing Controls.&lt;/li&gt; 
  &lt;li&gt;Continuous Assurance and Compliance.&lt;/li&gt; 
  &lt;li&gt;STAR Program.&lt;/li&gt; 
 &lt;/ol&gt;
 &lt;p&gt;Candidates can choose online self-paced, online instructor-led and in-person training.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="4. GIAC Cloud Security Automation (GCSA)"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;4. GIAC Cloud Security Automation (GCSA)&lt;/h2&gt;
 &lt;p&gt;Launched in April 2020, GIAC's GCSA certification is specifically &lt;a target="_blank" href="https://www.giac.org/certification/cloud-security-automation-gcsa" rel="noopener"&gt;designed&lt;/a&gt; for developers, analysts and engineers working to secure cloud and DevOps environments. It encompasses topics such as DevOps and DevSecOps fundamentals; securing cloud architecture; data and secrets protection and compliance; and security and automation related to deployment, runtime and content delivery.&lt;/p&gt;
 &lt;p&gt;The GIAC certification is affiliated with SANS Institute's in-person or online "SEC540: Cloud Security and DevSecOps Automation" course. The SEC540 five-day &lt;a target="_blank" href="https://www.sans.org/cyber-security-courses/cloud-security-devsecops-automation/" rel="noopener"&gt;course&lt;/a&gt;, which includes hands-on labs, covers topics in the following five sections:&lt;/p&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;DevOps Security Automation.&lt;/li&gt; 
  &lt;li&gt;Cloud Infrastructure Security.&lt;/li&gt; 
  &lt;li&gt;Cloud Native Security Operations.&lt;/li&gt; 
  &lt;li&gt;Microservice and Serverless Security.&lt;/li&gt; 
  &lt;li&gt;Continuous Compliance and Protection.&lt;/li&gt; 
 &lt;/ol&gt;
 &lt;p&gt;The GIAC certification exam can be purchased by itself or at a discounted rate when bought in conjunction with the SANS training. Purchasing a certification attempt comes with practice tests, which are in the same format as the exam.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="5. GIAC Cloud Security Essentials (GCLD)"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;5. GIAC Cloud Security Essentials (GCLD)&lt;/h2&gt;
 &lt;p&gt;Released in April 2021, GIAC's GCLD covers how to evaluate cloud service providers and how to plan, deploy and secure single and multi-cloud environments, as well as topics such as cloud auditing, security assessments and incident response.&lt;/p&gt;
 &lt;p&gt;Specialized for security engineers, analysts, managers and auditors, GCLD &lt;a target="_blank" href="https://www.giac.org/certifications/cloud-security-essentials-gcld/" rel="noopener"&gt;aims to help&lt;/a&gt; candidates prove their knowledge about how to prevent, detect and react to cloud workload security events.&lt;/p&gt;
 &lt;p&gt;GCLD certification is affiliated with "SEC488: Cloud Security Essentials," a &lt;a target="_blank" href="https://www.sans.org/cyber-security-courses/cloud-security-essentials/" rel="noopener"&gt;six-day course&lt;/a&gt; with hands-on training that teaches the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Identity and Access Management (IAM).&lt;/li&gt; 
  &lt;li&gt;Compute and Configuration Management.&lt;/li&gt; 
  &lt;li&gt;Data Protection.&lt;/li&gt; 
  &lt;li&gt;Networking and Detection.&lt;/li&gt; 
  &lt;li&gt;Compliance, Incident Response and Penetration Testing.&lt;/li&gt; 
  &lt;li&gt;CloudWars.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;The SANS training, offered online and in person, has no prerequisites, but a basic understanding of networking, security, Linux and the cloud is beneficial.&lt;/p&gt;
 &lt;p&gt;GIAC also offers specialized certifications that could apply depending on the candidate's career path. These include the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;a target="_blank" href="https://www.giac.org/certifications/certified-web-application-defender-gweb/" rel="noopener"&gt;GIAC Certified Web Application Defender&lt;/a&gt;, affiliated with "&lt;a target="_blank" href="https://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices/" rel="noopener"&gt;SEC522&lt;/a&gt;: Application Security: Securing Web Apps, APIs and Microservices."&lt;/li&gt; 
  &lt;li&gt;&lt;a target="_blank" href="https://www.giac.org/certifications/public-cloud-security-gpcs/" rel="noopener"&gt;GIAC Public Cloud Security&lt;/a&gt;, affiliated with "&lt;a target="_blank" href="https://www.sans.org/cyber-security-courses/public-cloud-security-aws-azure-gcp/" rel="noopener"&gt;SEC510&lt;/a&gt;: Cloud Security Controls and Mitigations."&lt;/li&gt; 
  &lt;li&gt;&lt;a target="_blank" href="https://www.giac.org/certifications/cloud-penetration-tester-gcpn/" rel="noopener"&gt;GIAC Cloud Penetration Tester&lt;/a&gt;, affiliated with "&lt;a target="_blank" href="https://www.sans.org/cyber-security-courses/cloud-penetration-testing/" rel="noopener"&gt;SEC588&lt;/a&gt;: Cloud Penetration Testing."&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;        
&lt;section class="section main-article-chapter" data-menu-title="6. Mile2 Certified Cloud Security Officer (C)CSO)"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;6. Mile2 Certified Cloud Security Officer (C)CSO)&lt;/h2&gt;
 &lt;p&gt;The C)CSO certification from Mile2 consists of a five-day program that includes instructor-led sessions, self-study time and live virtual trainings. It is &lt;a target="_blank" href="https://www.mile2.com/ccso_outline/" rel="noopener"&gt;composed&lt;/a&gt; of 15 modules:&lt;/p&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;Introduction to Cloud Computing and Architecture.&lt;/li&gt; 
  &lt;li&gt;Cloud Security Risks.&lt;/li&gt; 
  &lt;li&gt;ERM and Governance.&lt;/li&gt; 
  &lt;li&gt;Legal Issues.&lt;/li&gt; 
  &lt;li&gt;Virtualization.&lt;/li&gt; 
  &lt;li&gt;Data Security.&lt;/li&gt; 
  &lt;li&gt;Data Center Operations.&lt;/li&gt; 
  &lt;li&gt;Interoperability and Portability.&lt;/li&gt; 
  &lt;li&gt;Traditional Security.&lt;/li&gt; 
  &lt;li&gt;BCM and DR.&lt;/li&gt; 
  &lt;li&gt;Incident Response.&lt;/li&gt; 
  &lt;li&gt;Application Security.&lt;/li&gt; 
  &lt;li&gt;Encryption and Key Management.&lt;/li&gt; 
  &lt;li&gt;Identity, Entitlement and Access Management.&lt;/li&gt; 
  &lt;li&gt;Auditing and Compliance.&lt;/li&gt; 
 &lt;/ol&gt;
 &lt;p&gt;It also consists of 23 labs, including PaaS in Azure and Encryption/Key Management in SaaS.&lt;/p&gt;
 &lt;p&gt;Part of Mile2's Cloud Security and Virtualization career path, this advanced certification is ideal for professionals seeking careers in virtualization, cloud administration, auditing and compliance.&lt;/p&gt;
 &lt;p&gt;General knowledge of cloud architectures and one year of experience in both virtualization and infosec are recommended.&lt;/p&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="7. Arcitura Certified Cloud Security Specialist"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;7. Arcitura Certified Cloud Security Specialist&lt;/h2&gt;
 &lt;p&gt;Arcitura's Certified Cloud Security Specialist certification &lt;a target="_blank" href="https://www.arcitura.com/cert/cloud-security-specialist-certification-exam.html" rel="noopener"&gt;focuses&lt;/a&gt; on the security threats associated with cloud platforms, cloud services and other cloud technologies, including virtualization. Geared toward IT and security professionals, as well as cloud architects, the Certified Cloud Security Specialist certification is composed of the following five modules:&lt;/p&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;Fundamental Cloud Computing covers basic cloud technology topics such as cloud computing platforms, cost metrics and service-level agreement characteristics.&lt;/li&gt; 
  &lt;li&gt;Cloud Technology Concepts covers topics such as cloud service architecture and containerization.&lt;/li&gt; 
  &lt;li&gt;Fundamental Cloud Security contains training on cloud security mechanisms and threats, cloud auditing and cloud IAM.&lt;/li&gt; 
  &lt;li&gt;Advanced Cloud Security offers training on attack lifecycles, threat modeling and VM protection.&lt;/li&gt; 
  &lt;li&gt;Cloud Security Lab includes exercises on IAM in the cloud, public key infrastructure in the cloud, and cloud encryption and key management.&lt;/li&gt; 
 &lt;/ol&gt;
 &lt;p&gt;The approximately 50-hour training course culminates with the Cloud Security Specialist exam and certification. A general background in IT is recommended.&lt;/p&gt;
 &lt;figure class="main-article-image full-col" data-img-fullsize="https://www.techtarget.com/rms/onlineimages/best_cloud_security_certifications-f.png"&gt;
  &lt;img data-src="https://www.techtarget.com/rms/onlineimages/best_cloud_security_certifications-f_mobile.png" class="lazy" data-srcset="https://www.techtarget.com/rms/onlineimages/best_cloud_security_certifications-f_mobile.png 960w,https://www.techtarget.com/rms/onlineimages/best_cloud_security_certifications-f.png 1280w" alt="Chart comparing cloud security certifications and exams." height="770" width="560"&gt;
  &lt;figcaption&gt;
   &lt;i class="icon pictures" data-icon="z"&gt;&lt;/i&gt;Use this chart to compare the top cloud security certifications.
  &lt;/figcaption&gt;
  &lt;div class="main-article-image-enlarge"&gt;
   &lt;i class="icon" data-icon="w"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/figure&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="8. and 9. CompTIA Cloud Essentials+ and Cloud+"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;8. and 9. CompTIA Cloud Essentials+ and Cloud+&lt;/h2&gt;
 &lt;p&gt;CompTIA offers two certifications that, while not security-specific, cover cloud security topics. &lt;a target="_blank" href="https://www.comptia.org/certifications/cloud-essentials" rel="noopener"&gt;Cloud Essentials+&lt;/a&gt; is geared toward cloud business decision-making, while &lt;a target="_blank" href="https://www.comptia.org/certifications/cloud" rel="noopener"&gt;Cloud+&lt;/a&gt; is more about technical cloud implementation.&lt;/p&gt;
 &lt;p&gt;The entry-level Cloud Essentials+ certification covers cloud security concerns and measures, as well as risk assessment, cloud security policies and compliance. Six months to one year of IT business analyst experience, along with some cloud technology experience, is recommended. The more in-depth Cloud+ certification covers security configurations, access control, key and certificate management, and segmentation and microsegmentation. Two to three years of system administration or networking experience are recommended, in addition to CompTIA Network+ and Server+ certifications.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="10. Vendor-specific cloud security certifications"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;10. Vendor-specific cloud security certifications&lt;/h2&gt;
 &lt;p&gt;Because many enterprises work with specific vendors and technologies, it could be fruitful for their security team members to hold certifications in those areas. Some cloud platform providers offer practical product training, including the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;a target="_blank" href="https://aws.amazon.com/certification/certified-security-specialty/" rel="noopener"&gt;AWS Certified Security - Specialty&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;&lt;a target="_blank" href="https://cloud.google.com/certification/cloud-security-engineer" rel="noopener"&gt;Google Professional Cloud Security Engineer&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;&lt;a target="_blank" href="https://www.ibm.com/training/certification/ibm-cloud-security-engineer-v1-specialty-S0011100" rel="noopener"&gt;IBM Cloud Security Engineer Specialty&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;&lt;a target="_blank" href="https://training.linuxfoundation.org/certification/certified-kubernetes-security-specialist/" rel="noopener"&gt;Certified Kubernetes Security Specialist&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://learn.microsoft.com/en-us/credentials/certifications/azure-security-engineer/?practice-assessment-type=certification" target="_blank" rel="noopener"&gt;Microsoft Certified: Azure Security Engineer Associate.&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a target="_blank" href="https://www.vmware.com/learning/certification/vcta-security.html" rel="noopener"&gt;VMware Certified Technical Associate - Security&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;&lt;a target="_blank" href="https://www.vmware.com/learning/certification/vcp-ews.html" rel="noopener"&gt;VMware Certified Professional - Endpoint and Workload Security&lt;/a&gt;.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;&lt;b&gt;Editor's note:&lt;/b&gt; &lt;i&gt;This article was revised in December 2024 to&lt;/i&gt; &lt;i&gt;update certification information and to improve the reader experience.&lt;/i&gt;&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Sharon Shea is executive editor of TechTarget Security.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Certifications can help security pros prove their baseline knowledge of infosec topics. Consider adding these top cloud security certifications to your arsenal.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/certification_g483411626.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/tip/The-10-best-cloud-security-certifications-for-IT-pros-in-2025</link>
            <pubDate>Tue, 17 Dec 2024 00:00:00 GMT</pubDate>
            <title>The 10 best cloud security certifications for IT pros in 2025</title>
        </item>
        <item>
            <body>&lt;p&gt;Managing cyberthreats is one of the most important activities for organizations today. Fortunately, many different techniques and technologies are available to reduce the risk of cyberattacks. The following three widely used approaches are used to identify, assess, manage and resolve threats so that organizations can resume operations:&lt;/p&gt; 
&lt;ul class="default-list"&gt; 
 &lt;li&gt;&lt;b&gt;Security information and event management.&lt;/b&gt; &lt;a href="https://www.techtarget.com/searchsecurity/definition/security-information-and-event-management-SIEM"&gt;SIEM&lt;/a&gt;&lt;b&gt; &lt;/b&gt;collects event log data, analyzes the data to identify suspicious activity and generates visibility to the event so that remedial initiatives can be launched.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Security orchestration, automation and response.&lt;/b&gt; &lt;a href="https://www.techtarget.com/searchsecurity/definition/SOAR"&gt;SOAR&lt;/a&gt; automatically analyzes data on an event and orchestrates the response so that security operations center (&lt;a href="https://www.techtarget.com/searchsecurity/definition/Security-Operations-Center-SOC"&gt;SOC&lt;/a&gt;) teams can resolve events more quickly.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Extended detection and response.&lt;/b&gt; &lt;a href="https://www.techtarget.com/searchsecurity/definition/extended-detection-and-response-XDR"&gt;XDR&lt;/a&gt; provides threat hunting, identification of false positives and the creation of threat intelligence.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;SIEM, SOAR and XDR technologies are all used to detect and resolve security events. SIEM gathers data and analyzes security incidents; SOAR, which handles automated incident responses, uses information from SIEM to fulfill its functions. XDR, though, may use SIEM data but it's an all-inclusive product that handles security events end to end.&lt;/p&gt; 
&lt;p&gt;This article compares and contrasts each technology and offers guidance on which approach(es) to use for comprehensive cybersecurity management.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="What is SIEM?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What is SIEM?&lt;/h2&gt;
 &lt;p&gt;SIEM builds on two fundamental elements: security information management and security event management. One of the important functions of SIEM is to help cybersecurity teams achieve compliance with key security standards and regulations. &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-AI-could-change-threat-detection"&gt;AI enhances SIEM capabilities&lt;/a&gt; by providing greater analytical capabilities for identifying suspected or actual cyberincidents. SIEM also facilitates the launch of security incident response activities.&lt;/p&gt;
 &lt;p&gt;A key activity of SIEM tools is the collection of security event data for current and future analysis. Each tool has rules for how events are analyzed and can evaluate threats by comparing them with a large database of previous cyberattacks.&lt;/p&gt;
 &lt;p&gt;The principal output from a SIEM system is intelligence regarding a security event that can be used to formulate and launch a suitable response, mitigation and recovery. Integrated dashboards provide real-time displays of cyberattack data for launching incident responses and establishing priorities for event response activities.&lt;/p&gt;
 &lt;div class="youtube-iframe-container"&gt;
  &lt;iframe id="ytplayer-0" src="https://www.youtube.com/embed/1SVlUJ1lk5I?autoplay=0&amp;amp;modestbranding=1&amp;amp;rel=0&amp;amp;widget_referrer=null&amp;amp;enablejsapi=1&amp;amp;origin=https://searchcloudsecurity.techtarget.com" type="text/html" height="360" width="640" frameborder="0"&gt;&lt;/iframe&gt;
 &lt;/div&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="What is SOAR?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What is SOAR?&lt;/h2&gt;
 &lt;p&gt;Automation of cyberattack response activities is one of the principal activities of a SOAR system. The addition of SOAR technology in SOCs greatly improves the efficiency of cybersecurity teams. While they may be focusing on a variety of security issues, the SOAR system is actively addressing identified security breaches, providing real-time data on how the mitigation is going. It also supports &lt;a href="https://www.techtarget.com/searchsecurity/tip/What-is-threat-hunting-Key-strategies-explained"&gt;threat hunting&lt;/a&gt;, identification of false positives and the creation of &lt;a href="https://www.techtarget.com/whatis/definition/threat-intelligence-cyber-threat-intelligence"&gt;threat intelligence&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;The orchestration element gathers all relevant security tools and centrally manages them, which greatly increases the efficiency of event responses. It typically provides the starting point for launching the automation elements that actively go out and address the incident. The automation element uses numerous playbooks and other response tools to deliver the most effective response.&lt;/p&gt;
 &lt;p&gt;AI is also increasingly part of SOAR capabilities, as it can streamline the process of evaluating and selecting the best set of responses for a specific event.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="What is XDR?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What is XDR?&lt;/h2&gt;
 &lt;p&gt;Considering the complex environment in use by IT organizations today, various platforms and services -- particularly cloud, multi-cloud and hybrid environments -- are in use. They provide a full scope of detection, analysis and response capabilities that range from office endpoint devices and networks to &lt;a href="https://www.techtarget.com/searchnetworking/definition/WAN-wide-area-network"&gt;WAN&lt;/a&gt; environments and multiple offices within the IT ecosystem. AI is typically a key component in an XDR platform. XDR systems are quickly becoming a go-to solution for cybersecurity organizations and SOCs.&lt;/p&gt;
 &lt;p&gt;Similar to SOAR technology, XDR systems perform what may be considered a complete suite of cybersecurity prevention, detection, analysis and response activities. XDR can initiate automated incident response activities and provide end-to-end automated management of all detection, response and mitigation activities. It can also provide return-to-service activities that not only eliminate suspicious code, but also return systems to normal operations.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Key differences among SIEM vs. SOAR vs. XDR"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Key differences among SIEM vs. SOAR vs. XDR&lt;/h2&gt;
 &lt;p&gt;Each of the three solutions described in this article contributes to the detection and resolution of security events. They differ in their various activities yet can also complement each other in the right configuration. The inclusion of AI capabilities greatly increases the usability of each approach and is likely to be a major component of systems into the latter part of the decade.&lt;/p&gt;
 &lt;figure class="main-article-image full-col" data-img-fullsize="https://searchcloudsecurity.techtarget.com/rms/onlineimages/how_siem_soar_xdr_work_together-f.png"&gt;
  &lt;img data-src="https://searchcloudsecurity.techtarget.com/rms/onlineimages/how_siem_soar_xdr_work_together-f_mobile.png" class="lazy" data-srcset="https://searchcloudsecurity.techtarget.com/rms/onlineimages/how_siem_soar_xdr_work_together-f_mobile.png 960w,https://searchcloudsecurity.techtarget.com/rms/onlineimages/how_siem_soar_xdr_work_together-f.png 1280w" alt="SIEM, SOAR, XDR, incident response tools" height="314" width="560"&gt;
  &lt;figcaption&gt;
   &lt;i class="icon pictures" data-icon="z"&gt;&lt;/i&gt;How SIEM, SOAR and XDR respond to security events and complement one another
  &lt;/figcaption&gt;
  &lt;div class="main-article-image-enlarge"&gt;
   &lt;i class="icon" data-icon="w"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/figure&gt;
 &lt;p&gt;In practice, SIEM and SOAR tools complement each other, and XDR is a standalone product. However, the three tools &lt;i&gt;can&lt;/i&gt; complement one another. SIEM gathers and analyzes event data, helps facilitate incident responses and provides data needed by SOAR to launch the automated response. Working together, they provide a solid end-to-end means for managing security breaches.&lt;/p&gt;
 &lt;p&gt;XDR is a newer, more powerful and all-inclusive solution for end-to-end security event management. But, when preparing for an automated response, it also uses the data that SIEM captures. It may share data with SOAR, but SIEM has the more complementary relationship. XDR's ability to address issues occurring in internal endpoints, as well as distant offices, cloud environments, multiple websites and complex networks, makes it an important go-to solution for SOC teams.&lt;/p&gt;
 &lt;p&gt;The inclusion of AI capabilities in each approach greatly increases their overall value to cybersecurity teams and SOCs.&lt;/p&gt;
 &lt;figure class="main-article-image full-col" data-img-fullsize="https://searchcloudsecurity.techtarget.com/rms/onlineimages/siem_soar_xdr_how_they_compare-f.png"&gt;
  &lt;img data-src="https://searchcloudsecurity.techtarget.com/rms/onlineimages/siem_soar_xdr_how_they_compare-f_mobile.png" class="lazy" data-srcset="https://searchcloudsecurity.techtarget.com/rms/onlineimages/siem_soar_xdr_how_they_compare-f_mobile.png 960w,https://searchcloudsecurity.techtarget.com/rms/onlineimages/siem_soar_xdr_how_they_compare-f.png 1280w" alt="chart compares SIEM, SOAR, XDR" height="258" width="560"&gt;
  &lt;figcaption&gt;
   &lt;i class="icon pictures" data-icon="z"&gt;&lt;/i&gt;The features and capabilities of SIEM, SOAR and XDR
  &lt;/figcaption&gt;
  &lt;div class="main-article-image-enlarge"&gt;
   &lt;i class="icon" data-icon="w"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/figure&gt;
 &lt;p&gt;Each option offers many benefits and supports cybersecurity teams and SOCs. And, because each system, properly configured, can automate the security event management process, SOC efficiency and productivity are increased.&lt;/p&gt;
&lt;/section&gt;        
&lt;section class="section main-article-chapter" data-menu-title="10 steps to select tools"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;10 steps to select tools&lt;/h2&gt;
 &lt;p&gt;As noted earlier, the complementary nature of SIEM and SOAR systems means they are often paired. XDR may be a standalone solution, but combining the capabilities of all three tools makes good sense.&lt;/p&gt;
 &lt;p&gt;Consider the following steps when selecting your tools:&lt;/p&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Review and update your cybersecurity management requirements.&lt;/b&gt; Most organizations probably have some form of cybersecurity management and maybe a SOC, so the first step is to review security requirements in light of business needs and threat intelligence.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Examine current security systems.&lt;/b&gt; If security systems, including the three described in this article, are being used, determine if they are sufficient for current and future needs.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Secure senior management approval and budgeting.&lt;/b&gt; Brief senior company and IT management on plans for a change in cybersecurity management systems, and prepare a use case and an ROI analysis.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Review and update cybersecurity strategies.&lt;/b&gt; Determine if existing strategies are sufficient. Also, determine if skill sets are sufficient or need to be expanded. Finally, determine budgetary considerations, especially when evaluating the cost of prospective software tools and third-party services.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Check out security systems, especially SIEM, SOAR and XDR.&lt;/b&gt; In addition to a powerful platform, look for AI capabilities, easy-to-use dashboards, scalability, compatibility with existing platforms and overall performance. Examine multiple platforms, and consider blending two or all three of the tools discussed in this article. Don't forget to check out vendor capabilities and support.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Establish a project team and plan.&lt;/b&gt; Identify a team of cybersecurity employees who can facilitate all aspects of the project. Create a project plan for each phase of the new system. Examine current policies and procedures. Include a risk assessment, if possible.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Use a multiphase rollout, testing and acceptance process.&lt;/b&gt; If possible, install the new or updated system in phases to ensure that each step is tested and validated, bugs are fixed and each step has acceptance testing by the security department and SOC.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Provide training, advice to employees and senior management.&lt;/b&gt; Arrange for training of security team members, ensure that the system is fully documented and try out various scenarios to see how the system responds. Provide timely alerts to employees about the new or updated system, and regularly brief management on progress.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Ensure that maintenance and ongoing support are launched.&lt;/b&gt; Once the system is in production, conduct initial performance reviews to see how well it is working. Update security policies and procedures as needed.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Launch monitoring and continuous improvement.&lt;/b&gt; Schedule periodic reviews to see how the system is performing, review any security events, update &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-create-an-incident-response-playbook"&gt;playbooks&lt;/a&gt; and procedures, and continually improve the system's overall performance.&lt;/li&gt; 
 &lt;/ol&gt;
 &lt;p&gt;However an organization decides to do it, managing cyberthreats should be one of its highest priorities. Luckily, today, there is a wide variety of techniques and technologies that are available to reduce the risk, including SIEM, SOAR and XDR.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Paul Kirvan is an independent consultant, IT auditor, technical writer, editor and educator. He has more than 25 years of experience in business continuity, disaster recovery, security, enterprise risk management, telecom and IT auditing.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>SIEM, SOAR and XDR each possess distinct capabilities and drawbacks. Learn the differences among the three, how they can work together and which your company needs.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/security_a244600171.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/tip/SIEM-vs-SOAR-vs-XDR-Evaluate-the-key-differences</link>
            <pubDate>Tue, 12 Nov 2024 12:30:00 GMT</pubDate>
            <title>SIEM vs. SOAR vs. XDR: Evaluate the key differences</title>
        </item>
        <item>
            <body>&lt;p&gt;Extended detection and response platforms aggregate and analyze data from disparate security tools, enabling organizations to more quickly identify and respond to security incidents. As with any tool, XDR has more than one deployment option, specifically open or native.&lt;/p&gt; 
&lt;p&gt;Let's look at XDR and then more closely at open vs. native XDR, as well as which products XDR is often confused with.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="What is XDR?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What is XDR?&lt;/h2&gt;
 &lt;p&gt;Coined by Palo Alto Networks in 2018, XDR is an evolution of endpoint detection and response. &lt;a href="https://www.techtarget.com/searchsecurity/definition/endpoint-detection-and-response-EDR"&gt;EDR&lt;/a&gt; tools collect threat data from mobile devices, workstations and other endpoints to detect, investigate, analyze and respond to &lt;a href="https://www.techtarget.com/searchsecurity/feature/10-types-of-security-incidents-and-how-to-handle-them"&gt;security incidents&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;&lt;a href="https://www.techtarget.com/searchsecurity/definition/extended-detection-and-response-XDR"&gt;XDR&lt;/a&gt; platforms expand detection, investigation, analysis and response capabilities by collecting threat data from endpoints and networks, clouds, servers and email systems. With collected data ingested in an XDR tool, security teams have a more holistic view of their organization's threat landscape.&lt;/p&gt;
 &lt;p&gt;XDR platforms can provide the following benefits:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Enhanced threat detection.&lt;/b&gt; XDR tools' data collection and analysis features enable better identification of security threats and suspicious or malicious behaviors.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Faster incident response.&lt;/b&gt; XDR platforms use machine learning, playbooks and workflows to automate analysis and response to detected threats.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Better security posture.&lt;/b&gt; XDR's advanced detection and response capabilities provide coverage across a variety of assets and environments.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Improved security coverage.&lt;/b&gt; XDR platforms ingest data from disparate security tools to discover and &lt;a href="https://www.techtarget.com/searchsecurity/feature/How-to-map-security-gaps-to-the-Mitre-ATTCK-framework"&gt;remediate security gaps&lt;/a&gt; and blind spots.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="What is open XDR?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What is open XDR?&lt;/h2&gt;
 &lt;p&gt;Open XDR, also called &lt;i&gt;hybrid XDR&lt;/i&gt;, focuses on third-party integrations via APIs. These platforms enable organizations to collect telemetry and security data from a variety of security tools and products.&lt;/p&gt;
 &lt;p&gt;As vendor-agnostic products, open XDR platforms can integrate with other vendors' security tools. Instead of ripping and replacing existing security deployments, security teams work with a core open XDR platform designed to provide a central management plane for their current setup.&lt;/p&gt;
 &lt;p&gt;Open XDR platforms offer the following benefits:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Security teams don't need to learn multiple new tools because they can keep existing security tools.&lt;/li&gt; 
  &lt;li&gt;Teams can replace disparate security tools when necessary and as their organizations' security needs change.&lt;/li&gt; 
  &lt;li&gt;They prevent siloed security tools because the open platforms report data and telemetry to a central management dashboard.&lt;/li&gt; 
  &lt;li&gt;They help avoid vendor lock-in.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;A challenge with open XDR tools is that companies need to ensure the product they select has not only existing integrations, but also assurances that the product will continue to add integrations over time. Niche security products could be omitted because it's not feasible for vendors to engineer connections to every product. Organizations should research open XDR products before adoption to ensure they integrate with current security tools.&lt;/p&gt;
 &lt;p&gt;Open XDR platforms appeal to larger organizations that are focused on using best-in-class products and want an XDR tool that overlays their security stack.&lt;/p&gt;
 &lt;p&gt;Open XDR products include Exabeam Fusion XDR, ReliaQuest GreyMatter and Stellar Cyber Open XDR.&lt;/p&gt;
&lt;/section&gt;        
&lt;section class="section main-article-chapter" data-menu-title="What is native XDR?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What is native XDR?&lt;/h2&gt;
 &lt;p&gt;Native XDR, also called &lt;i&gt;closed XDR&lt;/i&gt;, is an all-in-one platform from a single vendor. Organizations with homogenous IT environments might choose to use a native XDR product that integrates that vendor's other security products in use.&lt;/p&gt;
 &lt;p&gt;A benefit of a single-vendor native XDR product is that security teams don't have to configure integrations. Native XDR can also offer smoother automation capabilities because it is designed to work with the vendor's other security tools out of the box.&lt;/p&gt;
 &lt;p&gt;Native XDR tools aren't without difficulties. If many of an organization's security tools aren't from a single vendor, it might need to rip and replace some existing tools to create a single-vendor environment. Native XDR platforms also can lack third-party integration capabilities. Organizations using native XDR can also experience vendor lock-in and can be prone to security gaps or blind spots.&lt;/p&gt;
 &lt;p&gt;Native XDR tools might appeal to smaller organizations with limited budgets or organizations primarily using a single vendor for all their tech deployments.&lt;/p&gt;
 &lt;p&gt;Examples of native XDR platforms include Cisco XDR, Microsoft Defender and Palo Alto Networks' Cortex XDR.&lt;/p&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="XDR vs. EDR, SIEM and SOAR"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;XDR vs. EDR, SIEM and SOAR&lt;/h2&gt;
 &lt;p&gt;As a relatively nascent technology, XDR is often confused with other security tools, such as EDR, &lt;a href="https://www.techtarget.com/searchsecurity/definition/security-information-and-event-management-SIEM"&gt;SIEM&lt;/a&gt; and security orchestration, automation and response (&lt;a href="https://www.techtarget.com/searchsecurity/definition/SOAR"&gt;SOAR&lt;/a&gt;):&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;XDR vs. EDR.&lt;/b&gt; EDR tools encompass endpoints, such as PCs, mobile devices and workstations, while XDR platforms cover endpoints, cloud assets, networks, servers, applications and other security tools. Most organizations do not need both an XDR and an EDR tool.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;XDR vs. SIEM.&lt;/b&gt; Traditional SIEM systems offer a central location that ingests security log data within a network and provides detection and alerting capabilities. XDR platforms correlate a wider range of data and, unlike traditional SIEM systems, can conduct automated responses. XDR platforms do not offer the log management, retention and compliance features of SIEM systems, however, so organizations using an XDR tool still need a SIEM system.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;XDR vs. SOAR.&lt;/b&gt; SOAR platforms &lt;a href="https://www.techtarget.com/searchsecurity/answer/SOAR-vs-SIEM-Whats-the-difference"&gt;bolster SIEM systems' capabilities&lt;/a&gt; and can automate response actions. XDR is not a replacement for SOAR because SOAR platforms work so tightly with data gathered by SIEM systems.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;&lt;i&gt;Kyle Johnson is technology editor for TechTarget Security.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Extended detection and response tools are open or native. Learn the differences between them, and get help choosing the right XDR type for your organization.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/security_a303570139.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/feature/The-differences-between-open-XDR-vs-native-XDR</link>
            <pubDate>Thu, 25 Jul 2024 09:00:00 GMT</pubDate>
            <title>The differences between open XDR vs. native XDR</title>
        </item>
        <item>
            <body>&lt;p&gt;To tap the flexibility of the cloud computing model, organizations continue to move operationally important workloads off premises. This shift to cloud makes safeguarding these assets a top priority.&lt;/p&gt; 
&lt;p&gt;Organizations need to be aware of potential vulnerabilities that could put their cloud environments at risk. The IBM-sponsored "Cost of a Data Breach Report 2023," &lt;a target="_blank" href="https://www.ibm.com/downloads/cas/E3G5JMBP" rel="noopener"&gt;conducted&lt;/a&gt; by Ponemon Institute, found that 82% of all reported security incidents were associated with data running in private, public or multiple clouds. Thirty-nine percent of all breaches traversed multiple clouds, according to the study, and carried a per-incident cost of $4.75 million.&lt;/p&gt; 
&lt;p&gt;While these risks and costs elevate &lt;a href="https://www.techtarget.com/searchsecurity/definition/cloud-security"&gt;cloud security&lt;/a&gt; as a corporate priority, the complexity associated with protecting workloads and infrastructure in virtual environments can be daunting. And the myriad acronyms don't make it easy to understand the functionality of the various options available to address cloud security risks.&lt;/p&gt; 
&lt;p&gt;Let's explore the similarities and differences of CASB vs. CSPM vs. CWPP.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="CASB: Cloud access security broker"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;CASB: Cloud access security broker&lt;/h2&gt;
 &lt;p&gt;To protect on-premises access to cloud resources, organizations might choose to deploy a cloud access security broker (&lt;a href="https://www.techtarget.com/searchcloudcomputing/definition/cloud-access-security-broker-CASB"&gt;CASB&lt;/a&gt;). This tool enforces policies in the transactions between users accessing cloud assets and the cloud services to which they are connecting. CASBs provide a mechanism to protect interactions with SaaS and other cloud services beyond the organization's perimeter. CASB products deliver insights into cloud access and policy enforcement of these interactions.&lt;/p&gt;
 &lt;figure class="main-article-image full-col" data-img-fullsize="https://searchcloudsecurity.techtarget.com/rms/onlineImages/cloud_security-casb_cloud_access_security_broker.jpg"&gt;
  &lt;img data-src="https://searchcloudsecurity.techtarget.com/rms/onlineImages/cloud_security-casb_cloud_access_security_broker_mobile.jpg" class="lazy" data-srcset="https://searchcloudsecurity.techtarget.com/rms/onlineImages/cloud_security-casb_cloud_access_security_broker_mobile.jpg 960w,https://searchcloudsecurity.techtarget.com/rms/onlineImages/cloud_security-casb_cloud_access_security_broker.jpg 1280w" alt="CASB tools are positioned in between users and cloud services" height="297" width="560"&gt;
  &lt;figcaption&gt;
   &lt;i class="icon pictures" data-icon="z"&gt;&lt;/i&gt;CASB tools sit between users and cloud services to ensure individual actions are authorized and conform to company policies.
  &lt;/figcaption&gt;
  &lt;div class="main-article-image-enlarge"&gt;
   &lt;i class="icon" data-icon="w"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/figure&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="CSPM: Cloud security posture management"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;CSPM: Cloud security posture management&lt;/h2&gt;
 &lt;p&gt;Cloud security posture management (&lt;a href="https://www.techtarget.com/searchsecurity/definition/Cloud-Security-Posture-Management-CSPM"&gt;CSPM&lt;/a&gt;) products monitor cloud infrastructure, including on-demand compute and storage, and PaaS and SaaS implementations, looking for vulnerabilities and compliance problems that could expose cloud assets to risk.&lt;/p&gt;
 &lt;p&gt;CSPM tools offer custom rules built on various regulatory constructs, including Center for Internet Security, HIPAA, International Organization for Standardization, GDPR, &lt;a href="https://www.techtarget.com/searchsoftwarequality/definition/NIST"&gt;NIST&lt;/a&gt; and PCI DSS. Because these tools can work across multi-cloud environments, they provide important protections. A CSPM product can also recommend fixes if it finds a vulnerability or misconfiguration.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="CWPP: Cloud workload protection platform"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;CWPP: Cloud workload protection platform&lt;/h2&gt;
 &lt;p&gt;A cloud workload protection platform (&lt;a href="https://www.techtarget.com/searchsecurity/definition/cloud-workload-protection-platform-CWPP"&gt;CWPP&lt;/a&gt;) offers ongoing threat management for cloud workloads.&lt;/p&gt;
 &lt;p&gt;CWPPs protect workloads from a range of vulnerabilities and risks, including configuration errors, DDoS attacks, data leakage, exfiltration and malware. Organizations use CWPPs to track and identify threats on an ongoing basis, looking at software configurations, network connections and end-user access privileges.&lt;/p&gt;
 &lt;p&gt;CWPPs also provide insights into and management of the infrastructure the workloads run on, including virtual and physical machines, as well as container and serverless workloads. CWPPs run security configuration checks and audits to verify compliance with regulatory requirements and corporate mandates.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="CASB vs. CSPM vs. CWPP: Key differences and areas of overlap"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;CASB vs. CSPM vs. CWPP: Key differences and areas of overlap&lt;/h2&gt;
 &lt;p&gt;CASBs, CSPMs and CWPPs have their own roles to play in cloud security. There is some &lt;a href="https://www.techtarget.com/searchsecurity/tip/Too-many-cloud-security-tools-Time-for-consolidation"&gt;overlap in functionality&lt;/a&gt;, but each focuses on securing specific aspects of cloud deployments.&lt;/p&gt;
 &lt;p&gt;CASB tools deliver an accurate perspective of end-user cloud interactions, both in terms of sanctioned and unsanctioned applications. This gives administrators insight into &lt;a href="https://www.techtarget.com/searchcio/tip/6-dangers-of-shadow-IT-and-how-to-avoid-them"&gt;shadow IT activity&lt;/a&gt; and can help inform &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-create-a-cloud-security-policy-step-by-step"&gt;security policy creation&lt;/a&gt; and enforcement.&lt;/p&gt;
 &lt;p&gt;A CASB can discern if corporate data is accessed and disseminated in a secure manner, detect non-compliance and use &lt;a href="https://www.techtarget.com/whatis/definition/data-loss-prevention-DLP"&gt;data loss prevention&lt;/a&gt; controls to deflect breaches or accidental leakage. A &lt;a href="https://www.techtarget.com/searchcloudcomputing/feature/Explore-CASB-use-cases-before-you-decide-to-buy"&gt;business can use a CASB tool&lt;/a&gt; to detect malware and sandbox dangerous content.&lt;/p&gt;
 &lt;p&gt;A CASB will have some overlap in functionality with CSPM products, as both look for noncompliance.&lt;/p&gt;
 &lt;div class="youtube-iframe-container"&gt;
  &lt;iframe id="ytplayer-0" src="https://www.youtube.com/embed/STv9iiJXZdo?si=1ZIWm7XSdCqLkGtl?autoplay=0&amp;amp;modestbranding=1&amp;amp;rel=0&amp;amp;widget_referrer=null&amp;amp;enablejsapi=1&amp;amp;origin=https://searchcloudsecurity.techtarget.com" type="text/html" height="360" width="640" frameborder="0"&gt;&lt;/iframe&gt;
 &lt;/div&gt;
 &lt;p&gt;CSPM tracks infrastructure within cloud environments and assesses potential issues based on a catalog of security risks. CSPM tools can make remediation recommendations, and some also apply automation to remediate certain types of events without manual involvement. Security engineers and IT administrators use CSPM particularly for hybrid and multi-cloud environments because the tools can work across infrastructure. A downside to using CSPM tools is that they capture a point in time, missing configuration and other minor changes that might create points of exposure over the longer term.&lt;/p&gt;
 &lt;p&gt;CWPPs provide a consolidated perspective on monitoring and identification of threats to cloud workloads. CWPPs give IT organizations insight into workload vulnerabilities across public, private and hybrid deployments. IT administrators use these insights to prioritize remediations and meet compliance requirements.&lt;/p&gt;
 &lt;p&gt;Other elements associated with cloud security include &lt;a href="https://www.techtarget.com/searchnetworking/definition/Secure-Access-Service-Edge-SASE"&gt;secure access service edge&lt;/a&gt; products, which merge security with WAN connectivity to protect access. Newer product categories are also emerging, such as cloud-native application protection platforms that combine aspects of CASBs, CWPPs and CSPMs to protect cloud-native applications and workloads.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Amy Larsen DeCarlo has covered the IT industry for more than 30 years, as a journalist, editor and analyst. As a principal analyst at GlobalData, she covers managed security and cloud services.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Let's break down some cloud security alphabet soup. CASB, CSPM and CWPP overlap to an extent, but you'll want to pay close attention to how they accomplish different things.</description>
            <image>https://cdn.ttgtmedia.com/visuals/searchEnterpriseLinux/linux_security/enterpriselinux_article_025.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/feature/CASB-vs-CSPM-vs-CWPP-Comparing-cloud-security-tool-types</link>
            <pubDate>Mon, 17 Jun 2024 16:30:00 GMT</pubDate>
            <title>CASB vs. CSPM vs. CWPP: Comparing cloud security tool types</title>
        </item>
        <item>
            <body>&lt;p&gt;SaaS has become the normative path for many enterprises in how they consume business applications. Data from Productiv, which makes software to help businesses manage their application spending, showed that the average company used 342 SaaS applications in 2023.&lt;/p&gt; 
&lt;p&gt;In addition to the quantity, the ways that organizations use SaaS products complicate efforts to protect sensitive data and guard against data breaches. Organizations make choices based on their particular industry, requirements, goals, regulatory mandates and so forth. This all means that there's no one-and-done, one-size-fits-all SaaS security checklist.&lt;/p&gt; 
&lt;p&gt;That said, certain SaaS security best practices and strategies can be applied to most situations. A few best practices to consider include the following.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="1. Discover and inventory applications"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;1. Discover and inventory applications&lt;/h2&gt;
 &lt;p&gt;One of the things that makes SaaS so compelling is how easily it can be put to work. This ease is both a blessing and a curse. New users can easily get started using a tool, creating situations where an application's usage can go from a handful of users to significant usage practically overnight.&lt;/p&gt;
 &lt;p&gt;These adoption dynamics complicate SaaS management. A survey of IT professionals for BetterCloud's "2023 State of SaaSOps" report found that &lt;a href="https://www.bettercloud.com/resources/stateofsaasops23/" target="_blank" rel="noopener"&gt;up to 65%&lt;/a&gt; of SaaS application usage is unsanctioned, a strong indication that the shadow IT tradition remains alive and well.&lt;/p&gt;
 &lt;p&gt;To discover which SaaS applications are in use, a business might employ both automated and manual methods. Additionally, it is wise to have strategies in place for how to gather and validate usage data. You might, for example, combine improvement of your SaaS inventory with other data-gathering activities you have underway. You might choose &lt;a href="https://www.techtarget.com/searchstorage/definition/business-impact-analysis"&gt;business impact analysis&lt;/a&gt; -- i.e., collecting information about applications' usage and relative priorities for business continuity purposes -- or evidence gathering for audit response as mechanisms to gather intelligence about SaaS applications in the environment. As you collect information, add the data to a running inventory or runbook associated with business use of these SaaS tools.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="2. Implement single sign-on"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;2. Implement single sign-on&lt;/h2&gt;
 &lt;p&gt;Finding and recording information about usage is useful, but you also need strategies that self-enforce the secure outcomes you want. One particularly illustrative example of this is single sign-on (&lt;a href="https://www.techtarget.com/searchsecurity/definition/single-sign-on"&gt;SSO&lt;/a&gt;).&lt;/p&gt;
 &lt;p&gt;From a user point of view, one of the biggest hassles with SaaS can be the proliferation of identities across the various business applications in use. A user might have dozens of username-password combinations; this is burdensome for them, plus it also creates management challenges and security risks, such as users sharing passwords across services or employees writing down their passwords.&lt;/p&gt;
 &lt;p&gt;Some SaaS providers offer the option of integrating with an external identity provider, such as Active Directory or &lt;a href="https://www.techtarget.com/searchwindowsserver/tip/What-should-admins-know-about-Microsoft-Entra-features"&gt;Microsoft's Entra ID&lt;/a&gt;. These are typically supported through federation mechanisms, including Security Assertion Markup Language (SAML) and &lt;a href="https://www.techtarget.com/whatis/definition/OpenID"&gt;OpenID Connect&lt;/a&gt; (&lt;a href="https://www.techtarget.com/whatis/definition/OpenID"&gt;OIDC&lt;/a&gt;). While these features are valuable on their own, they also help with discovery. Not needing to remember another username-password combination is directly beneficial to the end user -- so much so, in fact, that users can help pressure for this functionality in cases where it is not in place.&lt;/p&gt;
 &lt;p&gt;This pressure to support SSO from the user community is a good thing because it identifies SaaS usage that the security team might not otherwise know about. It also ties together the authentication constraints -- e.g., MFA and password complexity parameters -- as well as extending access logging in to the SaaS realm.&lt;/p&gt;
 &lt;div class="youtube-iframe-container"&gt;
  &lt;iframe id="ytplayer-0" src="https://www.youtube.com/embed/YvHmP2WyBVY?autoplay=0&amp;amp;modestbranding=1&amp;amp;rel=0&amp;amp;widget_referrer=null&amp;amp;enablejsapi=1&amp;amp;origin=https://searchcloudsecurity.techtarget.com" type="text/html" height="360" width="640" frameborder="0"&gt;&lt;/iframe&gt;
 &lt;/div&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="3. Enable multifactor authentication"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;3. Enable multifactor authentication&lt;/h2&gt;
 &lt;p&gt;One of the main mechanisms to enable &lt;a href="https://www.techtarget.com/searchsecurity/definition/multifactor-authentication-MFA"&gt;MFA&lt;/a&gt; is through federation of the user's identity to the existing, internally used identity provider. However, this is not the only way. Some SaaS applications do not directly support SSO -- e.g., via SAML or OIDC -- but nevertheless do allow an option for MFA through one or more supported mechanisms, such as a time-based, one-time password or text. In situations where MFA is supported, making use of that feature and enforcing it across the user base can be valuable as well.&lt;/p&gt;
 &lt;div class="youtube-iframe-container"&gt;
  &lt;iframe id="ytplayer-1" src="https://www.youtube.com/embed/_3rlQVXGKZc?autoplay=0&amp;amp;modestbranding=1&amp;amp;rel=0&amp;amp;widget_referrer=null&amp;amp;enablejsapi=1&amp;amp;origin=https://searchcloudsecurity.techtarget.com" type="text/html" height="360" width="640" frameborder="0"&gt;&lt;/iframe&gt;
 &lt;/div&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="4. Vet and perform oversight"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;4. Vet and perform oversight&lt;/h2&gt;
 &lt;p&gt;Just as you review and validate vendors from a supply chain perspective, it is important to evaluate SaaS providers and applications. You want to understand the usage of the application, as in who is using it and for what business purpose, as well as the security profile of the vendor. Identify the available security features. For example, are there optional data protection and privacy capabilities? Also, understand the core assumptions built into the product about which elements of protecting usage are on your side of the &lt;a href="https://www.techtarget.com/searchcloudcomputing/definition/shared-responsibility-model"&gt;shared responsibility&lt;/a&gt; fence.&lt;/p&gt;
&lt;/section&gt;  
&lt;section class="section main-article-chapter" data-menu-title="5. Employ data encryption"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;5. Employ data encryption&lt;/h2&gt;
 &lt;p&gt;Most channels used for communication with SaaS applications employ &lt;a href="https://www.techtarget.com/searchsecurity/definition/Transport-Layer-Security-TLS"&gt;TLS&lt;/a&gt; to protect data in transit. Many SaaS providers offer an encryption capability to &lt;a href="https://www.techtarget.com/searchsecurity/feature/Best-practices-to-secure-data-at-rest-in-use-and-in-motion"&gt;protect data at rest, too&lt;/a&gt;. For some providers, this is a default feature; for others, it must be explicitly enabled by the customer. If given the option, it is a good idea to enable data encryption features. If your providers do not offer encryption, let them know this is a feature you want to see added.&lt;/p&gt;
&lt;/section&gt;  
&lt;section class="section main-article-chapter" data-menu-title="6. Consider CASB"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;6. Consider CASB&lt;/h2&gt;
 &lt;p&gt;Depending on your security requirements, you might choose to evaluate tools and controls that help extend security requirements into the cloud. In a SaaS context, consider the &lt;a href="https://www.techtarget.com/searchcloudcomputing/definition/cloud-access-security-broker-CASB"&gt;cloud access security broker&lt;/a&gt; options. With a CASB tool, an organization can layer on additional controls not provided natively by the SaaS provider. For example, a &lt;a href="https://www.techtarget.com/searchcloudcomputing/feature/Explore-CASB-use-cases-before-you-decide-to-buy"&gt;CASB could provide better information&lt;/a&gt; about who is accessing the tool, better usage monitoring and better data protection. Pay attention to CASB deployment modes: TLS 1.3 has increased the complexity associated with some proxy-based models, while API-driven modes, in many cases, require support by the SaaS provider itself, which means your provider of choice might not support every product on the market.&lt;/p&gt;
&lt;/section&gt;  
&lt;section class="section main-article-chapter" data-menu-title="7. Consider SSPM"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;7. Consider SSPM&lt;/h2&gt;
 &lt;p&gt;Another option is &lt;a href="https://www.techtarget.com/searchsecurity/tip/SSPM-vs-CSPM-Whats-the-difference"&gt;SaaS security posture management&lt;/a&gt;. SSPM is similar in some ways to cloud security posture management. With &lt;a href="https://www.techtarget.com/searchsecurity/definition/Cloud-Security-Posture-Management-CSPM"&gt;CSPM&lt;/a&gt;, you more effectively ensure that you are enforcing a given security model across multiple cloud deployments. SSPM boosts efforts to ensure that security policy and enforcement are set universally across SaaS platforms. SSPM tool vendors have done the work of translating specific technical policy goals into the native configuration of different SaaS services; they then can query those services to ensure that your configuration is in the desired state. And they warn you if it is not.&lt;/p&gt;
&lt;/section&gt;  
&lt;section class="section main-article-chapter" data-menu-title="8. Maintain situational awareness"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;8. Maintain situational awareness&lt;/h2&gt;
 &lt;p&gt;As always, monitor SaaS use. Examine data from internal tools, including a CASB if you are using that, as well as any logs or other information provided by the service providers, to see where and how you are using SaaS.&lt;/p&gt;
 &lt;p&gt;It is important for IT and security leaders to understand that a SaaS offering is a powerful tool that requires the same degree of security as any other enterprise application. By adopting these SaaS security best practices in conjunction with systematic risk management measures and &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-conduct-a-cloud-security-assessment"&gt;ongoing security assessments&lt;/a&gt;, organizations can ensure SaaS is employed safely by users and usage stays protected.&lt;/p&gt;
 &lt;p&gt;&lt;b&gt;Editor's note:&lt;/b&gt; &lt;i&gt;This article has been updated and expanded to include changes in cloud security best practices since its original 2021 publication and to improve the reader experience.&lt;/i&gt;&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Ed Moyle is a technical writer with more than 25 years of experience in information security. He is currently CISO at Drake Software.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>SaaS has become ubiquitous. To secure it, take steps to inventory SaaS usage, securely authenticate usage, encrypt data, adopt single sign-on and more.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/cloud_g470542178.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/tip/8-SaaS-security-best-practices-for-2024</link>
            <pubDate>Mon, 10 Jun 2024 09:00:00 GMT</pubDate>
            <title>8 SaaS security best practices for 2024</title>
        </item>
        <item>
            <body>&lt;p&gt;Network security architectural best practices are undergoing a dramatic shift. The long-forecasted move away from perimeter protection as a primary focus of network architectures seems to finally be underway as &lt;a href="https://www.techtarget.com/searchsecurity/definition/zero-trust-model-zero-trust-network"&gt;zero trust&lt;/a&gt; and &lt;a href="https://www.techtarget.com/searchnetworking/definition/Secure-Access-Service-Edge-SASE"&gt;secure access service edge&lt;/a&gt; shift into the consciousness of cybersecurity professionals.&lt;/p&gt; 
&lt;p&gt;Simply put, the old network security method of using a drawbridge and moat to protect the castle doesn't cut it nowadays. Virtualization, cloud computing and remote workers have shifted the placement of the moat, which doesn't necessarily protect against risks from inside the castle itself.&lt;/p&gt; 
&lt;p&gt;Zero-trust network access (ZTNA) and secure access service edge (SASE) are two approaches gaining steam as organizations seek to better secure their increasingly dispersed remote workforces. Let's look at each of these architectural approaches and how they might work together to enhance your organization's cybersecurity posture.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="What is zero-trust network access?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What is zero-trust network access?&lt;/h2&gt;
 &lt;p&gt;Zero trust, coined in 2010 by Forrester Research, applies the longstanding security principle of least privilege (&lt;a href="https://www.techtarget.com/searchsecurity/definition/principle-of-least-privilege-POLP"&gt;POLP&lt;/a&gt;) to network access. It does so in a manner that doesn't make the same assumptions about trust used in past architectures.&lt;/p&gt;
 &lt;p&gt;Specifically, the core operating principle of ZTNA is that no user or device should ever be granted access to resources based solely on location on the network. Gone are the days of granting application access based on IP addresses or other network-based criteria.&lt;/p&gt;
 &lt;p&gt;Instead, ZTNA recognizes that, in today's operating environment, both users and sensitive data can be located anywhere: in a corporate office, at home, in the cloud or on the road. The zero-trust model replaces the network-focused access control approach with strong authentication and authorization technology that enables administrators to apply granular access controls.&lt;/p&gt;
 &lt;p&gt;Such access controls permit users to access specific applications based upon their specific role(s) in the organization. The controls also are instrumental in protecting the network from external risks, as well as &lt;a href="https://www.techtarget.com/searchsecurity/tip/Five-common-insider-threats-and-how-to-mitigate-them"&gt;malicious and negligent internal threats&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;A zero-trust network security approach not only simplifies network requirements, but also adapts to the flexible nature of today's technology environment. ZTNA enables users -- regardless of their network location -- to access services -- regardless of their network location -- while strictly enforcing POLP.&lt;/p&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="What is secure access service edge?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What is secure access service edge?&lt;/h2&gt;
 &lt;p&gt;SASE is an approach to networking and network security that builds on the ZTNA model to deliver a fully integrated network. This cloud architecture model, &lt;a target="_blank" href="https://www.gartner.com/en/information-technology/glossary/secure-access-service-edge-sase" rel="noopener"&gt;introduced&lt;/a&gt; by Gartner in 2019, integrates multiple cloud network and cloud security functions, delivering them as a single cloud service.&lt;/p&gt;
 &lt;p&gt;SASE combines software-defined WAN (SD-WAN) and the following networking services and functions:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;ZTNA.&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.techtarget.com/searchcloudcomputing/definition/cloud-access-security-broker-CASB"&gt;Cloud access security brokers&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.techtarget.com/searchnetworking/definition/firewall-as-a-service-FWaaS"&gt;Firewall as a service&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;Secure web gateways.&lt;/li&gt; 
  &lt;li&gt;SaaS.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;SASE's aim is to blend these services and technologies to build a cloud-aware and cloud-based secure network.&lt;/p&gt;
 &lt;p&gt;The SASE model is especially appealing to organizations that abundantly use the cloud and cloud services or are migrating to the cloud. This includes distributed organizations -- for example, those with branch locations and dispersed end users -- as well businesses with IoT and edge deployments.&lt;/p&gt;
 &lt;p&gt;SASE is built on the core identity principles of zero trust. Another common service model is security service edge (SSE), which is &lt;a href="https://www.techtarget.com/searchsecurity/tip/Explaining-the-differences-between-SASE-vs-SSE"&gt;similar to SASE&lt;/a&gt; but does not include SD-WAN.&lt;/p&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="Not ZTNA vs. SASE, but ZTNA and SASE"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Not ZTNA vs. SASE, but ZTNA and SASE&lt;/h2&gt;
 &lt;p&gt;Think of SASE as a higher-level design philosophy than ZTNA. They are not separate or competing network security models; rather, ZTNA is part of an overall SASE architecture.&lt;/p&gt;
 &lt;p&gt;Note, however, that, while &lt;a href="https://www.techtarget.com/searchsecurity/feature/How-to-implement-zero-trust-security-from-people-who-did-it"&gt;zero-trust implementation&lt;/a&gt; might be a short- to medium-term objective for network architects, SASE is a long-term goal. Organizations might decide today that they buy into the SASE approach and then slowly evolve their network and network security stacks toward the SASE model. This takes time as designers replace outdated security technologies and better integrate those that remain. Moving to a SASE model both requires and enables a zero-trust approach to network security.&lt;/p&gt;
 &lt;p&gt;The bottom line for today's cybersecurity professionals is that both zero trust and SASE are important to integrate into forward-looking architectural decisions. Organizations should plan to adopt &lt;a href="https://www.techtarget.com/searchsecurity/answer/What-are-the-most-important-pillars-of-a-zero-trust-framework"&gt;zero-trust principles&lt;/a&gt; in the short term to better secure remote workforces accessing both cloud-based and on-premises services. At the same time, they should view all new networking projects through the lens of creating an environment to support SASE down the road.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Benefits of using zero trust and SASE together"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Benefits of using zero trust and SASE together&lt;/h2&gt;
 &lt;p&gt;Consider the following key reasons to implement ZTNA and SASE together:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Implementation of common policies can centralize control of end-user and branch office connectivity.&lt;/li&gt; 
  &lt;li&gt;They enable content filtering and malware protection for all types of internet access.&lt;/li&gt; 
  &lt;li&gt;They improve monitoring capabilities through more granular behavioral access control for any geographic locations.&lt;/li&gt; 
  &lt;li&gt;They shift on-premises availability and redundancy controls to a cloud-based hub-and-spoke model. Access to cloud services and on-premises applications are managed through a cloud service provider instead of a traditional data center, potentially reducing Opex and Capex.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Organizations that haven't yet should consider a centralized, consolidated cloud brokering controls model. As zero trust continues to gain traction, &lt;a href="https://www.techtarget.com/searchsecurity/feature/Secure-service-edge-strengths-drive-SASE-deployments"&gt;SSE and SASE&lt;/a&gt; tools will become more prevalent to facilitate the move from traditional data centers as the central point of security control implementation.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Dave Shackleford is founder and principal consultant with Voodoo Security; SANS analyst, instructor and course author; and GIAC technical director.&lt;/i&gt;&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Mike Chapple is academic director of the Master of Science in Business Analytics program and teaching professor of IT, analytics and operations at the University of Notre Dame.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>When it comes to adopting SASE or zero trust, it's not a question of either/or, but using SASE to establish and enable zero-trust network access.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/security_a226543052.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/tip/Why-its-SASE-and-zero-trust-not-SASE-vs-zero-trust</link>
            <pubDate>Mon, 10 Jun 2024 09:00:00 GMT</pubDate>
            <title>Why it's SASE and zero trust, not SASE vs. zero trust</title>
        </item>
        <item>
            <body>&lt;p&gt;A cloud security framework is a set of guidelines and controls used to help secure an organization's cloud infrastructure. It provides cloud service providers (&lt;a href="https://www.techtarget.com/searchitchannel/definition/cloud-service-provider-cloud-provider"&gt;CSPs&lt;/a&gt;) and their customers with security baselines, validations and certifications.&lt;/p&gt; 
&lt;p&gt;Cloud has become increasingly less of an active architectural choice and more the de facto adoption strategy for new applications. Fewer organizations are purposefully selecting on-premises or colocation deployments for new deployments; instead, most are choosing cloud deployment.&lt;/p&gt; 
&lt;p&gt;Regardless of the deployment model, securing the technology landscape of organizations is essential. But securing a cloud environment is different from other environments, so there is a need in the industry for targeted resources about securing cloud. There's been quite a bit of valuable guidance published on how to best secure cloud usage and keep it secure over time.&lt;/p&gt; 
&lt;p&gt;There is a spectrum of available guidance that practitioners can choose from when it comes to securing their cloud use. On the one hand, there is detailed technical guidance, often from cloud providers themselves. This is useful when seeking to answer a specific, often technical, question like: How do I set up encryption of blob storing in XYZ environment? This type of guidance is less useful when looking at how to secure a cloud environment holistically and architecturally. By contrast, higher level guidance tends to be more vendor-agnostic -- i.e., applicable across different cloud environments -- but less germane to specific, detailed questions.&lt;/p&gt; 
&lt;p&gt;One type of guidance is the cloud security framework. These frameworks can provide significant utility to the practitioner. First, just like generalized security frameworks help you define the holistic security posture across your technology landscape generally, cloud security frameworks do this specifically for cloud deployments. They can also have additional value. For example, a cloud security framework can help with the validation of the security measures in place and in conducting preengagement vetting.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="What is a cloud security framework?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What is a cloud security framework?&lt;/h2&gt;
 &lt;p&gt;It's perhaps easiest to understand cloud frameworks through the lens of &lt;a href="https://www.techtarget.com/searchsecurity/tip/IT-security-frameworks-and-standards-Choosing-the-right-one"&gt;security frameworks&lt;/a&gt; more generally --i.e., guidance not specific to cloud. There are numerous broad security frameworks including frameworks for governance (e.g., &lt;a href="https://www.techtarget.com/searchsecurity/definition/COBIT"&gt;COBIT&lt;/a&gt;, ITIL), architecture (e.g., SABSA, TOGAF), management standards (e.g., &lt;a href="https://www.techtarget.com/whatis/definition/ISO-27001"&gt;ISO/IEC 27001&lt;/a&gt;) and NIST's Cybersecurity Framework. Just like these frameworks can apply broadly to any area of technology or security program, so too do they apply to cloud.&lt;/p&gt;
 &lt;figure class="main-article-image full-col" data-img-fullsize="https://searchcloudsecurity.techtarget.com/rms/onlineimages/security-it_security_framework.png"&gt;
  &lt;img data-src="https://searchcloudsecurity.techtarget.com/rms/onlineimages/security-it_security_framework_mobile.png" class="lazy" data-srcset="https://searchcloudsecurity.techtarget.com/rms/onlineimages/security-it_security_framework_mobile.png 960w,https://searchcloudsecurity.techtarget.com/rms/onlineimages/security-it_security_framework.png 1280w" alt="cybersecurity framework" height="560" width="560"&gt;
  &lt;figcaption&gt;
   &lt;i class="icon pictures" data-icon="z"&gt;&lt;/i&gt;A variety of general cybersecurity frameworks exist.
  &lt;/figcaption&gt;
  &lt;div class="main-article-image-enlarge"&gt;
   &lt;i class="icon" data-icon="w"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/figure&gt;
 &lt;p&gt;In addition to these general frameworks, there are also multiple specialized frameworks that could potentially be relevant depending on use case and context; an example of this would be HITRUST's Common Security Framework in a healthcare context or the &lt;a href="https://www.techtarget.com/searchsecurity/definition/PCI-DSS-Payment-Card-Industry-Data-Security-Standard"&gt;PCI DSS&lt;/a&gt; in a payment context.&lt;/p&gt;
 &lt;p&gt;These frameworks are useful for practitioners but don't target cloud specifically. They can, of course, be used to help inform an organization's cloud posture, but frameworks specific to cloud can be more useful. There are important ones to know, including the Cloud Security Alliance's (&lt;a href="https://www.techtarget.com/searchsecurity/definition/Cloud-Security-Alliance-CSA"&gt;CSA&lt;/a&gt;), Cloud Controls Matrix (&lt;a href="https://www.techtarget.com/searchsecurity/definition/Cloud-Controls-Matrix"&gt;CCM&lt;/a&gt;), CSA's Security, Trust, Assurance and Risk (STAR) registry, the Federal Risk and Authorization Management Program (FedRAMP) and ISO/IEC 27017. Also important are Center for Internet Security (CIS) Critical Security Controls, particularly when used together with the &lt;a target="_blank" href="https://www.cisecurity.org/insights/white-papers/cis-controls-v8-cloud-companion-guide" rel="noopener"&gt;Cloud Companion Guide&lt;/a&gt;. There are many others, too, with a broad spectrum of cloud applicability, but those mentioned here are frequently used, well-respected across the industry, specific to cloud and equally useful to CSPs and their customers.&lt;/p&gt;
 &lt;p&gt;Cloud security frameworks provide information to the broader industry about security measures that are applicable to cloud environments. Like any security framework, these include a set of controls with specific guidance about controls (including intent and rigor), control management, validation and other information related to securing a cloud use case.&lt;/p&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="Types of cloud security frameworks"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Types of cloud security frameworks&lt;/h2&gt;
 &lt;p&gt;Each framework has its own focus and goals; they are each unique. However, it's useful to think about them through the lens of a taxonomy. Doing so can help clarify which is potentially most useful for what purpose. At a high level then, the various frameworks can be separated into the following categories:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Generic framework.&lt;/b&gt; These frameworks are generic and attempt to provide broad guidance about control selection, scope, posture, and the like for cloud environments.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Tie-ins to existing broader frameworks.&lt;/b&gt; These include guidance specific to cloud that exists as part of a broader ecosystem that is not cloud-focused. One example is the CIS Cloud Companion Guide, which ties specific cloud controls to the non-cloud-specific CIS Critical Controls.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Control-specific guidance. &lt;/b&gt;There is also guidance more specific than a generic framework, including some that targets a specific control or control family. An example would be the NIST Special Publication (SP) 800-210 "General Access Control Guidance for Cloud Systems," which is specific to cloud but also focuses on one control family and topic -- in this case, access control -- as opposed to cloud more generically.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Certification framework. &lt;/b&gt;Some of the guidance available supports certification efforts, directly or indirectly. For example, CSA's CCM is instrumental to its STAR program registry. Likewise, FedRAMP is a certification vehicle to allow U.S. federal agencies to make use of cloud services.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;There is some overlap between these categories. For example, ISO/IEC 27017:2015 (Information technology -- Security techniques -- Code of practice for information security controls based on ISO/IEC 27002 for cloud services) checks several of the boxes associated with the above categories. On the one hand, it's a generic framework applicable to most cloud deployments. It also exists inside a broader ecosystem (ISO/IEC 27001 and 27002.) In addition, it's a potential target for certification. As such, it hits three of the different categories and acts as a reminder that it's important to employ a grain of salt when looking at the above taxonomy: it's a helpful way to think about frameworks but keep front of mind both the nuance and overlap.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="How are cloud security frameworks useful?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;How are cloud security frameworks useful?&lt;/h2&gt;
 &lt;p&gt;Using a framework as a set of controls and practices for consideration can be beneficial to both CSPs and cloud customers for several reasons. First, a normative list of controls and countermeasures helps guide practitioners to specific measures that they can evaluate and use in their own environments. Second, a list provides a frame of reference within which to discuss security practices and specific security countermeasures; this provides a foundation for security-relevant negotiations such as that between cloud consumers and providers on matters like respective responsibilities in a shared-responsibility model.&lt;/p&gt;
 &lt;p&gt;In addition, there is a near-infinite array of possible countermeasures an organization might employ to secure its environment. Having an agreed-upon list of generally accepted controls helps CSPs decide how to invest their time and budget, and it gives customers guidance on what they should look for as standard security mechanisms in evaluating a CSP.&lt;/p&gt;
 &lt;p&gt;Specifically, frameworks can serve as a baseline for evaluation: They provide a structure for cloud customers to evaluate providers or compare security practices between providers. They also can help service providers demonstrate their security practices, either to assist with preengagement vetting for their customers or as part of their sales narrative. The more specific and prescriptive the controls laid out in the framework, the more conducive they are to serving in this evaluation capacity.&lt;/p&gt;
 &lt;p&gt;If used strategically, frameworks reduce work and provide value for both the customer and CSP. As a basis for an evaluation checklist, they reduce work for the potential customer. Frameworks also reduce work for the CSP by reducing the number of disparate, one-off evaluation questionnaires customers might present to providers. Even if a customer insists on using their own questionnaire, frameworks can still streamline the work involved in customer vetting by enabling providers to organize responses, prepare narratives and gather evidence against a known set of criteria instead of individually for each customer they might encounter.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="How to choose a cloud security framework"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;How to choose a cloud security framework&lt;/h2&gt;
 &lt;p&gt;Adopting a cloud security framework is a relatively straightforward process, but it does vary a bit depending on whether you are a customer or CSP. For customers, selecting one will depend largely on the company's broader program and business context. For example, a U.S. federal government agency or contractor will almost certainly want to investigate FedRAMP first. FedRAMP offers a set of validation criteria based on standard security measures and streamlines the onboarding of CSPs for government use. A large multinational organization with a security program already built on ISO/IEC 27001 that incorporates controls from ISO/IEC 27002 might find ISO/IEC 27017 a better fit, because the controls will be familiar and it will align directly with the existing security program.&lt;/p&gt;
 &lt;p&gt;CSPs should employ a set of frameworks, both cloud and security ones, that are known and accepted within the markets they service. As mentioned, one of the reasons to consider these particular frameworks is their supporting assurance programs. In the case of FedRAMP, a CSP can become a FedRAMP authorized service provider. CSPs can be certified for the ISO/IEC standard, or with any of the ISO management system standards. CSA has its Consensus Assessment Initiative Questionnaire, built on CCM and its STAR registry, which certifies validation of adherence. The framework CSPs should favor is the one that is likely to be most recognized among its customers.&lt;/p&gt;
 &lt;p&gt;Regardless of which is chosen, cloud security frameworks can aid cloud security efforts. Frameworks provide a lingua franca for discussion of specific controls and a benchmark for evaluation and certification; they create a backbone for organization of internal security efforts. Learning about the framework options available is time well spent.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Best practices"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Best practices&lt;/h2&gt;
 &lt;p&gt;As you evaluate and decide which framework (or combination of frameworks) is right for you, keep the following best practices in mind:&lt;/p&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Tailor the framework to the business.&lt;/b&gt; Pay particular attention to the framework(s) that tie into the broader business context. As noted above, if you're a U.S. Federal agency, a structure like FedRAMP is probably preferable.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Tailor the framework to the security program.&lt;/b&gt; Also, consider the broader security program when evaluating frameworks. If your security program is built around ISO/IEC 27001/27002, then ISO/IEC 27017 might be a more natural fit than something like the CIS controls.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Go slow but be consistent. &lt;/b&gt;Remember this is a marathon, not a sprint; keep the pace manageable. Depending on context and your organization, there can be significant work involved in using frameworks, especially if, for example, you're new to cloud or maturing your security program. Don't try to do everything at once. Like an exercise regimen, using a framework is easier if you start slowly and build. Don't be the person who goes to the gym on day one for three hours and is so sore the next day they never return. Instead, look to make consistent progress over time.&lt;/li&gt; 
 &lt;/ol&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Future of cloud security frameworks"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Future of cloud security frameworks&lt;/h2&gt;
 &lt;p&gt;It's useful to consider how frameworks might change. While nobody knows for sure how or when they will, there are some likely ways they could evolve.&lt;/p&gt;
 &lt;p&gt;We might expect to see formalization and maturity over time. There was significant pressure in cloud's early days for guidance like these frameworks, given that cloud models were new and practitioners struggled to secure them. As cloud has become more ubiquitous -- now the normative deployment model -- there's an opportunity for guidance to mature in depth of coverage and to deal more comprehensively with edge cases.&lt;/p&gt;
 &lt;p&gt;Another thing we might see is the inclusion of newer technologies that are in active and frequent use but that were less normative when these frameworks were initially conceived. Consider, for example, technologies like &lt;a href="https://www.techtarget.com/searchitoperations/definition/service-mesh"&gt;service mesh&lt;/a&gt; and &lt;a href="https://www.techtarget.com/searchitoperations/definition/Infrastructure-as-Code-IAC"&gt;infrastructure as code&lt;/a&gt;. Both work almost seamlessly with cloud environments but might not be directly addressed by existing guidance. Expect new iterations and updates of the guidance to address these technologies. This could be through the issuance of supplemental material (e.g., technology-specific addenda) or in future refinements of the frameworks themselves.&lt;/p&gt;
 &lt;p&gt;Lastly, and perhaps most directly useful to practitioners, expect to see the professional community-building expertise and familiarity with the existing guidance, perhaps in the way of secondary source guidance -- e.g., experts writing guides and how-to tips like this one -- designed to help practitioners make use of these resources productively.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Ed Moyle is a technical writer with more than 25 years of experience in information security. He is currently the CISO at Drake Software. &lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>With so many apps and data residing in cloud, employing a security framework to help protect cloud infrastructure is an essential move for an organization.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/security_a292905838.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/tip/What-is-a-cloud-security-framework-A-complete-guide</link>
            <pubDate>Wed, 05 Jun 2024 12:35:00 GMT</pubDate>
            <title>What is a cloud security framework? A complete guide</title>
        </item>
        <item>
            <body>&lt;p&gt;Cloud &lt;a href="https://www.techtarget.com/searchitoperations/definition/security-automation"&gt;security automation&lt;/a&gt; is a process that lets a business automatically apply desired security settings to its cloud resources. This repeatable process ensures that those security controls are in place for each and every deployment, beginning with development and extending through operations.&lt;/p&gt; 
&lt;p&gt;By choosing automation, an organization reduces the risk of an oversight or misconfiguration, which, in turn, lowers the chance of a bad actor finding and exploiting a security flaw.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Why cloud security automation is important"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Why cloud security automation is important&lt;/h2&gt;
 &lt;p&gt;In cloud environments, particularly PaaS and Iaas clouds, security teams have a wealth of tools to automate various security controls and processes. Automating security across cloud development, deployment and operations is becoming a much more critical element in many organizations' security programs today. The nature and scale of cloud deployment are such that many security operations and architecture teams just can't keep up, especially in areas such as investigation and vulnerability analysis, where some degree of manual involvement has traditionally been needed. Cloud deployments change more often, and &lt;a href="https://www.techtarget.com/searchcloudcomputing/definition/cloud-infrastructure"&gt;cloud infrastructure&lt;/a&gt; tends to be much more dynamic than traditional on-premises environments. To enable and facilitate security practices at every step, security controls need to be embedded and automated in all stages of cloud design, deployment and runtime. Finally, through the concept of guardrails, security teams can implement always-on automated controls that ensure a secure state, regardless of changes in an environment. This is a critical concept that enables a much more stable and consistent cloud state that is less prone to accidental misconfiguration and exposure.&lt;/p&gt;
 &lt;p&gt;But what makes the most sense to automate, and why? Every security team's needs differ to some extent, but there are some well-known controls and processes that most teams can automate without disrupting operations. Others require more alignment and collaboration with cloud engineering and DevOps teams.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Steps for success in cloud security automation"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Steps for success in cloud security automation&lt;/h2&gt;
 &lt;p&gt;While there's not necessarily one right way to approach security &lt;a href="https://www.techtarget.com/searchcloudcomputing/definition/cloud-automation"&gt;automation in the cloud&lt;/a&gt;, organizations that have seen success in developing and applying automation in cloud controls and processes often take the following steps. Except for the first item listed below, these steps aren't necessarily in order.&lt;/p&gt;
 &lt;figure class="main-article-image half-col" data-img-fullsize="https://searchcloudsecurity.techtarget.com/rms/onlineimages/4_steps_toward_cloud_security_automation-h.png"&gt;
  &lt;img data-src="https://searchcloudsecurity.techtarget.com/rms/onlineimages/4_steps_toward_cloud_security_automation-h_half_column_mobile.png" class="lazy" data-srcset="https://searchcloudsecurity.techtarget.com/rms/onlineimages/4_steps_toward_cloud_security_automation-h_half_column_mobile.png 960w,https://searchcloudsecurity.techtarget.com/rms/onlineimages/4_steps_toward_cloud_security_automation-h.png 1280w" alt="The 4 steps to automate security in the cloud" height="250" width="279"&gt;
  &lt;div class="main-article-image-enlarge"&gt;
   &lt;i class="icon" data-icon="w"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/figure&gt;
 &lt;h3&gt;Plan a strategy and build standards&lt;/h3&gt;
 &lt;p&gt;The first step in cloud security automation should be to define a strategy and determine which standards to enforce. For every category of control or cloud asset and service, some policies are better to start with than others. For example, automated &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-conduct-a-cloud-security-assessment"&gt;vulnerability assessments of cloud workload images&lt;/a&gt; should result in a list of bugs in various categories. Which images are acceptable to push forward into deployments?&lt;/p&gt;
 &lt;p&gt;Look at existing internal standards from the Center for Internet Security, &lt;a href="https://www.techtarget.com/searchsoftwarequality/definition/NIST"&gt;NIST&lt;/a&gt;, third-party vendors and others that are applicable to current and planned cloud deployments, and map them to your cloud assets. Then, develop new standards for cloud control plane services or cloud-native services based on best practices or compliance requirements. Look at what you've relied on in-house and where these controls can apply, and be willing to adopt new standards that are relatively tried and true in the cloud now that the industry has had a number of years of experience with large-scale deployments.&lt;/p&gt;
 &lt;p&gt;One thing to note is that there are more converged solutions available than ever before, which might &lt;a href="https://www.techtarget.com/searchsecurity/tip/Types-of-cloud-security-tools-organizations-need"&gt;aid in automating a variety of cloud security controls&lt;/a&gt;. These include cloud-native application protection platforms (CNAPPs) that often encompass workload protection, pipeline security controls and some end-user protection in accessing cloud resources, as well as security service edge and secure access service edge technologies that offer protection for cloud and on-premises infrastructure, access controls and end users. The market is changing rapidly, so be sure to have discussions with invested stakeholders to determine where the priorities lie, as this might aid in choosing a more comprehensive tool the organization can grow into.&lt;/p&gt;
 &lt;h3&gt;Automate workload security controls&lt;/h3&gt;
 &lt;p&gt;Cloud security automation should begin with instance and container configuration management. As all instances and containers are software-based with images defined in template formats, security teams can work to implement configuration hardening guidelines and standards in the images. Orchestration tools, such as Puppet, Chef and Ansible, can then implement these standards automatically. The additional benefit of using orchestration tools is that each configuration profile is defined in a template that can be continuously reevaluated to account for changes as they occur. While these tools can be used effectively on premises, there are even more automation options in the cloud. There are also integration opportunities between these platforms and cloud-native systems, including AWS OpsWorks, which offers managed instances of Puppet and Chef. For traditional VM instance workloads, focus on the following to define and implement approved system images:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Specific tags applied to workload images and running instances.&lt;/li&gt; 
  &lt;li&gt;OS vulnerabilities and patch levels that are acceptable for deployment.&lt;/li&gt; 
  &lt;li&gt;Package and application components.&lt;/li&gt; 
  &lt;li&gt;Services and accounts on these systems.&lt;/li&gt; 
  &lt;li&gt;Approved and installed security agents.&lt;/li&gt; 
  &lt;li&gt;Specific metadata associations and attributes.&lt;/li&gt; 
  &lt;li&gt;Applied privileges and policy.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;For containers and serverless functions (PaaS workloads), define and configure the following controls:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Specific tags applied to workload images and running instances.&lt;/li&gt; 
  &lt;li&gt;Local users and groups.&lt;/li&gt; 
  &lt;li&gt;Application components in use.&lt;/li&gt; 
  &lt;li&gt;Approved container images.&lt;/li&gt; 
  &lt;li&gt;Orchestration controls, such as Kubernetes and Docker Swarm.&lt;/li&gt; 
  &lt;li&gt;Serverless code.&lt;/li&gt; 
  &lt;li&gt;Serverless input and output for services and APIs.&lt;/li&gt; 
  &lt;li&gt;Serverless permissions.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;A &lt;a href="https://www.techtarget.com/searchsecurity/definition/cloud-workload-protection-platform-CWPP"&gt;cloud workload protection platform&lt;/a&gt;, a tool often bundled with a CNAPP, offers a variety of controls that handle runtime protection, configuration validation and maintenance. In addition, all major network and application vulnerability scanners can function in major cloud environments and can often integrate with cloud provider APIs to enable continuous scanning and monitoring of assets in the environment. When new assets appear, event monitoring and alerting trigger automated scans.&lt;/p&gt;
 &lt;p&gt;Integrating agents into system images can also lead to automated reporting and even policy application with some tools. Once the environment is up and running with defined service configurations, use cloud-native tools, such as AWS Config or Capital One's open source Cloud Custodian, to automate the assessment and maintenance of cloud environments.&lt;/p&gt;
 &lt;p&gt;Through defined rules and policies, these tools can check to see whether Amazon Simple Storage Service buckets have been made public, for example, and then change the settings back to a desired state. Through cloud security automation, both the assets and the environments themselves can be assessed and remediated continuously.&lt;/p&gt;
 &lt;h3&gt;Use infrastructure as code to automate infrastructure controls&lt;/h3&gt;
 &lt;p&gt;Another practical step in automating &lt;a href="https://www.techtarget.com/searchsecurity/definition/cloud-security"&gt;cloud security&lt;/a&gt; operations and cloud environment configuration is the use of infrastructure as code (&lt;a href="https://www.techtarget.com/searchitoperations/definition/Infrastructure-as-Code-IAC"&gt;IaC&lt;/a&gt;). All major cloud providers support these templates either natively, such as in AWS CloudFormation, Azure Resource Manager or Google Cloud Deployment Manager, or through third-party platforms, such as HashiCorp Terraform. With many environment and asset configurations defined in a template format, security teams can ensure smooth and consistent deployments, audit template files to adhere to standards and automate security configuration items and infrastructure deployments. In addition to unique cloud environment-specific service definitions and configuration, core security elements that should be defined and codified in these templates include networking and storage controls.&lt;/p&gt;
 &lt;p&gt;For networking controls, define and implement the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Access controls in security groups.&lt;/li&gt; 
  &lt;li&gt;Subnet-subnet access if different from above.&lt;/li&gt; 
  &lt;li&gt;Firewall appliance images and configuration.&lt;/li&gt; 
  &lt;li&gt;Cloud-native edge configurations in services like AWS Network Firewall, Azure Firewall and Azure Web Application Firewall.&lt;/li&gt; 
  &lt;li&gt;Route table and Virtual Private Cloud/Virtual Network definitions.&lt;/li&gt; 
  &lt;li&gt;Load balancer and gateway definitions.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;For storage node and service controls, &lt;a href="https://www.techtarget.com/searchitoperations/tip/Infrastructure-as-code-testing-strategies-to-validate-a-deployment"&gt;use IaC templates&lt;/a&gt; to define and instantiate the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Encryption enablement and keys.&lt;/li&gt; 
  &lt;li&gt;Access controls.&lt;/li&gt; 
  &lt;li&gt;Logging and event generation.&lt;/li&gt; 
  &lt;li&gt;Exposure configuration for public and nonpublic access.&lt;/li&gt; 
  &lt;li&gt;Database security capabilities and controls.&lt;/li&gt; 
  &lt;li&gt;Retention configuration settings.&lt;/li&gt; 
  &lt;li&gt;Archival configuration settings.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Making liberal use of IaC helps to define and implement core controls and also acts as a fundamental guardrail &lt;a target="_blank" href="https://www.sans.org/webcasts/architecting-a-cloud-security-guardrails-model/" rel="noopener"&gt;model&lt;/a&gt; since IaC templates can be routinely applied and validated once infrastructure is up and running. This changes any assets and services that have shifted or drifted from a desired state back to standardized configurations.&lt;/p&gt;
 &lt;h3&gt;Enable control plane guardrail automation&lt;/h3&gt;
 &lt;p&gt;There are many types of cloud guardrails that security teams can enable to automate defenses within the cloud control plane. In essence, defensive guardrails come down to the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Intrusion detection and prevention for networking and workloads.&lt;/li&gt; 
  &lt;li&gt;Identity and access management (&lt;a href="https://www.techtarget.com/searchsecurity/definition/identity-access-management-IAM-system"&gt;IAM&lt;/a&gt;) policies and roles.&lt;/li&gt; 
  &lt;li&gt;Cloud-native monitoring services in each account or subscription to monitor cloud assets and cloud control plane configuration.&lt;/li&gt; 
  &lt;li&gt;Full-scope cloud logging and automated responses around alerts, detection and response actions.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;IAM, in particular, is a big area to tackle. Enabling IAM monitoring tools and services to continuously scan IAM policies and roles -- and to then issue a warning about those with excessive privileges or access -- is recommended. Enforcing only the approved policies and role assignments can be accomplished in a highly automated way with IaC templates, as well as native services, such as AWS Organizations and Azure Policy, among others.&lt;/p&gt;
 &lt;p&gt;You can automate guardrails by automating asset tagging based on specific security conditions detected in the environment. One of the top advantages of the cloud is the ability to enable cloud control plane logging, which effectively logs everything in the environment and stores logs in a central location. Once services such as AWS CloudTrail, Azure Log Analytics, Azure Monitor and Google Cloud Logging are enabled, security teams can build monitoring filters on top of them to detect suspicious activities or events.&lt;/p&gt;
 &lt;p&gt;These activities trigger serverless functions that tag running instances or even user accounts with metadata. Metadata is used to track assets and quickly discover possible investigation opportunities. Once assets are tagged, any number of automated or semiautomated security strategies can be pursued. Strategies include isolating systems by changing their network access control policies, &lt;a href="https://www.techtarget.com/searchsecurity/tip/Cloudcomputing-forensics-techniques-for-evidence-acquisition"&gt;collecting forensic evidence from the systems&lt;/a&gt;, performing system suspension or termination, and disabling user accounts.&lt;/p&gt;
&lt;/section&gt;                            
&lt;section class="section main-article-chapter" data-menu-title="What are the main benefits of cloud security automation?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What are the main benefits of cloud security automation?&lt;/h2&gt;
 &lt;p&gt;Automating security in the cloud has a number of benefits. Some of the most critical are the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Accuracy and consistency. &lt;/b&gt;With automation controls and processes, many mistakes or errors in configuration can be caught and corrected without human intervention or after-the-fact assessments. Validation of approved images and infrastructure definitions can also be performed continuously throughout all phases of cloud development, deployment and ongoing operations.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Velocity. &lt;/b&gt;One of the primary benefits of a software-based infrastructure is the ability to rapidly develop and deploy infrastructure and applications. Cloud environments represent an entire ecosystem of software services and components that can be rapidly manipulated and used to stage applications. In many cases, speed and security don't mix well, as controls can be forgotten or misconfigured. Automating controls can &lt;a target="_blank" href="https://www.cloudtruth.com/blog/why-deployment-velocity-matters" rel="noopener"&gt;accelerate&lt;/a&gt; the velocity of cloud deployments, while ensuring security is enabled and effective.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Effectiveness of security controls application. &lt;/b&gt;In traditional data center environments, applying security controls has been notoriously sporadic in some cases, with missing patches, lack of workload protection, configuration management lapses, weak credentials and overly privileged accounts. &lt;a href="https://www.techtarget.com/searchcloudcomputing/definition/cloud-sprawl"&gt;Infrastructure sprawl&lt;/a&gt; and a lack of visibility contribute to these issues.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Monitoring and reporting. &lt;/b&gt;Visibility is consistently &lt;a href="https://www.techtarget.com/searchsecurity/tip/Cybersecurity-challenges-and-how-to-address-them"&gt;ranked as one of the biggest challenges in cybersecurity&lt;/a&gt;. Fortunately, it's easier to automate logging and observability controls in the cloud than in most on-premises deployments, as monitoring functionality is tied to the same cloud fabric as all the services and assets deployed there. Security operations teams can enable logging and monitoring of all API calls with a few services and also &lt;a href="https://www.techtarget.com/searchsecurity/tip/The-history-evolution-and-current-state-of-SIEM"&gt;integrate SIEM&lt;/a&gt; and other tooling at scale with minimal effort.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Scalability. &lt;/b&gt;Automation can help accommodate changes to workload processing and network and application traffic volume, creating much more effective scalability than in traditional environments. Load balancing, provisioning of additional workloads to handle more traffic and requests, and dynamic backups and data synchronization efforts can be created in cloud environments, along with automated failover operations and high availability architecture design.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;While most of these benefits are largely centered around operations and some compliance benefits, there are a few secondary benefits. Through consolidated platforms, like CNAPPs, cloud security posture management (&lt;a href="https://www.techtarget.com/searchsecurity/definition/Cloud-Security-Posture-Management-CSPM"&gt;CSPM&lt;/a&gt;), cloud access security brokers and SaaS security posture management (SSPM), some types of automated monitoring and reporting can facilitate more unified governance across a range of stakeholders. For example, a &lt;a href="https://www.techtarget.com/searchcloudcomputing/tip/How-to-build-a-cloud-center-of-excellence"&gt;cloud center of excellence&lt;/a&gt; might include business stakeholders, application owners and operations teams who could be given access to platform dashboards and metrics for their specific areas of interest. Compliance and audit teams can also benefit from an automated output of state-based controls when working with regulators, external auditors and insurers.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Future of cloud security automation"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Future of cloud security automation&lt;/h2&gt;
 &lt;p&gt;There are definitely some clear trends in the marketplace and from the cloud providers themselves related to cloud security automation. For example, continuing convergence in the product and service market for cloud-oriented protection includes a plethora of automation capabilities. In particular, the CNAPP space is enveloping &lt;a href="https://www.techtarget.com/searchsecurity/feature/CASB-CSPM-CWPP-emerge-as-future-of-cloud-security"&gt;more types of cloud-specific security tooling&lt;/a&gt;, including cloud workload protection, vulnerability management that includes container images, IaC scanning and CSPM. All these capabilities offer opportunities to implement automation and often intersect and integrate with each other, as well as other solutions.&lt;/p&gt;
 &lt;p&gt;In addition, more services that automate specific cloud security functions are emerging. These include SSPM, cloud identity and entitlements management, data security posture management, and cloud detection and response. Many of these solve a specific need but are rapidly integrating into existing cloud controls and workflows and slowly merging into CNAPPs and other multifaceted cloud security solutions. Expect this convergence to continue and these products to evolve rapidly in the coming months and years.&lt;/p&gt;
 &lt;p&gt;&lt;b&gt;Editor's note:&lt;/b&gt;&lt;i&gt; This article has been updated and expanded to include changes in the cloud security automation market since its original 2021 publication date and to improve the reader experience.&lt;/i&gt;&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Dave Shackleford is founder and principal consultant with Voodoo Security; SANS analyst, instructor and course author; and GIAC technical director.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Automating security in the cloud can be invaluable for threat detection and mitigation. Explore key areas where security professionals should implement automation.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/cloud_g470542178.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/tip/Cloud-security-automation-Benefits-and-best-practices</link>
            <pubDate>Wed, 05 Jun 2024 09:00:00 GMT</pubDate>
            <title>Cloud security automation: Benefits and best practices</title>
        </item>
        <item>
            <body>&lt;p&gt;Organizations of all sizes make use of cloud computing in some fashion, enabling them to work in more efficient ways without taking on the burden of fully managing applications and infrastructure.&lt;/p&gt; 
&lt;p&gt;Use of cloud services continues to expand, with some estimates putting global spending in excess of $600 billion annually. And while those investments enable new and productive ways for businesses to interact with customers, suppliers, employees and partners, concerns about the security of those cloud environments are daunting. Surveys of IT staff and executives continue to show that costs and security are the top challenges organizations face in managing their use of cloud services.&lt;/p&gt; 
&lt;p&gt;This comprehensive guide to cloud security examines the challenges of securing data and workloads. You'll find information about the strategies, tools and best practices that can address the many and evolving threats that cloud users confront. Throughout this guide, links point to articles that delve into particular facets of &lt;a href="https://www.techtarget.com/searchsecurity/definition/cloud-security"&gt;cloud security&lt;/a&gt;, from the big strategic questions about how to safely use public, hybrid and multi-cloud environments to the finer points of ongoing security management and the products and services that can assist in those efforts.&lt;/p&gt; 
&lt;p&gt;While beneficial in many ways, cloud computing has its risks -- risks that cloud customers must learn to manage.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="What is cloud security management?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What is cloud security management?&lt;/h2&gt;
 &lt;p&gt;Cloud security management is a complementary combination of strategies, tools and practices that aims to help a business host workloads and data in a cloud efficiently and safely. This complicated endeavor to limit exposure to threats and vulnerabilities requires action on multiple fronts, including the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Authentication and authorization. User management techniques, such as identity and access management (&lt;a href="https://www.techtarget.com/searchsecurity/definition/identity-access-management-IAM-system"&gt;IAM&lt;/a&gt;), are essential to ensuring that only authorized users and devices access cloud workloads and data.&lt;/li&gt; 
  &lt;li&gt;Data security. Encryption is a crucial tool in guarding valuable business data against theft, loss and other unauthorized access.&lt;/li&gt; 
  &lt;li&gt;Suitable cloud architectures. Workloads are better protected from harm when they run on properly configured cloud architectures.&lt;/li&gt; 
  &lt;li&gt;Monitoring and reporting. Tools that continuously observe activities and events and provide real-time security alerts are essential for maintaining cloud security.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;div class="youtube-iframe-container"&gt;
  &lt;iframe id="ytplayer-0" src="https://www.youtube.com/embed/JyQ_NHwA0QI?autoplay=0&amp;amp;modestbranding=1&amp;amp;rel=0&amp;amp;widget_referrer=null&amp;amp;enablejsapi=1&amp;amp;origin=https://searchcloudsecurity.techtarget.com" type="text/html" height="360" width="640" frameborder="0"&gt;&lt;/iframe&gt;
 &lt;/div&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Why is security management in the cloud important?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Why is security management in the cloud important?&lt;/h2&gt;
 &lt;p&gt;Failing to take ownership of cloud security is a serious blunder that could lead organizations to suffer data loss, system breaches and devastating attacks. In addition to the potential harm done to its customers and reputation, a business that's been breached can expect to incur costs on average of $4 million to $5 million, according to a 2023 study by IBM and the Ponemon Institute.&lt;/p&gt;
 &lt;p&gt;Perhaps naively, many organizations approach cloud computing with the notion that the business can offload the problems and responsibilities of everyday computing. While this might be true with respect to facilities maintenance and capital expenditures, a cloud customer still bears considerable responsibility for data compliance and security.&lt;/p&gt;
 &lt;p&gt;In fact, organizations that engage cloud services must reckon with &lt;a href="https://www.techtarget.com/searchsecurity/tip/Top-11-cloud-security-challenges-and-how-to-combat-them"&gt;numerous security challenges&lt;/a&gt;, owing to the enormous attack surface the cloud presents. In addition to data breaches, the following are some of the most pressing problems in managing cloud security:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Misconfigured cloud environments.&lt;/li&gt; 
  &lt;li&gt;Poorly secured APIs.&lt;/li&gt; 
  &lt;li&gt;Loose control over access and credentials.&lt;/li&gt; 
  &lt;li&gt;Insider threats.&lt;/li&gt; 
  &lt;li&gt;Account hijacking.&lt;/li&gt; 
  &lt;li&gt;Shadow IT.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;The &lt;a href="https://www.techtarget.com/searchsecurity/tip/Private-vs-public-cloud-security-Benefits-and-drawbacks"&gt;type of cloud environment an organization selects&lt;/a&gt; also affects security management and therefore must be carefully considered. Private, public and hybrid options each have advantages and drawbacks. With a public cloud strategy, a customer gains access to a service provider's cybersecurity tools and expertise, which will almost always be more extensive than what that business could muster on its own. Offloading some of those management duties comes with a tradeoff, however. It's the service provider -- not the customer -- that makes important cybersecurity decisions. And because the provider's underlying technologies are abstracted, a business will have little visibility into the resources on which its workloads run.&lt;/p&gt;
 &lt;figure class="main-article-image full-col" data-img-fullsize="https://searchcloudsecurity.techtarget.com/rms/onlineimages/cloudsecurity-cloud_security_challenges-f.png"&gt;
  &lt;img data-src="https://searchcloudsecurity.techtarget.com/rms/onlineimages/cloudsecurity-cloud_security_challenges-f_mobile.png" class="lazy" data-srcset="https://searchcloudsecurity.techtarget.com/rms/onlineimages/cloudsecurity-cloud_security_challenges-f_mobile.png 960w,https://searchcloudsecurity.techtarget.com/rms/onlineimages/cloudsecurity-cloud_security_challenges-f.png 1280w" alt="Cloud security challenges" height="333" width="560"&gt;
  &lt;div class="main-article-image-enlarge"&gt;
   &lt;i class="icon" data-icon="w"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/figure&gt;
 &lt;p&gt;With a private cloud environment, an organization has full control of and visibility into its security picture; doing so, however, means accepting greater costs and complexity. And while a hybrid approach -- part public, part private -- might seem like the perfect compromise, it presents challenges, too, including policy enforcement across environments.&lt;/p&gt;
 &lt;p&gt;Companies must bear in mind that an attack on a single user's credentials can affect the entire organization. The fallout from cloud attacks is often exponential, and the blast radius of attacks continues to expand.&lt;/p&gt;
&lt;/section&gt;         
&lt;section class="section main-article-chapter" data-menu-title="What are the benefits of cloud security management?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What are the benefits of cloud security management?&lt;/h2&gt;
 &lt;p&gt;Protecting cloud workloads and data is a demanding task. Still, when carefully implemented and managed, cloud security efforts give an organization the chance to fend off malicious actions. Not every threat can be stopped, but a business and a cloud provider working in concert can put formidable obstacles between valuable data and those who seek to take it.&lt;/p&gt;
 &lt;p&gt;Effective cloud security delivers advantages over a do-it-yourself approach to on-premises IT security, including the following benefits:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Better tools.&lt;/b&gt; Cloud service providers offer comprehensive security tools that can scan, analyze, report and alert on potential security threats with a high degree of effectiveness. This alleviates the need for users to install and operate their own security applications or tools in the cloud.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Security services.&lt;/b&gt; Service providers typically offer &lt;a href="https://www.techtarget.com/searchstorage/definition/cloud-encryption-cloud-storage-encryption"&gt;cloud encryption&lt;/a&gt; and other services, such as data loss prevention (DLP), that are designed to protect business data at rest and in flight. Data backups, recovery, disaster recovery and other services can further protect vital business data from harm.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Lower security costs.&lt;/b&gt; Businesses can often lower security costs and improve security effectiveness when using the sophisticated security tools and services supplied through cloud providers. These offerings are typically updated more frequently and tested more comprehensively than security tools deployed in local data centers.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="What are the challenges of cloud security management?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What are the challenges of cloud security management?&lt;/h2&gt;
 &lt;p&gt;The cloud model requires users to come to terms with its inherent complexity. Cloud management is a difficult and ongoing task. From a security perspective, the challenges include the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Shared responsibility.&lt;/b&gt; Cloud computing operates on a &lt;a href="https://www.techtarget.com/searchcloudcomputing/definition/shared-responsibility-model"&gt;shared responsibility model&lt;/a&gt;, but there are often misunderstandings about which responsibilities fall to the service provider and which belong to the customer. When there's confusion, the likelihood increases that something important will be missed. That creates critical gaps in security management.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Limited visibility.&lt;/b&gt; If you can't see it, you can't manage it. It's an old axiom that perfectly suits cloud security efforts. A business that migrates its applications and data to cloud environments confronts a complicated situation in which control is decentralized. Different business teams and divisions, for example, might each make decisions about how they use cloud services. Without a means of discovering, tracking and reporting on the assets present in the cloud, an in-house security team might not even know what it is supposed to be managing.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Compliance challenges.&lt;/b&gt; A business is obligated to know where its cloud data is located and how it is being used. When a cloud provider obscures this information -- or a user does not bother to access this information -- the business could experience a costly breach in regulatory compliance. It's important to understand the tools and visibility offered by a provider and to know how that information helps a business meet its compliance requirements.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Limited control.&lt;/b&gt; While they can assert considerable control over user authorization and authentication, public cloud customers typically have little control over the underlying cloud infrastructure, which is owned by the service provider. This can lead to security concerns in how data is accessed and shared.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Cloud differences.&lt;/b&gt; As businesses explore hybrid and multi-cloud environments, they will find any number of differences in tools, services, configurations and capabilities. For instance, &lt;a href="https://www.techtarget.com/searchsecurity/tip/Multi-cloud-security-challenges-and-best-practices"&gt;multi-cloud security poses some specific challenges&lt;/a&gt;. These differences could result in a business having an inconsistent or incomplete security posture. Consultations with the providers can help address this heterogeneity.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Who is responsible for cloud security?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Who is responsible for cloud security?&lt;/h2&gt;
 &lt;p&gt;Security in cloud computing relies on the shared responsibility model, which places certain responsibilities on the cloud service provider and other responsibilities on the cloud customer. At a high level, this model stipulates that the service provider bears responsibility for security &lt;i&gt;of&lt;/i&gt; its cloud, while the cloud customer is responsible for security &lt;i&gt;in&lt;/i&gt; the cloud. It might seem like a fine distinction, but it's a vital one to understand:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;A cloud provider ensures that its infrastructure and services operate in a secure manner. Its servers and networks, for example, must be set up and configured securely.&lt;/li&gt; 
  &lt;li&gt;A cloud user takes steps to deploy the security features necessary to &lt;a href="https://www.techtarget.com/searchsecurity/tip/VM-security-in-cloud-computing-explained"&gt;securely operate VMs&lt;/a&gt; and workloads while carefully controlling access to that cloud environment.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;As an example, suppose a cloud provider offers IAM services to help customers manage user access to workloads and data. A customer that chooses to forego those services effectively opens access to workloads and data to anyone. The business has neglected its duty to maintain cloud security and, in the process, likely violated compliance and other regulatory obligations. In this scenario, the cloud customer -- not the service provider -- would bear responsibility for any data loss.&lt;/p&gt;
 &lt;p&gt;While traditional enterprise security teams can take on some cloud security duties, specific expertise is needed to ensure the ongoing and effective protection of cloud data and workloads. For example, a skilled &lt;a href="https://www.techtarget.com/searchsecurity/tip/What-is-a-cloud-security-engineer-and-how-do-I-become-one"&gt;cloud security engineer&lt;/a&gt; will have knowledge about cloud platforms, programming languages, security tools and other relevant topics.&lt;/p&gt;
 &lt;p&gt;An in-house security team might address &lt;a href="https://www.techtarget.com/searchsecurity/tip/4-steps-toward-cloud-security-automation"&gt;cloud security automation in four key areas&lt;/a&gt;:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Container, VM and serverless computing configurations.&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.techtarget.com/searchitoperations/definition/Infrastructure-as-Code-IAC"&gt;Infrastructure as code&lt;/a&gt; and other automated infrastructure composition techniques.&lt;/li&gt; 
  &lt;li&gt;Asset tagging and other cloud inventory management tactics.&lt;/li&gt; 
  &lt;li&gt;Vulnerability scanning.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Setting and managing IaaS controls and processes in these areas enables smooth and consistent deployments, proper auditing and reporting, and policy application and enforcement.&lt;/p&gt;
 &lt;p&gt;These special-purpose teams should &lt;a href="https://www.techtarget.com/searchcio/tip/Top-cloud-compliance-standards-and-how-to-use-them"&gt;follow cloud compliance standards&lt;/a&gt; closely, making sure service providers are current on the latest industry requirements. Various professional and technical organizations address compliance standards, offering recommendations and guidance for successful cloud implementation.&lt;/p&gt;
 &lt;figure class="main-article-image full-col" data-img-fullsize="https://searchcloudsecurity.techtarget.com/rms/onlineimages/certification_options_for_cloud_security_engineers-f.png"&gt;
  &lt;img data-src="https://searchcloudsecurity.techtarget.com/rms/onlineimages/certification_options_for_cloud_security_engineers-f_mobile.png" class="lazy" data-srcset="https://searchcloudsecurity.techtarget.com/rms/onlineimages/certification_options_for_cloud_security_engineers-f_mobile.png 960w,https://searchcloudsecurity.techtarget.com/rms/onlineimages/certification_options_for_cloud_security_engineers-f.png 1280w" alt="Graphic of a table listing cloud security engineer certifications, their issuing organization and key features." height="444" width="560"&gt;
  &lt;div class="main-article-image-enlarge"&gt;
   &lt;i class="icon" data-icon="w"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/figure&gt;
 &lt;p&gt;Cloud security training continues to improve, and &lt;a href="https://www.techtarget.com/searchsecurity/tip/The-best-cloud-security-certifications-for-IT-professionals"&gt;certifications can demonstrate professional training&lt;/a&gt;. The ISC2 &lt;a href="https://www.isc2.org/Certifications/CCSP" target="_blank" rel="noopener"&gt;Certified Cloud Security Professional&lt;/a&gt; program, for example, tests a cybersecurity professional's technical skills in securing cloud applications and infrastructure. Another popular certification is the &lt;a href="https://cloudsecurityalliance.org/education/ccsk" target="_blank" rel="noopener"&gt;Certificate of Cloud Security Knowledge&lt;/a&gt; from the &lt;a href="https://www.techtarget.com/searchsecurity/definition/Cloud-Security-Alliance-CSA"&gt;Cloud Security Alliance&lt;/a&gt;. Test takers must show expertise in data encryption, identity access, incident response and other essential aspects of cloud security. Cybersecurity training is also available from GIAC, Arcitura, SANS Institute and other groups.&lt;/p&gt;
&lt;/section&gt;           
&lt;section class="section main-article-chapter" data-menu-title="Building a cloud security policy"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Building a cloud security policy&lt;/h2&gt;
 &lt;p&gt;Any organization that commits to cloud computing will want to &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-create-a-cloud-security-policy-step-by-step"&gt;create a cloud security policy&lt;/a&gt;. The policy should address critical considerations, such as how employees can interact with the cloud, the types of data the organization will allow in the cloud, access controls for a cloud environment and more.&lt;/p&gt;
 &lt;p&gt;To design a cloud security policy, consider these starting points:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Add cloud elements into an existing cybersecurity policy.&lt;/li&gt; 
  &lt;li&gt;Evaluate and select software from vendors that can produce policies quickly.&lt;/li&gt; 
  &lt;li&gt;Review cloud security standards for frameworks and content that can be built into the policy.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;When a policy is not in place, a company could be at greater risk of security breaches and data loss. A business without relevant policies might also face penalties for noncompliance.&lt;/p&gt;
 &lt;p&gt;How you organize cloud security policies will also depend on the type of cloud service being used: &lt;a href="https://www.techtarget.com/searchcloudcomputing/definition/Software-as-a-Service"&gt;SaaS&lt;/a&gt;, &lt;a href="https://www.techtarget.com/searchcloudcomputing/definition/Infrastructure-as-a-Service-IaaS"&gt;IaaS&lt;/a&gt; or &lt;a href="https://www.techtarget.com/searchcloudcomputing/definition/Platform-as-a-Service-PaaS"&gt;PaaS&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;&lt;b&gt;SaaS security best practices.&lt;/b&gt; SaaS is not a monolithic service and shouldn't be treated as such when it comes to security. Organizations should review the &lt;a href="https://www.techtarget.com/searchsecurity/tip/6-SaaS-security-best-practices-to-protect-applications"&gt;best practices to protect SaaS-based applications&lt;/a&gt; and apply the ones that best fit the service being adopted. Experts advise customers to inventory cloud assets, as this clarifies exactly which applications are in use; to deploy enhanced authentication, such as &lt;a href="https://www.techtarget.com/searchsecurity/definition/multifactor-authentication-MFA"&gt;multifactor authentication&lt;/a&gt;, where possible; and to encrypt data in motion and at rest.&lt;/p&gt;
 &lt;p&gt;&lt;b&gt;IaaS security best practices.&lt;/b&gt; Like SaaS, IaaS requires organizations to consider how to encrypt data and inventory cloud assets, but securing infrastructure in the cloud requires even more attention. IaaS gives users extensive access to the provider's resources and services, which can be composed as desired to create an operating environment suitable for hosting a business workload and data. Organizations need to &lt;a href="https://www.techtarget.com/searchsecurity/tip/5-step-IaaS-security-checklist-for-cloud-customers"&gt;develop an IaaS security checklist&lt;/a&gt;. This begins with understanding a specific cloud provider's security practices, ensuring consistent patching and managing access.&lt;/p&gt;
 &lt;figure class="main-article-image full-col" data-img-fullsize="https://searchcloudsecurity.techtarget.com/rms/onlineimages/cloudcomputing-iaas_security_checklist-f.png"&gt;
  &lt;img data-src="https://searchcloudsecurity.techtarget.com/rms/onlineimages/cloudcomputing-iaas_security_checklist-f_mobile.png" class="lazy" data-srcset="https://searchcloudsecurity.techtarget.com/rms/onlineimages/cloudcomputing-iaas_security_checklist-f_mobile.png 960w,https://searchcloudsecurity.techtarget.com/rms/onlineimages/cloudcomputing-iaas_security_checklist-f.png 1280w" height="246" width="559"&gt;
  &lt;div class="main-article-image-enlarge"&gt;
   &lt;i class="icon" data-icon="w"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/figure&gt;
 &lt;p&gt;&lt;b&gt;PaaS security best practices.&lt;/b&gt; &lt;a href="https://www.techtarget.com/searchsecurity/tip/5-PaaS-security-best-practices-to-safeguard-the-application-layer"&gt;PaaS security guidelines&lt;/a&gt; recommend that organizations be deeply involved in the protection of their platform services and not leave the details to the provider. For example, enterprises should engage in threat modeling and the deconstruction of an application design, which will help identify vulnerabilities and mitigate them. The PaaS provider will offer security tooling and capabilities, but it's up to PaaS users to employ those features. Another key best practice for PaaS users is to carefully plan out portability so the organization isn't bound to one provider. For example, software development PaaS users might choose to work with common programming languages -- such as C#, Python and Java -- that are widely supported.&lt;/p&gt;
&lt;/section&gt;          
&lt;section class="section main-article-chapter" data-menu-title="Cloud security management strategies"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Cloud security management strategies&lt;/h2&gt;
 &lt;p&gt;Rarely do organizations have a single cloud environment. It's more likely that they have multiple ones to address various data, application, platform and infrastructure needs. Managing disparate cloud services can be challenging, so organizations need a sound strategy that protects corporate assets while maintaining compliance and managing costs.&lt;/p&gt;
 &lt;p&gt;To prevent or rein in sprawl, organizations should centralize the procurement, deployment and management of their multi-cloud environments. Doing so can ensure an organization's security policies and compliance requirements are applied and enforced. Centralizing also is critical for organizations to be able to collaborate and communicate in a uniform way about threats and mitigation strategies. Emerging &lt;a href="https://www.techtarget.com/searchcloudcomputing/tip/The-relationship-between-cloud-FinOps-and-security"&gt;FinOps practices&lt;/a&gt; can help establish collaborative cross-discipline teams tasked with managing cloud use, security and spending.&lt;/p&gt;
 &lt;p&gt;Cloud security teams need to test their cloud environments regularly. Testing is essential for the shared responsibility model, where in-house and provider security teams together assume the role of protecting assets in the cloud. &lt;a href="https://www.techtarget.com/searchsecurity/definition/cloud-penetration-testing"&gt;Cloud penetration testing&lt;/a&gt; is a useful way to test the shared responsibility model and the security of a cloud environment overall.&lt;/p&gt;
 &lt;p&gt;Some organizations in highly regulated or high-risk industries might want to employ &lt;a href="https://www.techtarget.com/searchsecurity/tip/Cloudcomputing-forensics-techniques-for-evidence-acquisition"&gt;forensics techniques in their cloud environment&lt;/a&gt;. Automation should be top of mind for this goal so that organizations can not only inspect and analyze information in the cloud for court proceedings (e.g., network packets, workload memory, workload disk volumes, logs and other event data) but also mitigate any problems that are discovered.&lt;/p&gt;
 &lt;p&gt;One of the most significant types of attacks security teams must ward off through better cloud security management is account hijacking, in which hackers compromise a subscription or other type of cloud account to engage in malicious activity. To &lt;a href="https://www.techtarget.com/searchsecurity/tip/Prevent-cloud-account-hijacking-with-3-key-strategies"&gt;protect against account hijacking&lt;/a&gt;, security teams should take three crucial steps: require multifactor authentication; segregate duties; and trust but verify account access.&lt;/p&gt;
 &lt;p&gt;One often overlooked aspect of cloud security testing and security management is information sharing. Although there are many tools and practices that can help to find and fix security problems, answers to the following questions can easily be lost or ignored unless documented and shared across the cloud management team:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;What happened?&lt;/li&gt; 
  &lt;li&gt;Why did it happen?&lt;/li&gt; 
  &lt;li&gt;What was the root cause?&lt;/li&gt; 
  &lt;li&gt;What was the remediation?&lt;/li&gt; 
  &lt;li&gt;What were the results?&lt;/li&gt; 
  &lt;li&gt;How should policy, practices and processes be adjusted?&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Information sharing enables the entire cloud management team to benefit and learn from problems or incidents that affect cloud security.&lt;/p&gt;
&lt;/section&gt;         
&lt;section class="section main-article-chapter" data-menu-title="Implementing cloud security management"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Implementing cloud security management&lt;/h2&gt;
 &lt;p&gt;Approaches to implementing and managing cloud security are as varied as the tools and businesses that use cloud computing. Still, several guiding principles can be applied to implementation:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Understand the business drivers and goals.&lt;/b&gt; Cloud security -- and its proper management -- is there for a purpose, which is to serve the business and facilitate business interests. Any implementation of cloud security management should be in response to business needs. A highly regulated business, for example, will make compliance a primary goal of its security efforts.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Understand the threats.&lt;/b&gt; From malware to intrusion to disasters, it's vital to understand where the attacks will come from and how those attacks put the business -- and its goals -- at risk. Perform regular security audits on cloud-based workloads, data and services. By properly identifying the threats it faces, an organization will find it easier to build new policies and processes as well as to select tools suitable for the task.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Select and implement tools.&lt;/b&gt; A business has plenty of tools, platforms and services available to help manage cloud security. One size does not fit all, and each product has specific strengths and tradeoffs. Knowing the business goals and intended practices, however, makes the job of finding and validating cloud security management tools considerably easier. This could still require some adjustments to principles and practices, but the underlying ideas should be consistent.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Encrypt data and monitor.&lt;/b&gt; Data should ideally be encrypted at rest and in flight. User and workload access should adopt a &lt;a href="https://www.techtarget.com/searchsecurity/definition/zero-trust-model-zero-trust-network"&gt;zero-trust&lt;/a&gt; model and other highly restricted postures. Monitor network traffic and watch for intrusion. Scan for malicious activity, such as unauthorized data access. Oversee end users and devices.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Report.&lt;/b&gt; Use the alerting and reporting features of cloud security systems to deliver timely security reports to cloud workload stakeholders and business leaders. Recognize the threats (e.g., an unpatched OS) and take proactive action to mitigate those risks.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Reevaluate.&lt;/b&gt; Threats and business needs are always changing, and so should cloud security. To address new and emerging threats, a business will likely need a team effort involving business, technology and legal leadership from across the organization.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Other strategies an organization might consider include adoption of &lt;a href="https://www.techtarget.com/searchsecurity/definition/cloud-infrastructure-entitlement-management-CIEM"&gt;cloud infrastructure entitlement management&lt;/a&gt;, a discipline that aims to more rigorously track who has access to cloud infrastructure, and &lt;a href="https://www.techtarget.com/searchsecurity/tip/Cloud-vulnerability-management-A-complete-guide"&gt;cloud vulnerability management&lt;/a&gt;, an emerging tactic to provide continuous remediation of detected vulnerabilities.&lt;/p&gt;
 &lt;p&gt;Not surprisingly, &lt;a href="https://www.techtarget.com/searchsecurity/tip/Ways-AI-is-transforming-cloud-security-according-to-experts"&gt;security vendors are attempting to incorporate AI&lt;/a&gt; into their products. Experts predict AI will be helpful in the following areas, among others:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Detection and remediation of misconfigurations.&lt;/li&gt; 
  &lt;li&gt;User behavior analysis.&lt;/li&gt; 
  &lt;li&gt;Threat detection and response.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;The prospect of AI being used offensively is a growing concern. In fact, 38% of respondents in a 2024 survey of infosec professionals by Palo Alto Networks ranked AI-powered attacks as one of their leading cloud security worries.&lt;/p&gt;
 &lt;div class="youtube-iframe-container"&gt;
  &lt;iframe id="ytplayer-1" src="https://www.youtube.com/embed/D6nql-FGAyk?autoplay=0&amp;amp;modestbranding=1&amp;amp;rel=0&amp;amp;widget_referrer=null&amp;amp;enablejsapi=1&amp;amp;origin=https://searchcloudsecurity.techtarget.com" type="text/html" height="360" width="640" frameborder="0"&gt;&lt;/iframe&gt;
 &lt;/div&gt;
&lt;/section&gt;        
&lt;section class="section main-article-chapter" data-menu-title="A cloud security checklist"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;A cloud security checklist&lt;/h2&gt;
 &lt;p&gt;To determine the effectiveness of cloud security practices, an organization will need to be methodical about checking its defenses. It's not enough to simply implement security; these measures require ongoing assessment and adjustment.&lt;/p&gt;
 &lt;p&gt;A business should take the time to develop a &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-conduct-a-cloud-security-assessment"&gt;cloud security assessment process&lt;/a&gt;. Through this process, IT teams will learn about potential risks they did not know they faced. Plus, they'll be able to learn the answers to important questions, such as the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;How extensive is our attack surface?&lt;/b&gt; A business cannot mount an adequate defense against cloud threats until it determines exactly how many cloud services and applications are in use.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Which assets are most at risk?&lt;/b&gt; An assessment can identify where insufficiently secured images and workloads are being created.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Are IAM practices effective?&lt;/b&gt; Organizations that carefully examine their access policies typically find they have been overly generous with granting of permissions. By limiting access, you limit risks.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Is the architecture properly designed?&lt;/b&gt; Service providers can help their customers design cloud environments that stand a better chance of withstanding an attack.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Do we know when there's a problem?&lt;/b&gt; Tools that monitor and log cloud security incidents can be useful, but these tools need to be checked to verify that they are paying attention to the right things.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;What about compliance?&lt;/b&gt; Routine assessments will give an organization the chance to see how well it is meeting its compliance responsibilities.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;In addition to uncovering potentially unpleasant surprises, ongoing security assessments will reinforce the absolutely essential idea that the cloud security task is never fully accomplished.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="Cloud security tools"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Cloud security tools&lt;/h2&gt;
 &lt;p&gt;Some security tools used on-premises can be extended to protect cloud workloads, but &lt;a href="https://www.techtarget.com/searchsecurity/feature/CASB-CSPM-CWPP-emerge-as-future-of-cloud-security"&gt;tools and tactics designed specifically for cloud computing&lt;/a&gt; will provide more seamless and comprehensive protection. Here are some common product categories:&lt;/p&gt;
 &lt;p&gt;&lt;b&gt;Cloud access security brokers.&lt;/b&gt; Cloud access security brokers (&lt;a href="https://www.techtarget.com/searchcloudcomputing/definition/cloud-access-security-broker-CASB"&gt;CASBs&lt;/a&gt;) serve as a security policy enforcement gateway to ensure users' actions are authorized and compliant with company policies. They have four main characteristics: visibility, compliance, threat protection and data security.&lt;/p&gt;
 &lt;p&gt;&lt;a href="https://www.techtarget.com/searchcloudcomputing/feature/Explore-CASB-use-cases-before-you-decide-to-buy"&gt;CASBs also have business-critical use cases&lt;/a&gt;, such as cloud application usage tracking and user behavior analytics.&lt;/p&gt;
 &lt;figure class="main-article-image full-col" data-img-fullsize="https://searchcloudsecurity.techtarget.com/rms/onlineimages/cloud_computing-casb_core_features.png"&gt;
  &lt;img data-src="https://searchcloudsecurity.techtarget.com/rms/onlineimages/cloud_computing-casb_core_features_mobile.png" class="lazy" data-srcset="https://searchcloudsecurity.techtarget.com/rms/onlineimages/cloud_computing-casb_core_features_mobile.png 960w,https://searchcloudsecurity.techtarget.com/rms/onlineimages/cloud_computing-casb_core_features.png 1280w" height="314" width="560"&gt;
  &lt;div class="main-article-image-enlarge"&gt;
   &lt;i class="icon" data-icon="w"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/figure&gt;
 &lt;p&gt;&lt;b&gt;Cloud security posture management tools.&lt;/b&gt; Cloud security posture management (&lt;a href="https://www.techtarget.com/searchsecurity/definition/Cloud-Security-Posture-Management-CSPM"&gt;CSPM&lt;/a&gt;) tools enable companies to perform continuous compliance monitoring, prevent configuration drift, set limits on permittable configurations or behavior in the cloud and support security operations center investigations.&lt;/p&gt;
 &lt;p&gt;Organizations can use CSPM tools to uniformly apply cloud security best practices to increasingly complex systems, such as hybrid, multi-cloud and container environments.&lt;/p&gt;
 &lt;p&gt;&lt;b&gt;Cloud workload protection platforms.&lt;/b&gt; A cloud workload protection platform (&lt;a href="https://www.techtarget.com/searchsecurity/definition/cloud-workload-protection-platform-CWPP"&gt;CWPP&lt;/a&gt;) can safeguard workloads regardless of whether they run on a physical server, on a virtual server, as a serverless function or in a container. A CWPP tool should enhance security through several key capabilities, including the following functions:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Tracking workloads on premises and in one or more cloud environments.&lt;/li&gt; 
  &lt;li&gt;Monitoring workload configurations.&lt;/li&gt; 
  &lt;li&gt;Scanning for malware.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;&lt;b&gt;Cloud-native application protection platform.&lt;/b&gt; One of the stresses of cloud security management is the abundance of security tools on the market. Vendors in the cloud-native application protection platform (&lt;a href="https://www.techtarget.com/searchsecurity/definition/cloud-native-application-protection-platform-CNAPP"&gt;CNAPP&lt;/a&gt;) category seek to address this by bundling capabilities from several tools into a single product. These tools are designed to integrate multiple security functions, including monitoring, response, analysis and optimization, thereby reducing the number of standalone products a team would need to select, adopt and manage.&lt;/p&gt;
&lt;/section&gt;          
&lt;section class="section main-article-chapter" data-menu-title="Cloud security management vendors"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Cloud security management vendors&lt;/h2&gt;
 &lt;p&gt;There are countless vendors and products available for cloud security management. Each product, platform or service focuses on unique specialties or use cases; might offer some overlap in CASB, CSPM, CNAPP or CWPP areas; and carries its own unique tradeoffs for enterprise users. As with most enterprise tools, it's worth evaluating a number of offerings and investing in proof-of-concept projects to identify and validate preferred products before making a commitment.&lt;/p&gt;
 &lt;p&gt;Examples of &lt;strong&gt;CASB&lt;/strong&gt; vendors and tools include the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Avast Secure Internet Gateway.&lt;/li&gt; 
  &lt;li&gt;Cato SASE Cloud.&lt;/li&gt; 
  &lt;li&gt;Citrix Secure Workspace Access.&lt;/li&gt; 
  &lt;li&gt;Citrix Workspace Essentials.&lt;/li&gt; 
  &lt;li&gt;Forcepoint One.&lt;/li&gt; 
  &lt;li&gt;Fortinet FortiCASB.&lt;/li&gt; 
  &lt;li&gt;Microsoft Defender for Cloud.&lt;/li&gt; 
  &lt;li&gt;Netskope.&lt;/li&gt; 
  &lt;li&gt;Oracle CASB Cloud Service.&lt;/li&gt; 
  &lt;li&gt;Proofpoint Cloud App Security Broker.&lt;/li&gt; 
  &lt;li&gt;SonicWall Cloud App Security.&lt;/li&gt; 
  &lt;li&gt;Symantec CloudSOC CASB.&lt;/li&gt; 
  &lt;li&gt;Symantec Cloud Secure Web Gateway.&lt;/li&gt; 
  &lt;li&gt;Trend Micro Cloud App Security.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Examples of &lt;strong&gt;CSPM&lt;/strong&gt; vendors and tools include the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Check Point CloudGuard.&lt;/li&gt; 
  &lt;li&gt;CrowdStrike Falcon Cloud Security.&lt;/li&gt; 
  &lt;li&gt;Cyscale.&lt;/li&gt; 
  &lt;li&gt;Lacework Polygraph Data Platform.&lt;/li&gt; 
  &lt;li&gt;Microsoft Defender for Cloud.&lt;/li&gt; 
  &lt;li&gt;Orca Security.&lt;/li&gt; 
  &lt;li&gt;Palo Alto Networks Prisma Cloud.&lt;/li&gt; 
  &lt;li&gt;Rapid7 InsightCloudSec.&lt;/li&gt; 
  &lt;li&gt;Sonrai Security.&lt;/li&gt; 
  &lt;li&gt;Sysdig Secure.&lt;/li&gt; 
  &lt;li&gt;Tenable Cloud Security.&lt;/li&gt; 
  &lt;li&gt;Trend Micro Cloud One Conformity.&lt;/li&gt; 
  &lt;li&gt;Zscaler Posture Control.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Examples of &lt;strong&gt;CWPP&lt;/strong&gt; vendors and tools include the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;AWS Control Tower.&lt;/li&gt; 
  &lt;li&gt;AWS GuardDuty.&lt;/li&gt; 
  &lt;li&gt;Check Point CloudGuard Network Security (IaaS).&lt;/li&gt; 
  &lt;li&gt;CrowdStrike Falcon Cloud Security.&lt;/li&gt; 
  &lt;li&gt;Google Cloud Security.&lt;/li&gt; 
  &lt;li&gt;Illumio Core.&lt;/li&gt; 
  &lt;li&gt;Microsoft Defender for Cloud.&lt;/li&gt; 
  &lt;li&gt;Orca Security.&lt;/li&gt; 
  &lt;li&gt;Palo Alto Networks Prisma Cloud.&lt;/li&gt; 
  &lt;li&gt;PingSafe.&lt;/li&gt; 
  &lt;li&gt;SentinelOne Singularity Cloud.&lt;/li&gt; 
  &lt;li&gt;Sophos Cloud Workload Protection.&lt;/li&gt; 
  &lt;li&gt;Trend Micro Deep Security.&lt;/li&gt; 
  &lt;li&gt;VMware Carbon Black Workload.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;&lt;b&gt;Editor's note:&lt;/b&gt;&lt;i&gt; The lists above have been assembled from varied research sources and are meant to provide examples only; they are not intended to represent all available products in a given area. Readers are advised to perform their own research and make product selections based on their own needs, research and testing results.&lt;/i&gt;&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Phil Sweeney is an industry editor and writer focused on information security topics.&lt;/i&gt;&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Stephen J. Bigelow, senior technology editor at TechTarget, has more than 20 years of technical writing experience in the technology industry.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>This cloud security guide explains challenges enterprises face today; best practices for securing and managing SaaS, IaaS and PaaS; and comparisons of cloud-native security tools.</description>
            <image>https://cdn.ttgtmedia.com/visuals/digdeeper/3.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/feature/What-is-cloud-security-management-A-strategic-guide</link>
            <pubDate>Tue, 04 Jun 2024 00:00:00 GMT</pubDate>
            <title>What is cloud security management? A strategic guide</title>
        </item>
        <item>
            <body>&lt;p&gt;Effective cloud security means more than implementing strong access and authentication controls or encrypting data at rest and in transit. What's needed is a set of rules for how cloud security is managed, and the key to that is a cloud security policy.&lt;/p&gt; 
&lt;p&gt;A &lt;a href="https://www.techtarget.com/searchsecurity/definition/cloud-security"&gt;cloud security&lt;/a&gt; policy contains detailed guidelines to help an organization ensure that it operates safely in the cloud. Because cloud resources can be used in multiple configurations of private, public and &lt;a href="https://www.techtarget.com/searchcloudcomputing/definition/hybrid-cloud"&gt;hybrid cloud&lt;/a&gt;, each of these arrangements must be accounted for when considering a &lt;a href="https://www.techtarget.com/searchsecurity/definition/security-policy"&gt;security policy&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;Let's look at what it takes to prepare a cloud security policy to address data breaches and security incidents. Also included here is a ready-to-use template to help prepare a basic cloud security policy.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Why is a cloud security policy important?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Why is a cloud security policy important?&lt;/h2&gt;
 &lt;p&gt;Most IT department policies and procedures complement each other. They define what is to be provided -- e.g., a cloud security policy -- and how policy compliance is achieved -- e.g., cloud security procedures, assessments and testing.&lt;/p&gt;
 &lt;p&gt;Without policies, companies could be at risk of security breaches, financial losses and other security consequences. Absence of relevant policies can be cited during IT audit activities and, in some cases, might result in noncompliance fines or other penalties.&lt;/p&gt;
 &lt;p&gt;&lt;a href="https://www.techtarget.com/searchsecurity/tip/Top-cloud-security-standards-and-frameworks-to-consider"&gt;Cloud security standards&lt;/a&gt; must also be examined for compliance requirements. One particular standard is ISO 27001:2022 Information security, cybersecurity and privacy protection -- Information security management systems -- Requirements. This global standard has specific requirements for compliance, and organizations can qualify for certification of compliance. Two important domestic cloud security standards include the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;NIST SP 800-53 Rev. 5 (2020), Security and Privacy Controls for Information Systems and Organizations. This is an important security standard and it applies to cloud services.&lt;/li&gt; 
  &lt;li&gt;NIST SP 800-144 (2011), Guidelines on Security and Privacy in Public Cloud Computing. This standard provides guidance on implementing public cloud security, including security measures, protecting user accounts, use of strong passwords and other authentication methods.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;In addition, customers might want assurances that their data will be protected from malware and other cyberattacks. Making the cloud security policy -- or an abbreviated version with key elements highlighted -- available for customer review can often alleviate fears of data damage or theft and improve brand reputation.&lt;/p&gt;
 &lt;p&gt;Cloud security policies are often written around topics such as the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Cloud security controls.&lt;/li&gt; 
  &lt;li&gt;Security management tools.&lt;/li&gt; 
  &lt;li&gt;Acceptable employee cloud use.&lt;/li&gt; 
  &lt;li&gt;Data allowed in the cloud.&lt;/li&gt; 
  &lt;li&gt;Data protection in the cloud.&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.techtarget.com/searchsecurity/tip/Incident-response-best-practices-for-your-organization"&gt;Incident response procedures&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;Cloud access control.&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.techtarget.com/searchcio/tip/Top-cloud-compliance-standards-and-how-to-use-them"&gt;Cloud compliance standards&lt;/a&gt;.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;        
&lt;section class="section main-article-chapter" data-menu-title="Steps to create a cloud security policy"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Steps to create a cloud security policy&lt;/h2&gt;
 &lt;p&gt;To begin, six cost-effective options are available for creating a cloud security policy:&lt;/p&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;Adapt existing information security policies to cloud. These can use the existing policy structure and incorporate relevant components that address cloud security.&lt;/li&gt; 
  &lt;li&gt;Add cloud elements into an existing cybersecurity policy.&lt;/li&gt; 
  &lt;li&gt;Find &lt;a target="_blank" href="https://www.luc.edu/its/aboutits/itspoliciesguidelines/cloud_computing_policy.shtml/" rel="noopener"&gt;examples of policies&lt;/a&gt; and adapt them to your organization's needs.&lt;/li&gt; 
  &lt;li&gt;Evaluate and select software from vendors that can produce policies quickly.&lt;/li&gt; 
  &lt;li&gt;Review cloud security standards for frameworks and content that can be built into the policy.&lt;/li&gt; 
  &lt;li&gt;Use the cloud security policy template included in this article.&lt;/li&gt; 
 &lt;/ol&gt;
 &lt;p&gt;When preparing a cloud security policy, ensure the following steps are adhered to, at a minimum:&lt;/p&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;Identify the business purpose for having cloud security and, therefore, a cloud security policy and associated procedures.&lt;/li&gt; 
  &lt;li&gt;Secure senior management's approval to develop the policy.&lt;/li&gt; 
  &lt;li&gt;Establish a project plan to develop and approve the policy.&lt;/li&gt; 
  &lt;li&gt;Convene a team to develop the draft policy.&lt;/li&gt; 
  &lt;li&gt;Ask the cloud vendor(s) to assist with policy development.&lt;/li&gt; 
  &lt;li&gt;Schedule management briefings during the writing to ensure relevant issues are addressed.&lt;/li&gt; 
  &lt;li&gt;If the cloud vendor(s) is part of the policy development team, ensure they are invited to meetings&lt;/li&gt; 
  &lt;li&gt;Invite legal and HR teams to review and comment.&lt;/li&gt; 
  &lt;li&gt;Invite internal audit and/or IT audit teams to review.&lt;/li&gt; 
  &lt;li&gt;Invite risk management department to review.&lt;/li&gt; 
  &lt;li&gt;Distribute the draft for final review (include the cloud vendor) for comments prior to submitting it for management approval.&lt;/li&gt; 
  &lt;li&gt;Secure management approval, then disseminate the policy to employees.&lt;/li&gt; 
  &lt;li&gt;Arrange security-awareness training sessions for employees.&lt;/li&gt; 
  &lt;li&gt;Establish a review and change process for the policy using &lt;a href="https://www.techtarget.com/searchcio/definition/change-management"&gt;change management&lt;/a&gt; procedures.&lt;/li&gt; 
  &lt;li&gt;Schedule and prepare for annual audits of the policy.&lt;/li&gt; 
 &lt;/ol&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;div class="imagecaption alignRight"&gt;&lt;/div&gt; 
   &lt;div class="imagecaption alignRight"&gt; 
    &lt;a href="https://cdn.ttgtmedia.com/rms/pdf/Cloud_security_policy_template.docx" target="_blank" rel="noopener"&gt;&lt;img src="https://cdn.ttgtmedia.com/rms/onlineimages/cloud_security_policy_template_cover.png" alt="Cloud security policy template"&gt;&lt;/a&gt; 
   &lt;/div&gt; 
   &lt;h3&gt;Cloud security policy template&lt;/h3&gt; This cloud security policy template provides suggested wording for the policy and identifies areas to be completed by the policy author(s). The template can be modified in any way your policy development team sees fit. 
   &lt;br&gt; 
   &lt;br&gt; 
   &lt;br&gt; 
   &lt;br&gt; 
   &lt;br&gt; 
   &lt;br&gt; 
   &lt;br&gt; 
   &lt;br&gt;
  &lt;/div&gt;
 &lt;/div&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="Components of a cloud security policy"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Components of a cloud security policy&lt;/h2&gt;
 &lt;p&gt;Policies for cloud security can be simple. A few paragraphs might suffice to describe relevant cloud activities without going into a lot of specifics. More details can and should be included as needed, but most IT departments will want to keep policies concise while still addressing the important issues.&lt;/p&gt;
 &lt;p&gt;The following is an outline of the necessary components of a cloud security policy:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Introduction.&lt;/b&gt; State the fundamental reasons for having a cloud security policy.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Purpose and scope.&lt;/b&gt; Provide details on the cloud policy's purpose and scope.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Statement of policy.&lt;/b&gt; State the cloud security policy in clear terms, including systems that might be affected, the cloud vendor(s) involved, standards that address cloud security and any other relevant data.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Policy leadership.&lt;/b&gt; State who is responsible for approving and implementing the policy.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Verification of policy compliance.&lt;/b&gt; State what is needed, such as assessments, exercises or penetration tests, to &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-conduct-a-cloud-security-assessment"&gt;verify cloud security activities comply with policies&lt;/a&gt;. If a service-level agreement (SLA) is in place, it should be noted in the policy.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Penalties for noncompliance.&lt;/b&gt; Define penalties -- for example, verbal reprimand and a note in the personnel file for internal incidents or fines and legal action for external activities -- for failure to comply with policies and SLAs if they are part of the policy.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Appendices (as needed).&lt;/b&gt; Provide additional reference information, such as lists of contacts, standards and frameworks, SLAs or additional details on specific cloud security policy statements.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Things to remember"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Things to remember&lt;/h2&gt;
 &lt;p&gt;Once a cloud security policy has been approved and put into effect, think of it as a &lt;i&gt;living&lt;/i&gt; document -- not a static one. Use the policy to help establish &lt;a href="https://www.techtarget.com/searchsecurity/tip/7-key-cybersecurity-metrics-for-the-board-and-how-to-present-them"&gt;key performance indicators for security&lt;/a&gt;, plan for future audits, ensure compliance and establish a culture where security is emphasized. In addition, be sure the policy includes requirements for regular testing of cloud security services, using tools, penetration tests and breach-attack simulations.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Paul Kirvan is an independent consultant, IT auditor, technical writer, editor and educator. He has more than 25 years of experience in business continuity, disaster recovery, security, enterprise risk management, telecom and IT auditing.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>What are the necessary components of a cloud security policy, and why should an organization go to the trouble to create one? Download a template to get the process started.</description>
            <image>https://cdn.ttgtmedia.com/visuals/LeMagIT/hero_article/Clouds.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/tip/How-to-create-a-cloud-security-policy-step-by-step</link>
            <pubDate>Mon, 13 May 2024 09:00:00 GMT</pubDate>
            <title>How to create a cloud security policy, step by step</title>
        </item>
        <item>
            <body>&lt;section class="section main-article-chapter" data-menu-title="What is the Cloud Security Alliance?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What is the Cloud Security Alliance?&lt;/h2&gt;
 &lt;p&gt;The Cloud Security Alliance (CSA) is a nonprofit organization that promotes research into best practices for securing cloud computing and the use of cloud technologies to secure other forms of computing. CSA uses the expertise of industry practitioners, associations and governments, as well as its corporate and individual members, to offer research, education, certification, events and products specific to cloud security.&lt;/p&gt;
 &lt;p&gt;The organization's activities, knowledge and extensive network benefit the entire cloud community, including cloud service providers (CSPs), customers, entrepreneurs and governments. CSA also &lt;a href="https://cloudsecurityalliance.org/circle/" target="_blank" rel="noopener"&gt;offers a forum&lt;/a&gt; through which all parties can work together to create and maintain a trusted cloud ecosystem.&lt;/p&gt;
 &lt;p&gt;The industry group provides security education and guidance to companies in different stages of cloud adoption and helps CSPs address security in their software delivery models. CSA membership is available to any interested parties with the expertise to contribute to the security of cloud computing.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Cloud Security Alliance research areas"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Cloud Security Alliance research areas&lt;/h2&gt;
 &lt;p&gt;CSA leads a number of ongoing research initiatives through which it provides white papers, tools and reports to help companies and vendors secure cloud computing services.&lt;/p&gt;
 &lt;p&gt;CSA working groups target 32 cloud security domains and address almost every aspect of cloud security. These include the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;The CSA IoT Working Group develops relevant use cases for internet of things (&lt;a href="https://www.techtarget.com/iotagenda/definition/Internet-of-Things-IoT"&gt;IoT&lt;/a&gt;) implementations and establishes actionable guidance to enable security practitioners to secure their deployments.&lt;/li&gt; 
  &lt;li&gt;The CSA Application Containers and Microservices Working Group conducts research on application &lt;a href="https://www.techtarget.com/searchitoperations/definition/container-containerization-or-container-based-virtualization"&gt;containers&lt;/a&gt; and &lt;a href="https://www.techtarget.com/searchapparchitecture/definition/microservices"&gt;microservices&lt;/a&gt; security. It is charged with publishing guidance and best practices for the secure use of application containers and microservices.&lt;/li&gt; 
  &lt;li&gt;The CSA SaaS Governance Working Group encourages and defines mechanisms to promote cooperation and helps vendors and customers work closely together to manage &lt;a href="https://www.techtarget.com/searchcloudcomputing/definition/Software-as-a-Service"&gt;software-as-a-service&lt;/a&gt; risks and guarantee the security of customer data and the resilience of the SaaS cloud infrastructure.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="CSA programs and partnerships"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;CSA programs and partnerships&lt;/h2&gt;
 &lt;p&gt;CSA offers numerous programs and partnerships, such as CSA Security, Trust &amp;amp; Assurance Registry (STAR), which is a program for security assurance in the cloud. STAR incorporates the principles of transparency, rigorous auditing and the harmonization of standards. The STAR program offers several benefits, including "indications of best practices and validation of security posture of cloud offerings," according to the CSA website.&lt;/p&gt;
 &lt;p&gt;CSA Code of Conduct for GDPR Compliance offers a consistent and comprehensive framework to help companies comply with the European Union's General Data Protection Regulation. CSA Code of Conduct offers a &lt;a href="https://www.techtarget.com/searchdatamanagement/definition/compliance"&gt;compliance&lt;/a&gt; tool to achieve GDPR compliance, as well as transparency guidelines regarding the level of data protection offered by a cloud service provider.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="CSA membership"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;CSA membership&lt;/h2&gt;
 &lt;p&gt;Cloud Security Alliance offers three membership options:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Corporate Membership for Solution Providers offers a venue for members to learn about the latest developments in the cloud, showcase their expertise to a global audience and connect with users.&lt;/li&gt; 
  &lt;li&gt;Corporate Membership for Enterprises provides information, tools and guidance to help members realize the benefits of their cloud investments.&lt;/li&gt; 
  &lt;li&gt;Individual Membership offers any individual with an interest in cloud computing and the expertise to help make it more secure a complimentary individual membership based on a minimum level of participation.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;CSA currently has 90,000 individual members, 80 global chapters and 400 corporate members.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Cloud Security Alliance certifications"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Cloud Security Alliance certifications&lt;/h2&gt;
 &lt;p&gt;Cloud Security Alliance also offers professional cloud security certifications, such as the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;CSA STAR Certification is a rigorous, third-party, independent assessment of the security of a CSP. STAR Certification is based on achieving ISO/IEC 27001, as well as the specified set of criteria detailed in the Cloud Controls Matrix. Achieving the STAR Certification means that cloud providers will be able to offer prospective customers a greater understanding of their level of security control.&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://cloudsecurityalliance.org/education/ccsk/" target="_blank" rel="noopener"&gt;CSA CCSK&lt;/a&gt; (Certificate of Cloud Security Knowledge) is a web-based examination of a person's competency in the primary cloud security issues. The CCSK aims to provide an understanding of security issues and best practices over a range of cloud computing domains. Recommended for IT auditors, the CCSK is required for portions of the CSA STAR program.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;&lt;i&gt;This article was written by Linda Rosencrance in 2018. TechTarget editors revised it in 2024 to improve the reader experience.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>The Cloud Security Alliance (CSA) is a nonprofit organization that promotes research into best practices for securing cloud computing and the use of cloud technologies to secure other forms of computing.</description>
            <image>https://cdn.ttgtmedia.com/visuals/digdeeper/2.jpg</image>
            <link>https://www.techtarget.com/cybersecurity/definition/Cloud-Security-Alliance-CSA</link>
            <pubDate>Tue, 30 Apr 2024 13:31:00 GMT</pubDate>
            <title>Cloud Security Alliance (CSA)</title>
        </item>
        <title>SearchCloudSecurity Resources and Information from TechTarget</title>
        <ttl>60</ttl>
        <webMaster>webmaster@techtarget.com</webMaster>
    </channel>
</rss>
