Security News > 2023 > February > Application and cloud security is a shared responsibility
Cloud and application security is everyone's responsibility - there isn't much of a choice.
Many enterprise cloud customers make the mistake of believing that they are free from obligation when it comes to application security, and they deploy the apps in the cloud, exposing themselves to security gaps at the seam of enterprise and cloud vendor infrastructures.
Comprehensive security has always required the enterprise to be responsible and proactive in their security defenses, but the fact of the matter is that enterprises are really forced to share in the responsibility.
Cloud and application security encompasses the entire ecosystem of people, processes, policies and technology that serve to protect the data that operates within, but security for things like data classification, network controls and physical security need clear owners.
The shared responsibility model for cloud security provides a clear breakdown of who should be doing what.
Today's cloud and application security providers have so many services and figuring out how to configure these services or understanding their security perimeters can be incredibly challenging, as it requires some special skills and training.
News URL
https://www.helpnetsecurity.com/2023/02/16/application-cloud-security-shared-responsibility/
Related news
- Whitepaper: Reach higher in your career with cloud security (source)
- Transforming cloud security with real-time visibility (source)
- Top 5 Cloud Security Automations for SecOps Teams (source)
- Microsoft lost some customers’ cloud security logs (source)
- How AI Is Changing the Cloud Security and Risk Equation (source)
- Strategies for CISOs navigating hybrid and multi-cloud security (source)
- Researchers Discover Severe Security Flaws in Major E2EE Cloud Storage Providers (source)
- Apple Opens PCC Source Code for Researchers to Identify Bugs in Cloud AI Security (source)
- Enhancing visibility for better security in multi-cloud and hybrid environments (source)