Basics
Cloud security
Who is responsible for security in the cloud?
In the cloud responsibility is shared. The provider secures the technology your service runs on. You secure what you put into it and who may reach it. The second part is frequently overlooked.
The provider takes care of the data centre, the hardware and the availability of the platform. Your accounts, your permissions, your shares and your data remain your business. A publicly shared folder is not the provider's mistake.
The most common cloud incidents are unspectacular. An account taken over because it had no second factor. A share meant for one customer that stands open to everyone. A departed employee whose access nobody revoked. An administrator account used for everyday work.
So check regularly who has access, which data is shared and whether two factor authentication applies everywhere. Clarify the backup as well. Many providers secure the platform, but not your content against your own mistake or against encryption by attackers.
All terms in the knowledge base
Note: This entry reflects the state of knowledge to the best of our understanding and serves as general orientation. It is not legal advice. What counts is always the version currently in force at the responsible body, for example dsb.gv.at, nis.gv.at or enisa.europa.eu.
From the term to practice
Where does your business actually stand?
The IT Check reviews your IT across 8 audit areas with more than 100 individual checks and delivers documented findings with a prioritised action plan. From 1,299 € excl. VAT. The first call takes 20 minutes and carries no charge.