SHARE
Facebook X Pinterest WhatsApp

Ten Questions to Ask When Writing a Cloud Security Policy

Cloud security seems to baffle people, and it is not surprising why. It seems like no one is quite sure who is in charge of security in the cloud. Is it the company who owns the data stored there or is it the cloud provider? Or should it be some kind of combination of the […]

Written By
SP
Sue Poremba
Jul 2, 2013

Cloud security seems to baffle people, and it is not surprising why. It seems like no one is quite sure who is in charge of security in the cloud. Is it the company who owns the data stored there or is it the cloud provider? Or should it be some kind of combination of the two?

A combination of the data owner and the cloud provider may be the best option for security, but it has to be up to the data owner to make sure they are doing everything possible to make sure that information is kept secure. Yet, according to a Ponemon Institute study, 36 percent of businesses do not have a centralized cloud security policy in place and 45 percent do not enforce employees’ use of private clouds. This despite the increase of cloud adoption in the workspace.

So what do you need to know about developing a solid cloud security policy? According to Scott Hazdra, principal security consultant for Neohapsis, a security and risk management consulting company specializing in mobile and cloud security services, it is all about thinking of the right questions and understanding your cloud culture and what you are moving into the cloud.

Hazdra provided the following questions a company should ask when writing up a cloud security policy.

Ten Questions to Ask When Writing a Cloud Security Policy - slide 1

Click through for 10 questions a company should ask when writing up a cloud security policy.

Ten Questions to Ask When Writing a Cloud Security Policy - slide 2

What do we want to put in the cloud – data, applications or both? Based on this, you will be able to identify criteria to determine the best cloud provider and service required such as IaaS, PaaS or SaaS.

Ten Questions to Ask When Writing a Cloud Security Policy - slide 3

Do we have a good data classification policy and procedure and what type of data will we allow in the cloud – sensitive corporate data, protected data such as PII, SSNs or HIPAA related, day-to-day operational data? If you don’t have a good data classification policy, create that too so you aren’t inadvertently transmitting and storing data in a cloud that you don’t want there.

Ten Questions to Ask When Writing a Cloud Security Policy - slide 4

What existing policy does our company have that also applies to what we want to do in the cloud?

Ten Questions to Ask When Writing a Cloud Security Policy - slide 5

What have others in our industry done and what can we borrow? Calling up a peer who’s already ventured into the cloud and has experience with the good, the bad and the unexpected can really help you craft your policy. Checking out what a standards body, like ISO, NIST or the CSA, has created is also a great idea for discovering policy areas you may not have considered.

Ten Questions to Ask When Writing a Cloud Security Policy - slide 6

Who within our organization is allowed to enter into agreements with cloud providers? Who has authority to negotiate SLAs? Who can set up an application in or move data to the cloud and with whom should it be approved beforehand?

Ten Questions to Ask When Writing a Cloud Security Policy - slide 7

Where can my data or application be physically located? Where your data lives and where it could be moved to have legal and privacy implications.

Ten Questions to Ask When Writing a Cloud Security Policy - slide 8

What is our exit strategy and policy for removing data or applications from this cloud provider? Having a clear exit strategy before you start prevents you from potentially large operational costs or downtime later.

Ten Questions to Ask When Writing a Cloud Security Policy - slide 9

If we choose to put sensitive or protected data in the cloud, how well does the cloud provider’s security policies and procedures align with our organizations? Ensuring your cloud provider’s security program maturity is as advanced or more advanced than yours is a good sign.

Ten Questions to Ask When Writing a Cloud Security Policy - slide 10

For applications in the cloud, who within our organization is allowed to modify settings on the cloud that affect performance? Define who, when and under what circumstances changes can be made.

Ten Questions to Ask When Writing a Cloud Security Policy - slide 11

How should we manage administrative privileges to the cloud provider? For example, do you allow application developers to make changes to security settings in the cloud to improve performance?

SP

Sue Poremba is freelance writer based on Central PA. She's been writing about cybersecurity and technology trends since 2008.

Recommended for you...

Strategies for Successful Data Migration
Kashyap Vyas
May 25, 2022
Leveraging AI to Secure CloudOps as Threat Surfaces Grow
ITBE Staff
May 20, 2022
The Emergence of Confidential Computing
Tom Taulli
Apr 20, 2022
IT Business Edge Logo

The go-to resource for IT professionals from all corners of the tech world looking for cutting edge technology solutions that solve their unique business challenges. We aim to help these professionals grow their knowledge base and authority in their field with the top news and trends in the technology space.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.