Sekit CSF · Familia
Cloud Security
24 controles en 8 temas, cada uno visto a través de las lentes de política, proceso y técnica.
Política
RCF-0334Cloud IAM7 mapeosAccess to cloud environments is formally governed by policies defining who can access what and under what conditionsRCF-0343Cloud logging5 mapeosThe company formally requires that all significant cloud activity is logged and retainedRCF-0337CSPM posture5 mapeosThe company formally requires continuous assessment of cloud environment configurations against security standardsRCF-0340KMS & HSM3 mapeosThe company formally governs how encryption keys are created, stored, rotated and retiredRCF-0349Multi-tenancy controls5 mapeosThe company formally addresses the risk of data leakage between tenants in shared cloud environmentsRCF-0352SaaS security configuration6 mapeosSecurity configuration requirements for all software-as-a-service applications are formally definedRCF-0331Shared responsibility model6 mapeosSecurity responsibilities between the company and its cloud providers are formally understood and documentedRCF-0346Workload protection7 mapeosSecurity standards for protecting workloads running in cloud environments are formally defined
Proceso
RCF-0335Cloud IAM7 mapeosCloud access rights are consistently reviewed and aligned with the principle of least privilegeRCF-0344Cloud logging5 mapeosCloud audit logs are consistently enabled across all accounts and services and reviewed regularlyRCF-0338CSPM posture7 mapeosCloud security posture is consistently monitored and misconfigurations are remediated within agreed timelinesRCF-0341KMS & HSM3 mapeosEncryption key management procedures are consistently followed and key material is never exposed in plain textRCF-0350Multi-tenancy controls5 mapeosMulti-tenant boundaries are consistently verified and configurations that could enable cross-tenant access are avoidedRCF-0353SaaS security configuration7 mapeosSaaS applications are consistently configured to meet security standards and reviewed when settings changeRCF-0332Shared responsibility model8 mapeosTeams consistently apply the correct security controls for their side of the cloud shared responsibility modelRCF-0347Workload protection6 mapeosCloud workloads are consistently assessed against security standards and anomalies are investigated
Técnica
RCF-0336Cloud IAM8 mapeosTechnical controls enforce identity-based access policies across all cloud environments and servicesRCF-0345Cloud logging5 mapeosTechnical controls ensure cloud activity logs are centralised, tamper-proof and available for investigationRCF-0339CSPM posture7 mapeosCloud security posture management tools continuously scan for and alert on misconfigured cloud resourcesRCF-0342KMS & HSM3 mapeosTechnical key management systems and hardware security modules protect cryptographic material at rest and in useRCF-0351Multi-tenancy controls5 mapeosTechnical controls enforce strict tenant isolation to prevent unauthorised access to other customers' dataRCF-0354SaaS security configuration5 mapeosTechnical tools assess SaaS application configurations and alert on deviations from security baselinesRCF-0333Shared responsibility model7 mapeosTechnical controls fill the security gaps that fall on the company's side of the cloud shared responsibility boundaryRCF-0348Workload protection7 mapeosTechnical tools monitor cloud workloads for threats and enforce security policies at the workload level
Esta familia en ISO/IEC 27001:2022
Cada elemento de marco al que mapean los controles de la familia, primero los más conectados; agrupado por familia del Sekit CSF, nunca por el índice del propio marco.
Esta familia en NIST CSF 2.0
Esta familia en ISO/IEC 42001:2023 — Annex A
Esta familia en Cyber Essentials
Pregúntale a Sekura: «¿Qué evidencia demuestra Cloud Security?»
También vía MCP, gratis con cuenta