Security controls

A security control acts as a tool to restrict a list of possible actions down to those that are allowed or permitted. An industry group, called the The Cloud Security Alliance, has documented a complete list of data security controls in a reference called the Cloud Control Matrix. This matrix is an important tool and is designed to help the security professional identify and selected data security controls, based on the applicable industry regulations or security governance environment.

Controls are generally described as being within one of three categories:

  • Administrative: regulations, policies, laws, guidelines, and practices governing the overall information security requirements and controls
  • Logical: Virtual technical ...

Get Architecting Cloud Computing Solutions now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.