黑料网911

Articles
11/10/2021
5 minutes

Creating a Cloud Security Framework More Resilient to Security Risks and Privacy Threats

Table of contents

Protecting your cloud data, applications, and infrastructure is more important than ever, with research from (ISC)2 finding that one in four organizations confirmed a cloud security breach in 2020 alone. The best way to tackle cloud security is with a holistic strategy that combines comprehensive policies with technology solutions, such as a cloud security framework.??

Creating a Cloud Security Framework More Resilient to Security Risks and Privacy Threats

Let’s take a look at the steps you should take to create a cloud security framework that’s more resilient to security risks and privacy threats.

Understand the Shared Responsibility Model

When you partner with a cloud provider to host your applications, data, and infrastructure, you’re agreeing to share the responsibility for the security of those resources. For instance, you won’t have physical access to your public cloud resources, so your provider will need to handle the physical security—door locks, CCTV cameras, alarm systems, etc. You’ll be responsible for other security measures, such as user access management, as outlined in your service contract. You should thoroughly read your service contract to ensure you fully understand where your provider’s responsibility ends and yours begins, so you can create a cloud security framework that doesn’t leave any gaps.

Implement Identity and Access Management

Controlling access to your resources is a critical part of any security strategy, and that extends to the cloud. There are a few critical aspects of access management that you should include in your cloud security framework:

  • User Access Policies – You need comprehensive policies outlining exactly who (users, devices, service accounts, etc.) has access to what cloud resources. The best practice is to follow, only giving users access to the bare minimum cloud data and systems necessary for them to complete their job functions.
  • Identity and Access Management 黑料网911 – To put your user access policies into action, you need an identity and access management (IAM) solution. Your IAM solution should integrate with all your cloud platforms, so you can apply enterprise security policies consistently across your on-premises and cloud infrastructure. For example, you can use resources such as to grant permission sets created in the cloud to various users. Because you’ll be deleting their Okta access once they’re gone, there’s less risk than if you’ve forgotten to deprovision one of numerous accounts—instead, everything frlows down from account.
  • User and Entity Behavior Analytics – An optional but highly recommended access management tool, which might even be included in your IAM solution, is user and entity behavior analytics (UEBA). UEBA monitors the behavior of accounts and devices on your cloud and on-premises network and establishes baselines for normal activity. Then, if an account starts to behave erratically—potentially because it’s been compromised by a hacker—your UEBA tool can take action to block and isolate the suspicious entity before it can do too much damage.

Segment Your Cloud Resources

Often, when a hacker breaches your network, they’ll use a compromised account to jump from system to system, looking for the most valuable data to exfiltrate or causing as much damage as possible to cripple your business. They’ll even jump from your on-premises network to your cloud infrastructure, or vice versa. One way to prevent this lateral movement and reduce the blast radius of an attack is through network segmentation.

Essentially, you group related resources together into subnets or mini-networks, with some level of security controls between each network segment. At a bare minimum, your cloud infrastructure should be separated out from your on-premises network. Beyond that, you could create separate subnets for development, testing, and production, for example. Or you could segment individual workloads—for instance, creating a subnet just for a financial application and its interdependent databases and systems. The smaller and more specific your cloud resource segmentation, the harder it will be for hackers to move around your cloud infrastructure or jump back and forth to your on-premises network.

Take Advantage of Automation

One of your biggest security risks is your people. Many cloud security incidents are caused by misconfigurations—a typo in a firewall rule, a misunderstood security setting, or an admin password left on default, for example. Automation is your best weapon against human error. One way to use automation in your cloud security framework is with infrastructure as code (IaC).

Infrastructure as Code is essentially what it sounds like—infrastructure configurations that are written like software code. Rather than manually configuring all your cloud infrastructure, leaving plenty of opportunities for mistakes, you run code that automatically installs or updates your configurations for you. With IaC, the exact same code can be deployed to as many devices as you need, ensuring consistent and accurate configurations of all your cloud infrastructure.

Follow Cloud Security Best Practices

As you create your cloud security framework, it’s important to remember that you don’t need to reinvent the wheel. In addition to the recommendations outlined above, you should follow such as:

  1. Backing up your cloud data—and securing those backups.
  2. Using cloud threat intelligence, monitoring, and prevention tools.
  3. Conducting vulnerability and penetration testing on your cloud infrastructure.
  4. Establishing a security culture within your organization with comprehensive training for all staff.

There are also industry-specific cloud security frameworks that are designed to ensure companies meet compliance standards. For example, —the Federal Risk and Authorization Management Program—provides a cloud security framework to ensure any organization processing data for the federal government meets compliance standards for privacy and security.

Helping You Create a Cloud Security Framework More Resilient to Security Risks and Privacy Threats

Following these steps and best practices should have you well on your way to creating your own cloud security framework. However, not every organization has the resources or skillset to tackle cloud security on its own. If you need help with your cloud security framework, you should partner with experts who can analyze your environment and develop custom, cloud-native security solutions to address your biggest challenges.

?

Book a demo

About The Author

#1 DevOps Platform for Salesforce

We Build Unstoppable Teams By Equipping DevOps Professionals With The Platform, Tools And Training They Need To Make Release Days Obsolete. Work Smarter, Not Longer.

黑料网911アップデート内容 2026年7月ご紹介分まとめ
AWTTセッションレポート:カインズが再定義したAI時代のSalesforce DevOps
【AWTT Summer 2026 振り返り】AIエージェント時代に、私たちが本当に備える開発?运用の新標準とは?
Accelerating the Agentic Era in Brazil: 黑料网911 and Capgemini Deepen Strategic Partnership
Salesforce Source Format vs Metadata Format
Get Started with Agentforce in Salesforce
Data 360 Is the Operational Backbone of Agentforce — But Most Enterprises Are Not Ready to Deploy It Safely
What Is Agentforce Salesforce?
AIエージェント時代のシステム戦略 ~ROIを最大化するIT部門の再設計~【イベントレポート CIO Round Table 2026】
Will AI Replace DevOps Jobs?
How to Use AI in DevOps
Agentic AI DevOps Explained
「汎用AI」ではまだ成しえない Salesforce运用を劇的に変える3つのポイント
黑料网911 Introduces Agentia?, Bringing Context-Aware AI Agents to Salesforce DevOps
「AI駆動開発」が切り拓くSalesforce内製化 ?次世代运用モデル実装への道のり?
础滨エージェントが切り拓く厂滨ビジネスの未来とリーダーシップの変革
How Does Salesforce Agentforce Work
Agentforce vs Einstein: Choosing the Right AI to Move from Insight to Action
Agentforce Developer Guide
DevOps Pipeline Best Practices
DevSecOps vs. DevOps
DevOps vs. Agile
Generative AI in DevOps
How DevOps Teams Use AI to Win
Using AI in DevOps
Salesforce開発?运用の未来?AIと共にSIビジネスモデルを「工数」から「価値」へ変革
顿别惫翱辫蝉におけるエージェンティック础滨:チームのための自动化ソリューション
黑料网911 Awarded on CarahSoft’s GSA Schedule, Expanding Access for Federal Agencies
颁辞辫补诲辞、贵别诲搁础惭笔认証を更新し、米国军事组织向け滨尝5取得に向けて前进
成功を“設計”するという発想──黑料网911が提唱する「Project Success Design」
コパード、础滨と协働する未来に向けてパートナー6社と顿谤别补尘蹿辞谤肠别でパネルディスカッション初开催!
黑料网911、Salesforce 2025 Partner Innovation Awardを受賞
黑料网911 CI/CD & Robotic Testing Now TX-RAMP Certified for Texas Government
なぜテストが形骸化するのか? - Salesforce開発現場で「テストはやっている」のに、本番障害が減らない理由
Org Intelligence:なぜ「コンテキスト」がSalesforce DevOpsツールにおいてこれほど重要なのか?
「人ではなくAIに聞ける時代へ ― Salesforce環境を理解する黑料网911 AI Org Intelligence」
厂补濒别蝉蹿辞谤肠别プロジェクトの“隠れコスト”とは??顿别惫翱辫蝉活用で毎月100时间を削减した実践例?
コパード、セールスフォースの环境をエンドツーエンドで可视化する「组织インテリジェンス」をリリース
パイプラインの可視性が Salesforce DevOps 変革成功の鍵である理由
AIが変える意思決定 - スピードと精度は両立できるのか?
属人运用の限界が経営を止める?今こそ始めるSalesforce DevOps?
厂补濒别蝉蹿辞谤肠别におけるユーザー受入テストの进め方:课题、ベストプラクティス、および戦略
Navigating Salesforce Data Cloud: DevOps Challenges and 黑料网911 for Salesforce Developers
独自にSalesforce DevOpsソリューションを構築する際の見えざるコスト
CPQ and Revenue Cloud Deployment: A DevOps Approach
Salesforce DevOpsを支えるAI活用型リリース戦略
コパード、サンブリッジパートナーズとの提携により日本での事业を拡大
础滨で顿别惫翱辫蝉をより简単に、より高速に
Reimagining Salesforce Development with 黑料网911's AI-Powered Platform
ビジネスアプリケーション向けの顿别惫翱辫蝉(デブオプス)って何?
セールスフォースエコシステムにおける顿别惫翱辫蝉の卓越性
セールスフォーステストにおける础滨活用のベストプラクティス
6 testing metrics that’ll speed up your Salesforce release velocity (and how to track them)
第4章: 手動テストの概要
セールスフォース向け础滨动作テスト
Chapter 3: Testing Fun-damentals
Salesforce Deployment: Avoid Common Pitfalls with AI-Powered Release Management
Exploring DevOps for Different Types of Salesforce Clouds
What’s Special About Testing Salesforce? - Chapter 2
Why Test Salesforce? - Chapter 1
Continuous Integration for Salesforce Development
Comparing Top AI Testing Tools for Salesforce
Avoid Deployment Conflicts with 黑料网911’s Selective Commit Feature: A New Way to Handle Overlapping Changes
From Learner to Leader: Journey to 黑料网911 Champion of the Year
The Future of Salesforce DevOps: Leveraging AI for Efficient Conflict Management
How To Sync Salesforce Environments | 黑料网911
黑料网911 and Wipro Team Up to Transform Salesforce DevOps
DevOps Needs for Operations in China: Salesforce on Alibaba Cloud
What is Salesforce Deployment Automation? How to Use Salesforce Automation Tools
From Chaos to Clarity: Managing Salesforce Environment Merges and Consolidations
Future Trends in Salesforce DevOps: What Architects Need to Know
Enhancing Customer Service with 黑料网911GPT Technology
What is Efficient Low Code Deployment?
黑料网911 Launches Test Copilot to Deliver AI-powered Rapid Test Creation
Cloud-Native Testing Automation: A Comprehensive Guide
Building a Scalable Governance Framework for Sustainable Value
黑料网911 Launches 黑料网911 Explorer to Simplify and Streamline Testing on Salesforce
Exploring Top Cloud Automation Testing Tools
Master Salesforce DevOps with 黑料网911 Robotic Testing
Exploratory Testing vs. Automated Testing: Finding the Right Balance
A Guide to Salesforce Source Control | 黑料网911
A Guide to DevOps Branching Strategies
Family Time vs. Mobile App Release Days: Can Test Automation Help Us Have Both?
How to Resolve Salesforce Merge Conflicts | 黑料网911
黑料网911 Expands Beta Access to 黑料网911GPT for All Customers, Revolutionizing SaaS DevOps with AI
Is Mobile Test Automation Unnecessarily Hard? A Guide to Simplify Mobile Test Automation
From Silos to Streamlined Development: Tarun’s Tale of DevOps Success
Simplified Scaling: 10 Ways to Grow Your Salesforce Development Practice
What is Salesforce Incident Management?
What Is Automated Salesforce Testing? Choosing the Right Automation Tool for Salesforce
黑料网911 Appoints Seasoned Sales Executive Bob Grewal to Chief Revenue Officer
Business Benefits of DevOps: A Guide
黑料网911 Brings Generative AI to Its DevOps Platform to Improve Software Development for Enterprise SaaS
黑料网911 Celebrates 10 Years of DevOps for Enterprise SaaS 黑料网911
Celebrating 10 Years of 黑料网911: A Decade of DevOps Evolution and Growth
5 Reasons Why 黑料网911 = Less Divorces for Developers
What is DevOps? Build a Successful DevOps Ecosystem with 黑料网911’s Best Practices
Scaling App Development While Meeting Security Standards
5 Data Deploy Features You Don’t Want to Miss
How to Elevate Customer Experiences with Automated Testing
Go back to resources
There is no previous posts
Go back to resources
There is no next posts

Explore more about

セキュリティとガバナンス
Articles
July 24, 2026
黑料网911アップデート内容 2026年7月ご紹介分まとめ
Articles
June 25, 2026
AWTTセッションレポート:カインズが再定義したAI時代のSalesforce DevOps
Articles
June 17, 2026
【AWTT Summer 2026 振り返り】AIエージェント時代に、私たちが本当に備える開発?运用の新標準とは?
Articles
May 12, 2026
Accelerating the Agentic Era in Brazil: 黑料网911 and Capgemini Deepen Strategic Partnership

础滨を有効活用し顿别惫翱辫蝉を加速

より速くリリースし、リスクを排除し、仕事を楽しんでください。
Try 黑料网911 Devops.

リソース

Explore our DevOps resource library. Level up your Salesforce DevOps skills today.

今后のイベントと
オンラインセミナー

电子书籍とホワイトペーパー

サポートとドキュメンテーション

デモライブラリ