,TheapermanentaandaofficialalocationaforaCloudaSecurityaAlliance’saSecurityaGuidanceaforaCriticalaArea
saofaFocusainaCloudaComputingav4.0aisahttps://cloudsecurityalliance.org/download/security-
a guidance-v4/.
OfficialaStudyaGuideaforathe
©a2021aCloudaSecurityaAlliancea–aAllaRightsaReserved.
TheaSecurityaGuidanceaforaCriticalaAreasaofaFocusainaCloudaComputingav4.0a(“Guidanceav4.0”)aisalicen
sedabyatheaCloudaSecurityaAllianceaunderaaaCreativeaCommonsaAttribution-NonCommercial-
aShareAlikea4.0aInternationalaLicensea(CC-BY-NC-SAa4.0).
Sharinga-aYouamayashareaandaredistributeatheaGuidanceainaanyamediumaoraanyaformat,aonlyaforanon-
commercial apurposes.
a
Adaptationa-
aYouamayaadapt,atransform,amodifyaandabuildauponatheaGuidanceav4aandadistributeatheamodifiedaGuidan
ceav4.0,aonlyaforanon-commercialapurposes.
Attributiona-
YouamustagiveacreditatoatheaCloudaSecurityaAlliance,alinkatoaGuidanceav4.0awebpagealocatedaatahttp
a
s://cloudsecurityalliance.org/download/security-guidance-
v4/,aandaindicateawhetherachangesawereamade.aYouamayanotasuggestathataCSAaendorsedayouaorayo
urause.
Share-Alikea-
aAllamodificationsaandaadaptationsamustabeadistributedaunderatheasamealicenseaasatheaoriginalaGuidan
ceav4.0.
Noaadditionalarestrictionsa-
Youamayanotaapplyalegalatermsaoratechnologicalameasuresathatarestrictaothersafromadoingaanythingat
a
hatathisalicenseapermits.
CommercialaLicensesa-
aIfayouawishatoaadapt,amodify,ashareaoradistributeacopiesaofatheaGuidanceav4.0aforarevenueageneratingapur
posesayouamustafirstaobtainaanaappropriatealicenseafromatheaCloudaSecurityaAlliance.aPleaseacontactausaata
SecurityaGuidanceav4.0a©aCopyrighta2021,aCloudaSecurityaAlliance.aAllarightsareserved 2
,.
Notices:aAllatrademark,acopyrightaoraotheranoticesaaffixedaontoatheaGuidanceav4.0amustabeareproduc
edaandamayanotabearemoved.
SecurityaGuidanceav4.0a©aCopyrighta2021,aCloudaSecurityaAlliance.aAllarightsareserved 3
, FOREWORD
WelcomeatoatheafourthaversionaofatheaCloudaSecurityaAlliance’saSecurityaGuidanceaforaCriticalaAreasaofaFo
cusainaCloudaComputing.aTheariseaofacloudacomputingaasaanaever-
evolvingatechnologyabringsawithaitaaanumberaofaopportunitiesaandachallenges.aWithathisadocument,awea
aimatoaprovideabothaguidanceaandainspirationatoasupportabusinessagoalsawhileamanagingaandamitigati
ngathearisksaassociatedawithatheaadoptionaofacloudacomputingatechnology.
TheaCloudaSecurityaAllianceapromotesaimplementingabestapracticesaforaprovidingasecurityaassuranceawit
hinatheadomainaofacloudacomputingaandahasadeliveredaaapractical,aactionablearoadmapaforaorganizationsa
seekingatoaadoptatheacloudaparadigm.aTheafourthaversionaofatheaSecurityaGuidanceaforaCriticalaAreasaof
FocusainaCloudaComputingaisabuiltaonapreviousaiterationsaofatheasecurityaguidance,adedicatedaresearch,aa
a
ndapublicaparticipationafromatheaCloudaSecurityaAllianceamembers,aworkingagroups,aandatheaindustryaex
pertsawithinaouracommunity.aThisaversionaincorporatesaadvancesainacloud,asecurity,aandasupportingatech
nologies;areflectsaonareal-
worldacloudasecurityapractices;aintegratesathealatestaCloudaSecurityaAlliancearesearchaprojects;aandaoffer
saguidanceaforarelatedatechnologies.
Theaadvancementatowardasecureacloudacomputingarequiresaactiveaparticipation afromaaabroadas
etaofaglobally-distributedastakeholders.aCSAabringsatogetherathisadiverseacommunityaofaindustry
partnerships,ainternationalachapters,aworkingagroups,aandaindividuals.aWeaareaprofoundlyagratefulatoaal
lawhoacontributedatoathisarelease.
Pleaseavisitacloudsecurityalliance.comatoalearnahowayouacanaworkawithausatoaidentifyaandapromoteabe
stapracticesatoaensureaaasecureacloudacomputingaenvironment.
Bestaregards,
Lucianoa(J.R.)aSantos
ExecutiveaViceaPresidentaofaResearchaClo
udaSecurityaAlliance
SecurityaGuidanceav4.0a©aCopyrighta2021,aCloudaSecurityaAlliance.aAllarightsareserved 4
saofaFocusainaCloudaComputingav4.0aisahttps://cloudsecurityalliance.org/download/security-
a guidance-v4/.
OfficialaStudyaGuideaforathe
©a2021aCloudaSecurityaAlliancea–aAllaRightsaReserved.
TheaSecurityaGuidanceaforaCriticalaAreasaofaFocusainaCloudaComputingav4.0a(“Guidanceav4.0”)aisalicen
sedabyatheaCloudaSecurityaAllianceaunderaaaCreativeaCommonsaAttribution-NonCommercial-
aShareAlikea4.0aInternationalaLicensea(CC-BY-NC-SAa4.0).
Sharinga-aYouamayashareaandaredistributeatheaGuidanceainaanyamediumaoraanyaformat,aonlyaforanon-
commercial apurposes.
a
Adaptationa-
aYouamayaadapt,atransform,amodifyaandabuildauponatheaGuidanceav4aandadistributeatheamodifiedaGuidan
ceav4.0,aonlyaforanon-commercialapurposes.
Attributiona-
YouamustagiveacreditatoatheaCloudaSecurityaAlliance,alinkatoaGuidanceav4.0awebpagealocatedaatahttp
a
s://cloudsecurityalliance.org/download/security-guidance-
v4/,aandaindicateawhetherachangesawereamade.aYouamayanotasuggestathataCSAaendorsedayouaorayo
urause.
Share-Alikea-
aAllamodificationsaandaadaptationsamustabeadistributedaunderatheasamealicenseaasatheaoriginalaGuidan
ceav4.0.
Noaadditionalarestrictionsa-
Youamayanotaapplyalegalatermsaoratechnologicalameasuresathatarestrictaothersafromadoingaanythingat
a
hatathisalicenseapermits.
CommercialaLicensesa-
aIfayouawishatoaadapt,amodify,ashareaoradistributeacopiesaofatheaGuidanceav4.0aforarevenueageneratingapur
posesayouamustafirstaobtainaanaappropriatealicenseafromatheaCloudaSecurityaAlliance.aPleaseacontactausaata
SecurityaGuidanceav4.0a©aCopyrighta2021,aCloudaSecurityaAlliance.aAllarightsareserved 2
,.
Notices:aAllatrademark,acopyrightaoraotheranoticesaaffixedaontoatheaGuidanceav4.0amustabeareproduc
edaandamayanotabearemoved.
SecurityaGuidanceav4.0a©aCopyrighta2021,aCloudaSecurityaAlliance.aAllarightsareserved 3
, FOREWORD
WelcomeatoatheafourthaversionaofatheaCloudaSecurityaAlliance’saSecurityaGuidanceaforaCriticalaAreasaofaFo
cusainaCloudaComputing.aTheariseaofacloudacomputingaasaanaever-
evolvingatechnologyabringsawithaitaaanumberaofaopportunitiesaandachallenges.aWithathisadocument,awea
aimatoaprovideabothaguidanceaandainspirationatoasupportabusinessagoalsawhileamanagingaandamitigati
ngathearisksaassociatedawithatheaadoptionaofacloudacomputingatechnology.
TheaCloudaSecurityaAllianceapromotesaimplementingabestapracticesaforaprovidingasecurityaassuranceawit
hinatheadomainaofacloudacomputingaandahasadeliveredaaapractical,aactionablearoadmapaforaorganizationsa
seekingatoaadoptatheacloudaparadigm.aTheafourthaversionaofatheaSecurityaGuidanceaforaCriticalaAreasaof
FocusainaCloudaComputingaisabuiltaonapreviousaiterationsaofatheasecurityaguidance,adedicatedaresearch,aa
a
ndapublicaparticipationafromatheaCloudaSecurityaAllianceamembers,aworkingagroups,aandatheaindustryaex
pertsawithinaouracommunity.aThisaversionaincorporatesaadvancesainacloud,asecurity,aandasupportingatech
nologies;areflectsaonareal-
worldacloudasecurityapractices;aintegratesathealatestaCloudaSecurityaAlliancearesearchaprojects;aandaoffer
saguidanceaforarelatedatechnologies.
Theaadvancementatowardasecureacloudacomputingarequiresaactiveaparticipation afromaaabroadas
etaofaglobally-distributedastakeholders.aCSAabringsatogetherathisadiverseacommunityaofaindustry
partnerships,ainternationalachapters,aworkingagroups,aandaindividuals.aWeaareaprofoundlyagratefulatoaal
lawhoacontributedatoathisarelease.
Pleaseavisitacloudsecurityalliance.comatoalearnahowayouacanaworkawithausatoaidentifyaandapromoteabe
stapracticesatoaensureaaasecureacloudacomputingaenvironment.
Bestaregards,
Lucianoa(J.R.)aSantos
ExecutiveaViceaPresidentaofaResearchaClo
udaSecurityaAlliance
SecurityaGuidanceav4.0a©aCopyrighta2021,aCloudaSecurityaAlliance.aAllarightsareserved 4