CASP+ Definitions: Cloud
In cybersecurity, the term “cloud” refers to the delivery of computing services, including servers, storage, databases, networking, software, analytics, and more, over the internet, rather than using on-premises hardware and infrastructure. Cloud computing allows organizations to access computing resources and services on demand, often using a pay-per-use model, and provides flexibility, scalability, and cost savings.
However, the use of cloud computing also presents security challenges, as data and applications are often hosted outside of an organization’s traditional network perimeter, and security controls must be implemented to protect against threats and attacks in the cloud. Cloud security often involves a shared responsibility model between the cloud provider and the cloud customer, where both parties are responsible for implementing security controls to protect the cloud infrastructure, applications, and data. Cloud security measures may include access controls, encryption, network security, data loss prevention, identity and access management, and more.