Cloud Security

  1. Cloud Governance and Risk Management
    1. Cloud Governance Frameworks
      1. Governance Principles
        1. Cloud Security Alliance (CSA) Framework
          1. Cloud Controls Matrix (CCM)
            1. Consensus Assessments Initiative Questionnaire (CAIQ)
            2. NIST Cloud Computing Framework
              1. NIST SP 800-144
                1. NIST SP 800-146
                2. ISO/IEC 27017
                  1. Cloud-Specific Controls
                    1. Implementation Guidelines
                    2. Center for Internet Security (CIS) Controls
                      1. Critical Security Controls
                        1. Cloud Implementation Guidance
                      2. Risk Assessment and Management
                        1. Cloud Risk Identification
                          1. Technical Risks
                            1. Operational Risks
                            2. Risk Analysis Methodologies
                              1. Qualitative Risk Assessment
                                1. Quantitative Risk Assessment
                                  1. Risk Matrices and Scoring
                                  2. Risk Treatment Strategies
                                    1. Risk Acceptance
                                      1. Risk Mitigation
                                        1. Risk Transfer
                                          1. Risk Avoidance
                                          2. Vendor Risk Management
                                            1. Due Diligence Processes
                                              1. Third-Party Assessments
                                                1. Contract Security Requirements
                                                  1. Ongoing Vendor Monitoring
                                                2. Compliance and Regulatory Requirements
                                                  1. Regulatory Landscape Overview
                                                    1. Data Protection Regulations
                                                      1. General Data Protection Regulation (GDPR)
                                                        1. California Consumer Privacy Act (CCPA)
                                                          1. Personal Information Protection and Electronic Documents Act (PIPEDA)
                                                          2. Industry-Specific Regulations
                                                            1. Health Insurance Portability and Accountability Act (HIPAA)
                                                              1. Payment Card Industry Data Security Standard (PCI DSS)
                                                                1. Sarbanes-Oxley Act (SOX)
                                                                  1. Federal Information Security Management Act (FISMA)
                                                                  2. International Standards
                                                                    1. ISO/IEC 27001
                                                                      1. ISO/IEC 27002
                                                                        1. ISO/IEC 27018
                                                                        2. Compliance Frameworks
                                                                          1. Service Organization Control (SOC) Reports
                                                                            1. Cloud Security Alliance STAR
                                                                              1. FedRAMP Authorization
                                                                            2. Audit and Assessment
                                                                              1. Cloud Audit Planning
                                                                                1. Audit Scope Definition
                                                                                  1. Evidence Collection Methods
                                                                                    1. Continuous Monitoring
                                                                                      1. Compliance Reporting
                                                                                        1. Gap Analysis and Remediation