Cloud security guidance
Pages
Page 29 of 29
Responses to the cloud security principles
Some cloud service providers choose to publish a response to the NCSC’s cloud security principles, so that you can find out how they meet the goals of each principle, in a single place.
Using vendor-written responses
These responses are designed to help you choose a cloud provider that meets your security needs.
You will still need to do your own analysis to determine whether you can be confident that a cloud service meets those needs. The responses are designed to help you find the relevant information.
The fact that a service has, or has not, published a response to our security principles does not imply it is more or less secure than any other.
If the default configuration of the service does not meet a principle, the response should explain what steps are necessary to do so. This will include links to any scripts, configuration files that simplify the process.
Providers may include, or link to, good practice guidance as part of their response to Principle 14: secure use of the service. This helps you with your responsiblity to configure their cloud service securely in line with our using cloud services securely guidance.
The NCSC does not formally validate the answers provided in these responses. Ways that you can gain more confidence in the accuracy of responses include:
- the response being signed off by a member of the company’s board, or a named delegate with security responsibility
- it being publicly available on the service provider’s website
- putting the requirement to provide an accurate response to the cloud security principles in your procurement contract
- looking for evidence in reports from independent audits, which may be performed as part of a certification activity
Responses written prior to 2022 may refer to the previous version of the Cloud Security Principles, from which the current versions have been developed. That previous framework is available via The National Archives but should not be used for new or updated responses to the principles.
Writing a response
A response should explain how the service and the service provider meet each of the security goals outlined in the cloud security principles . Your response should contain the information needed for a customer to choose a cloud product that meets their security needs. You should also include a link to this page, so the reader knows what to expect. When writing a response to the principles, we recommend the following guidance:
- 1
Focus on the goals
The most important outcome for a customer is that they gain confidence in your ability to meet the goals for each principle. As a result, your responses should focus on the goals, and not just the high-level purpose of the principle.
- 2
Keep it short
Aim to be concise, calling out the key headlines and providing information that directly responds to the goal.
- 3
Refer to existing publications
Provide the key statements that respond to each principle’s goals, and refer to documentation and evidence that you publish elsewhere, rather than repeating the detail in the response.
- 4
Present your evidence
Where possible, back up the assertions you’re making, with evidence. This may be from external audits, or the evidence that you will have presented to gain certification of international standards. It is easier for your customers to trust evidence that you are able to present in a transparent way on your public website, as we discuss in this blog post. If good evidence is available under an NDA, the response should say so.
- 5
Be clear and specific
Make sure the language you use in your response is clear and easy to understand. Where you rely on particular technologies or protocols, be as specific as you can about your implementation. If the NCSC has guidance on the topic linked from within the cloud principles, we recommend that you compare your implementation directly with that guidance. Protecting data with TLS and system administration models are notable examples of this.
- 6
Keep it up to date
Cloud services constantly evolve, so you should check periodically that your response to the principles still reflect the nature of your service. Linking to external documentation and keeping the response document concise should help to make this easier.
- 7
Call out optional security features
Some cloud services have powerful security features that cost extra, or require configuration. Where your service offers customers optional security features, relevant to the principles, call them out and explain the specific security benefits especially where they help meet a requirement in our using the cloud securely guidance. Ideally, link to documentation explaining how to enable the feature and any configuration considerations.
- 8
Identify specific security controls that your customers need to configure
Some aspects of the service may need to be configured in a certain way so that it can meet the security goals in principles 1-13. This is called out in Principle 14.1: Security by design and by default. Customers may also need to adjust configurations when following our using cloud services securely guidance. You should be specific which settings they should be using, including what they need to be set to.
- 9
Cloud all the way down
If your service is built on another cloud platform or service, you should refer to their documentation when it’s relevant. Even better, if they have a response to the cloud security principles, refer to that. When it’s relevant to the principle, you should also be clear about your configuration of those other cloud services. For example, you may rely on their equipment disposal process or their external interface protection. Alternatively, you may want to show how your design means you don’t have to rely on your supplier’s security. For example, encrypting data before sending it to a storage provider may make their personnel security management irrelevant.


