Skip to main content
Guidance

Cloud security guidance

How to choose, configure and use cloud services securely.

Page 15 of 29

Principle 2: Asset protection and resilience

Your data (and the assets storing or processing it) should be adequately protected.

Data types that are often overlooked include credentials, configuration data, derived metadata and logs. These must also be appropriately protected.

You should consider:

  1. Physical location and legal jurisdiction
  2. Data centre security
  3. Data encryption
  4. Data sanitisation and equipment disposal
  5. Physical resilience and availability






Published

Reviewed

Version

2.1