SECURITY
Protecting Cloud Resources and
Business Data
Cloud security and database security depend heavily
on how access is designed and managed.
Depending on the environment, controls may include
restricted network access, authentication,
least-privilege permissions, protected credentials,
encrypted connections where supported, controlled
administrative access, logging, and separation
between development, testing, and production
environments.
Applications should generally access databases
through controlled application services and APIs
rather than exposing direct database access to
users.
Security requirements also vary according to the
information being stored. Business records,
customer information, financial data, and other
sensitive information may require additional
safeguards based on organizational policies and
applicable regulations.
Cloud security is therefore not a single
configuration. It involves infrastructure,
applications, databases, identities, operating
systems, and connected services working together
securely.