• Access Rights & Permissions Matrix
    • Data Breach Notification Log
    • Data Classification Register
    • Data Loss Prevention (DLP) Incident Log
    • Document Retention & Disposal Tracker
    • Security KPI Dashboard
    • Asymmetric-Key Cryptography
    • Combined Security Model: Digital Signature + Digital Envelope
    • Database Encryption Techniques (API, Plug-in, TDE)
    • Diffie-Hellman Key Exchange
    • Digital Envelope
    • Digital Signature
    • Hash Function
    • Homomorphic Encryption
    • Hybrid Cryptography
    • PKI (Public Key Infrastructure)
    • Post-Quantum Cryptography (PQC)
    • Quantum Security
    • RSA Encryption
    • Sign-then-Encrypt
    • Symmetric-Key Cryptography
    • CIA Triad
    • Endpoint Security
    • Systematic Server Defense Strategy
    • DDoS Attack Mitigation Plan Tracker
    • IP Whitelist–Blacklist Tracker
    • Network Access Control Log
    • Network Device Inventory
    • Network Security Risk Mitigation
    • Network Traffic Monitoring Dashboard
    • DDoS (Distributed Denial of Service)
    • DRDoS (Distributed Reflective Denial of Service)
    • Network Separation & Integration
    • SASE (Secure Access Service Edge)
    • SDP (Software Defined Perimeter)
    • Spoofing
    • Zero Trust
    • IPSec
    • OSI 7-Layer Security
    • OSI 7-Layer Security Threats
    • TLS (Transport Layer Security)
    • Cloud Access Control Matrix
    • Cloud Asset Inventory Tracker
    • Cloud Backup & Recovery Testing Tracker
    • Cloud Incident Response Log
    • Cloud Security Configuration Baseline
    • CASB (Cloud Access Security Broker)
    • CNAPP (Cloud Native Application Protection Platform)
    • The Two Pillars of Cloud Security (CSPM and CWPP)
    • DSPM (Data Security Posture Management)
    • Integrated Cloud-Native Security Architecture
    • Shadow IT
    • Kubernetes Security
    • Amdahl's Law
    • Patch & Update Tracker
    • Secure Coding Checklist
    • Secure Mobile App Testing Tracker
    • Security Misconfiguration Log
    • Static Code Analysis Log
    • Web Application Vulnerability Tracker
    • Application Threat Modeling
    • CSRF (Cross-Site Request Forgery)
    • SQL Injection
    • XSS (Cross-Site Scripting)
    • API Security (OWASP API Top 10 and BOLA)
    • Code Security (SAST, DAST, and Secure Coding)
    • DevSecOps Pipeline
    • DevSecOps
    • Software Supply Chain Security (SBOM and SLSA)
    • Acceptable Use of Assets Policy
    • Password Policy
    • Backup and Recovery Policy
    • Compliance Management
    • Disposal and Destruction Policy
    • Information Classification Policy
    • Information Transfer Policy
    • ISMS Policy
    • COBIT-Based Security Governance
    • ISMS-P
    • ISO 27001
    • Privacy Impact Assessment (PIA)
    • Korea's Data 3 Acts
    • Differential Privacy
    • EU AI Act
    • 5 Pseudonymization Techniques
    • CSAP Tiered Certification
    • Incident Management Policy
    • Incident Management Process
    • Intern Incident Report
    • Major Incident Report Template
    • Structural Damage Incident Report
    • Workplace Violence Report
    • The Core of Endpoint Visibility, EDR
    • The Integrated Control Tower for Threat Detection and Analysis, SIEM
    • Digital Forensics
    • Known Error (KE) Record Template
    • Major Problem Report Template
    • Problem Management Process
    • Problem Record Template
    • DR Approach Document
    • DR Asset Register
    • DR Closure Report
    • DR Communications Plan
    • DR Plan Template
    • MAC vs. DAC vs. RBAC: Access Control Models Compared
    • Access Control
    • Authentication vs. Authorization
    • FIDO (Fast IDentity Online)
    • Identity Provider (IdP)
    • JWT (JSON Web Token)
    • Kerberos
    • OAuth 2.0
    • OAuth 2.0 and OIDC
    • OpenID Connect (OIDC)
    • Passkey
    • SAML (Security Assertion Markup Language)
    • Single Sign-On (SSO)
    • Active Directory (AD)
    • LDAP (Lightweight Directory Access Protocol)
    • Systematic Classification of Attack Techniques
    • Penetration Testing Methodology
    • OSINT (Open Source Intelligence)
    • OSSTMM (Open Source Security Testing Methodology Manual)
    • PTES (Penetration Testing Execution Standard)
    • RAV (Risk Assessment Value)
    • Fuzzing
    • CTF Categories
    • Red Teaming
    • AI System Security
    • Deepfake
    • LLM Security (OWASP Top 10 for LLM)
    • OT/ICS Security and the Purdue Model
    • Blockchain
    • GitHub
  • to navigate
  • to select
  • to close
    • Home
    • Cloud Security
    On this page
    cloud

    Cloud Security

    Templates and trackers for cloud access governance, asset visibility, backup assurance, and incident response in cloud environments.

    admin_panel_settings

    Cloud Access Control Matrix

    A structured record mapping human and service identities to cloud accounts, roles, and permission scopes to enforce least privilege.

    inventory

    Cloud Asset Inventory Tracker

    A discovery-driven register of cloud resources across accounts and providers, used to close visibility gaps and shadow cloud usage.

    backup

    Cloud Backup & Recovery Testing Tracker

    A log of cloud backup schedules and periodic restore tests, used to verify recovery objectives can actually be met.

    report

    Cloud Incident Response Log

    A chronological record of security incidents detected in cloud environments, from detection through containment and root-cause closure.

    tune

    Cloud Security Configuration Baseline

    The approved, enforceable hardening standard cloud resources must meet, derived from recognized benchmarks and checked continuously.

    cloud_sync

    CASB (Cloud Access Security Broker)

    A security control point placed between on-premises infrastructure and cloud services that unifies policy enforcement and visibility across …

    apps

    CNAPP (Cloud Native Application Protection Platform)

    A cloud-native security platform that unifies configuration posture management (CSPM) and workload protection (CWPP) into a single system.

    security

    The Two Pillars of Cloud Security (CSPM and CWPP)

    An overview of CSPM, which checks cloud infrastructure for misconfiguration, and CWPP, which protects running workloads such as VMs and …

    data_thresholding

    DSPM (Data Security Posture Management)

    A security technology that automatically discovers structured and unstructured data across cloud infrastructure and analyzes its sensitivity …

    layers

    Integrated Cloud-Native Security Architecture

    A layered defense-in-depth framework spanning cloud configuration, workload runtime, data, and user access points.

    visibility_off

    Shadow IT

    Information assets and services used for business purposes outside an organization's official security policy and asset management process.

    hub

    Kubernetes Security

    A multi-layered set of mechanisms protecting cluster components and workloads in a container orchestration environment from external threats …

    speed

    Amdahl's Law

    An architectural principle stating that the maximum speedup achievable through parallel processing is limited by the proportion of a task …


    © 2026 Cybersecurity Knowledge Base. Built with Lotus Docs