Cloud Security, Security Program Controls/Technologies, Channel technologies, Multi-cloud management, Vulnerability Management

NIST identifies 23 new security risks in multi-cloud environments

The U.S. government, through the National Institute of Standards and Technology (NIST), has issued a warning regarding the distinct cybersecurity and compliance hurdles organizations face when operating within multi-cloud environments. NIST highlighted that managing security policies, controls, and authentication becomes more complex compared to single-cloud or on-premises setups, as each cloud service provider (CSP) has its own security models and frameworks, based on information published by Infosecurity Magazine.

NIST identified 23 new challenges across identity and access management, vulnerability management, incident response, disaster recovery, and data protection. In identity and access management, ensuring consistent policies and multi-factor authentication across different CSPs is difficult. Vulnerability management is complicated by varying CSP reporting formats and limited customer access for independent scans. Incident response and disaster recovery are hampered by inconsistent or delayed data from CSPs and a lack of transparency in their contingency planning. Data protection poses risks due to inconsistent encryption standards and difficulties in obtaining documentation to prove compliance with regulations like GDPR. NIST urges the cybersecurity community to collaborate on solutions, emphasizing the need for robust governance, centralized visibility, consistent policy enforcement, and automation to address these multi-cloud complexities.

Source: Infosecurity Magazine

An In-Depth Guide to Cloud Security

Get essential knowledge and practical strategies to fortify your cloud security.

You can skip this ad in 5 seconds