Circle
Events
Blog

Download Publication

Cloud Security for Startups
Cloud Security for Startups

Cloud Security for Startups

Release Date: 11/20/2017

As a Software-as-a-Service (SaaS) startup, it’s important to build solid security foundations in order to gain and maintain customers’ trust. SaaS startups should view security as an essential foundation of their company, as well as a competitive advantage that influences potential customers. In this document, we provide an outline of cloud security best practices that SaaS organizations should follow, including guidelines for application security, platform security, and security management, and provide some quick tips along the way. This document provides a security roadmap that you can follow as your company progresses through its cloud journey. We also provide a list of which controls should be implemented during each phase of a startup’s growth.

All together, these guidelines should help SaaS startups meet the most important security and privacy requirements presented by customers considering new services and products.

Key Takeaways: Besides providing cloud security recommendations, this document covers the following specific areas of security (and more):
  • Authentication and authorization
  • Secure software development lifecycle (SSDLC)
  • Management dashboard
  • Data flows and network separation
  • Encryption and key management
  • Transparency
  • Industry standards
  • Incident response
Who It’s For: This document is designed for founders, CTOs, product managers, and architects of cloud-based startups that are developing on public Infrastructure-as-a-Service/Platform-as-a-Service (IaaS/PaaS).

Download this Resource

LoginCreate Account

Prefer to access this resource without an account? Download it now.

Acknowledgements

Srinivas Tatipamula Headshot
Srinivas Tatipamula
Principal Security Advisor

Srinivas Tatipamula

Principal Security Advisor

C-CISO|CISSP|CISA|AWS CSS|AWS CSA|CDPSE|CISM|CGEIT|CRISC|ISO 27000LA|CCSK|ITIL-F|PMP|Bachelor of Economics (Hons)|Bachelor of Law| MS in Digital Forensics

Overall 30 plus years in IT and over 18 years in Cyber Security

Publications:

1. Cloud Security Alliance Internet of Things (IoT) Working Group IoT Security Controls Guide Version Published March 2019

2. CSA IoT Controls Matrix March 2019

3. ...

Read more

Michael Roza Headshot
Michael Roza
Risk, Audit, Control and Compliance Professional

Michael Roza

Risk, Audit, Control and Compliance Professional

Since 2012 Michael has contributed to over 85 CSA projects completed by CSA's Internet of Things, Zero Trust/Software-Defined Perimeter, Top Threats, Cloud Control Matrix, Containers/Microservices, DevSecOps, and other working groups. He has also served as co-chair of CSA's Enterprise Architecture, Top Threats, and Security-as-a-Service working groups while also serving as the Standards Liaison Officer for IoT, ICS, EA, SECaaS, and Cloud Key M...

Read more

Moshe Ferber Headshot Missing
Moshe Ferber

Moshe Ferber

Moshe Ferber is a recognized industry expert and popular public speaker, with over 20 years’ experience at various positions ranging from the largest enterprises to innovative startups. Currently Ferber focuses on cloud security as certified instructor for CCSK & CCSP certification and participate in various initiative promoting responsible cloud adoption.

Read more

Alexandre Caramelo Pinto Headshot Missing
Alexandre Caramelo Pinto

Alexandre Caramelo Pinto

This person does not have a biography listed with CSA.

Yael Nishry Headshot Missing
Yael Nishry

Yael Nishry

This person does not have a biography listed with CSA.

Shahar Geiger Maor Headshot Missing
Shahar Geiger Maor

Shahar Geiger Maor

This person does not have a biography listed with CSA.

Marius Aharonovich Headshot Missing
Marius Aharonovich

Marius Aharonovich

This person does not have a biography listed with CSA.

Rich Campagna Headshot Missing
Rich Campagna

Rich Campagna

This person does not have a biography listed with CSA.

Scott Kennedy Headshot Missing
Scott Kennedy

Scott Kennedy

This person does not have a biography listed with CSA.

Ron Peled Headshot Missing
Ron Peled

Ron Peled

This person does not have a biography listed with CSA.

Yuval Reut Headshot Missing
Yuval Reut

Yuval Reut

This person does not have a biography listed with CSA.

Ofer Smadar Headshot Missing
Ofer Smadar

Ofer Smadar

This person does not have a biography listed with CSA.

Omer Taran Headshot Missing
Omer Taran

Omer Taran

This person does not have a biography listed with CSA.

Govindasamy Chinnu Headshot Missing
Govindasamy Chinnu

Govindasamy Chinnu

This person does not have a biography listed with CSA.

Kyle McAuliffe Headshot Missing
Kyle McAuliffe

Kyle McAuliffe

This person does not have a biography listed with CSA.

Gurpreet Sahota Headshot Missing
Gurpreet Sahota

Gurpreet Sahota

This person does not have a biography listed with CSA.

Zeal Somani Headshot Missing
Zeal Somani

Zeal Somani

This person does not have a biography listed with CSA.

James Stewart Headshot Missing
James Stewart

James Stewart

This person does not have a biography listed with CSA.

Peter van Eijk Headshot Missing
Peter van Eijk

Peter van Eijk

Dr. Peter van Eijk is one of the world's most experienced cloud trainers. He offers CCSK as an instructor-led online course, as well as in-person. He is an authorized CSA CCSK (since 2011) and (ISC)2 CCSP trainer with a passion to make you more effective in your work.

Read more

Are you a research volunteer? Request to have your profile displayed on the website here.