Cloud 101CircleEventsBlog
Help shape the CCSK by participating in the peer reviews for the upcoming CCSK v5 by February 22nd!

Download Publication

Secure Connection Requirements of Hybrid Cloud
Secure Connection Requirements of Hybrid Cloud
Who it's for:
  • cloud customers
  • cloud security practitioners
  • security architects
  • security engineers

Secure Connection Requirements of Hybrid Cloud

Release Date: 11/05/2021

Working Group: Hybrid Cloud Security

The National Institute of Standards and Technology (NIST) defines hybrid cloud infrastructure as 
a composition of distinct cloud infrastructures (private, community, and/or public) that remain unique entities. These infrastructures are bound together by standardized or proprietary technology that enables data and application portability.

Hybrid cloud is becoming an essential enterprise cloud model that allows the best of both worlds, providing customers with diverse resources to run different workloads depending on their needs. To successfully secure this complex landscape, enterprises should develop and employ perimeter, transmission, storage, and management cross-cloud security capabilities. This document from the Hybrid Cloud Security Working Group lists best practices for these four areas of security, along with their applicability to the Cloud Controls Matrix (CCM).

Key Takeaways:
  • What private, public, community, and hybrid cloud are
  • Cross-cloud security best practices
  • The ideal architecture for hybrid cloud connectivity
  • The CCM v4 control domains referenced in these cross-cloud security capabilities

Download this Resource

Prefer to access this resource without an account? Download it now.

Bookmark
Share
View translations
Related resources
An Agile Data Doctrine for a Secure Data Lake
An Agile Data Doctrine for a Secure Data Lake
Software-Defined Perimeter (SDP) Specification v2.0
Software-Defined Perimeter (SDP) Specification ...
The Continuous Audit Metrics Catalog
The Continuous Audit Metrics Catalog
Uncovering Hybrid Cloud Attacks Through Intelligence-Driven Incident Response: Part 1– Addressing the Speed of Cloud Attacks
Uncovering Hybrid Cloud Attacks Through Intelligence-Driven Inciden...
Published: 01/10/2024
Practical Ways to Combat Generative AI Security Risks
Practical Ways to Combat Generative AI Security Risks
Published: 01/05/2024
How to Modernize Permissioning with the Cross-Cloud Solution Shaping the Future of IDaaS
How to Modernize Permissioning with the Cross-Cloud Solution Shapin...
Published: 11/30/2023
UPI is an Indian Success Story. Zero Trust Architecture Can Help Ensure It Stays That Way
UPI is an Indian Success Story. Zero Trust Architecture Can Help En...
Published: 11/21/2023

Acknowledgements

Michael Roza
Michael Roza
Head of Risk, Audit, Control and Compliance

Michael Roza

Head of Risk, Audit, Control and Compliance

Since 2012 Michael has contributed to over 100 CSA projects completed by CSA's Internet of Things, Zero Trust/Software-Defined Perimeter, Top Threats, Cloud Control Matrix, Containers/Microservices, DevSecOps, and other working groups. He has also served as co-chair of CSA's Enterprise Architecture, Top Threats, and Security-as-a-Service working groups while also serving as the Standards Liaison Officer for IoT, ICS, EA, SECaaS, and Cloud K...

Read more

Rajiv Mishra Headshot Missing
Rajiv Mishra

Rajiv Mishra

This person does not have a biography listed with CSA.

Dr. Hing-Yan Lee
Dr. Hing-Yan Lee
Executive Vice President of Government Affairs, CSA

Dr. Hing-Yan Lee

Executive Vice President of Government Affairs, CSA

Dr. Hing Yan Lee serves as the Executive Vice President of Asia Pacific (APAC) for Cloud Security Alliance. Dr. Lee has over 30 years of ICT working experience in both the public and private sectors. In the recent 9+ years, he was Director of National Cloud Computing Office at Infocomm Development Authority, where he was responsible for, inter alia, developing the cloud ecosystem, promoting cloud adoption by government agencies and private...

Read more

Rolando Marcelo Vallejos Headshot Missing
Rolando Marcelo Vallejos

Rolando Marcelo Vallejos

This person does not have a biography listed with CSA.

David Chong Headshot Missing
David Chong

David Chong

This person does not have a biography listed with CSA.

Zou Feng
Zou Feng

Zou Feng

Zou has been working in IT for 15+ years with a strong technical background and broad experience in heterogeneous systems and multi-culture environments.
Starting as Communication Engineer at ICBC, the largest bank in China, Zou maintained legacy telecommunication circuits and an IBM mainframe communication controller. During this period, Zou built up their first experience in data security by implementing a cipher machine to...

Read more

Narudom Roongsiriwong
Narudom Roongsiriwong
Head of Digital Architecture

Narudom Roongsiriwong

Head of Digital Architecture

Narudom ROONGSIRIWONG (SVP, Head of Digital Architecture, Bank of Ayudhya (Krungsri Bank) PCL, Thailand) has been an information security professional for over twenty years with solid technical experience in architecture, data analytics, application development and cloud computing. He has experience in running three security operation centers and the last one operated with in-house AI and Machine Learning. He was a pioneer in setting up the...

Read more

Geng Tao Headshot Missing
Geng Tao

Geng Tao

This person does not have a biography listed with CSA.

Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?

Related Certificates & Training