Cloud 101CircleEventsBlog
Participate in the Peer Review of SaaS Technical Controls!

Download Publication

Secure Connection Requirements of Hybrid Cloud
Secure Connection Requirements of Hybrid Cloud
Who it's for:
  • cloud customers
  • cloud security practitioners
  • security architects
  • security engineers

Secure Connection Requirements of Hybrid Cloud

Release Date: 11/05/2021

Working Group: Hybrid Cloud Security

The National Institute of Standards and Technology (NIST) defines hybrid cloud infrastructure as 
a composition of distinct cloud infrastructures (private, community, and/or public) that remain unique entities. These infrastructures are bound together by standardized or proprietary technology that enables data and application portability.

Hybrid cloud is becoming an essential enterprise cloud model that allows the best of both worlds, providing customers with diverse resources to run different workloads depending on their needs. To successfully secure this complex landscape, enterprises should develop and employ perimeter, transmission, storage, and management cross-cloud security capabilities. This document from the Hybrid Cloud Security Working Group lists best practices for these four areas of security, along with their applicability to the Cloud Controls Matrix (CCM).

Key Takeaways:
  • What private, public, community, and hybrid cloud are
  • Cross-cloud security best practices
  • The ideal architecture for hybrid cloud connectivity
  • The CCM v4 control domains referenced in these cross-cloud security capabilities

Download this Resource

Prefer to access this resource without an account? Download it now.

Bookmark
Share
View translations
Related resources
Shadow Access and AI
Shadow Access and AI
Zero Trust Guidance for Small and Medium Size Businesses (SMBs) - Japanese Translation
Zero Trust Guidance for Small and Medium Size B...
AI Organizational Responsibilities: AI Tools and Applications
AI Organizational Responsibilities: AI Tools an...
AI Agents: Human or Non-Human?
AI Agents: Human or Non-Human?
Published: 03/13/2025
Agentic AI Identity Management Approach
Agentic AI Identity Management Approach
Published: 03/11/2025
Why Unified Data Security is Essential for Modern Enterprises
Why Unified Data Security is Essential for Modern Enterprises
Published: 03/11/2025
Why Should Active Directory Hygiene Be Part of Your NHI Security Program?
Why Should Active Directory Hygiene Be Part of Your NHI Security Pr...
Published: 02/25/2025

Acknowledgements

Michael Roza
Michael Roza
Risk, Audit, Control and Compliance Professional at EVC

Michael Roza

Risk, Audit, Control and Compliance Professional at EVC

Since 2012, Michael Roza has been a pivotal member of the Cloud Security Alliance (CSA) family. He has contributed to over 125 projects, as a Lead Author or Author/Contributor and many more as a Reviewer/Editor.
Michael's extensive contributions encompass critical areas including Artificial Intelligence, Zero Trust/Software Defined Perimeter, Internet of Things, Top Threats, Cloud Control Matrix, DevSecOps, and Key Management. H...

Read more

Rajiv Mishra Headshot Missing
Rajiv Mishra

Rajiv Mishra

Dr. Hing-Yan Lee
Dr. Hing-Yan Lee
Executive Vice President of Government Affairs, CSA

Dr. Hing-Yan Lee

Executive Vice President of Government Affairs, CSA

Dr. Hing Yan Lee serves as the Executive Vice President of Asia Pacific (APAC) for Cloud Security Alliance. Dr. Lee has over 30 years of ICT working experience in both the public and private sectors. In the recent 9+ years, he was Director of National Cloud Computing Office at Infocomm Development Authority, where he was responsible for, inter alia, developing the cloud ecosystem, promoting cloud adoption by government agencies and private...

Read more

Rolando Marcelo Vallejos Headshot Missing
Rolando Marcelo Vallejos

Rolando Marcelo Vallejos

David Chong Headshot Missing
David Chong

David Chong

Zou Feng
Zou Feng

Zou Feng

Zou has been working in IT for 15+ years with a strong technical background and broad experience in heterogeneous systems and multi-culture environments.
Starting as Communication Engineer at ICBC, the largest bank in China, Zou maintained legacy telecommunication circuits and an IBM mainframe communication controller. During this period, Zou built up their first experience in data security by implementing a cipher machine to...

Read more

Narudom Roongsiriwong
Narudom Roongsiriwong
Head of Digital Architecture

Narudom Roongsiriwong

Head of Digital Architecture

Narudom ROONGSIRIWONG (SVP, Head of Digital Architecture, Bank of Ayudhya (Krungsri Bank) PCL, Thailand) has been an information security professional for over twenty years with solid technical experience in architecture, data analytics, application development and cloud computing. He has experience in running three security operation centers and the last one operated with in-house AI and Machine Learning. He was a pioneer in setting up the...

Read more

Geng Tao Headshot Missing
Geng Tao

Geng Tao

Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?

Related Certificates & Training