How to Design a Secure Serverless Architecture
How to Design a Secure Serverless Architecture


Peer Review: C-Level Guidance to Securing Serverless Architectures
What is serverless?
Serverless computing is an execution model for the cloud. It gives users/developers the ability to build and run applications and services without thinking about servers. Applications are built faster, launched only as needed, and the management of the infrastructure is no longer required. Servers do continue to exist in serverless, but they are abstracted away from the application development procedure. The infrastructure is handled and maintained by the cloud provider, while developers simply package the deployment of their code in containers.

Why is it important?
Serverless brings quite some promising benefits for application developers. Because of automatic scalability, provisioning, and other such characteristics done by the cloud provider, that eliminate the infrastructure concerns from the developers’ focus, the deployment of applications becomes easy, faster and at a lower cost. This way, serverless architecture aims at changing the economic model of cloud computing.

If you are interested in learning how to better secure serverless applications, we recommend you start by reading these recommendations from CSA. 

ServerlessApplication Containers and MicroservicesDevSecOps

The Serverless working group seeks to develop best practices to help organizations that want to run their business with a serverless business model. With the complexity of this business model, it is imperative that industry best practices are established to provide companies with guidelines to achieve compliance and security.

Next Meeting

No Meetings Currently Scheduled

Working Group Leadership

Aradhna Chetal Headshot
Aradhna Chetal
Aradhna Chetal

Senior Director Executive- Cloud Security

Aradhna serves as a Senior Director Executive- Cloud Security at TIAA, a financial services company. She is responsible for the cloud security vision, strategy, standards, security patterns for a multi-cloud hybrid enterprise and engineer security solutions, to support the vision. Aradhna has worked in various Cybersecurity leadership roles at JP Morgan Chase, Boeing Company, Microsoft & T-Mobile.

Aradhna is an active member in the cy...

Read more

Vishwas Manral Headshot
Vishwas Manral
Vishwas Manral

Head of Cloud Native Security and Chief Architect, Cloud at McAfee Enterprise

Vishwas is the co-chair of CSA’s Serverless working group and a contributor to theApplication Containers and Microservices working group. He has served as a presenter at the CSA Virtual EU Summit 2020, and as chair of the Silicon Valley chapter. He is the head of Cl...

Read more

Join this working group

Cloud Security Research for Serverless

CSA Research crowd-sources the knowledge and expertise of security experts and helps address the challenges and needs they’ve experienced, or seen others experience, within the cybersecurity field. Each publication is vendor-neutral and follows the peer review process outlined in the CSA Research Lifecycle. We recommend getting started by reading the following documents.

The 12 Most Critical Risks for Serverless Applications

The 12 Most Critical Risks for Serverless Applications

As many organizations are still exploring serverless architectures or just taking their first steps in the serverless world, Cloud Security Alliance (CSA) believes this guide is critical for their success in building robust, secure and reliable applications. The 12 Most Critical Risks for Serverless Applications 2019 document is meant to serve as a security awareness and education guide. This report was curated and maintained by top industry practitioners and security researchers with vast experience in application security, cloud, and serverless architectures.

How to Design a Secure Serverless Architecture

How to Design a Secure Serverless Architecture

Like any solution, serverless computing brings with it a variety of cyber risks. This paper covers security for serverless applications, focusing on best practices and recommendations. It offers an extensive overview of the different threats, focusing on the application owner risks that serverless platforms are exposed to and suggesting the appropriate security controls.

Blog Posts

What is Serverless? How Does it Impact Security?
Kubernetes Security Best Practices
What is a Cloud-Native Application Protection Platform (CNAPP)?