Approximately 39% of UK business owners are worried about cloud cyber security. Many have logical and grounded concerns about their data or customers’ data, and how safe it truly is within the cloud or stored on remote servers far from their offices and workspaces.
This is something that the NCSC (National Cyber Security Centre) aims to address through its NCSC cloud security principles. It outlines 14 of these principles. Together, they form a clear framework for secure cloud development, and they are invaluable for those on both sides of the cloud service market – the developers and the consumers.
What Are the NCSC 14 Cloud Security Principles?
A straightforward way to think of the NCSC cloud security principles is like a rulebook for secure cloud development. They are a list of guidelines that cloud service providers should follow to ensure every aspect and layer of their end products is as secure as possible, so the end user feels protected and has peace of mind.
However, the NCSC cloud security principles are not just for developers and providers. They also offer value to other businesses and even individuals looking to invest in cloud technology. They provide a guide for consumers to understand the risks cloud technology may bring and find solutions that do the best job of mitigating those risks.
A complete list of the NCSC 14 cloud security principles follows:
- Data in transit protection: This concerns data protection as it transits from network to network and device to device across the cloud.
- Asset protection and resilience: All data within the cloud, along with the assets that store and process that data, must be protected against damage, tampering, etc.
- Separation between customers: People who use the service or product should not be able to access the data of other customers – boundaries must exist to keep them separate and isolated.
- Governance framework: Cloud providers should establish management and oversight networks to maintain security standards of cloud services throughout their lifecycle.
- Operational security: The service must be handled in a proactive, secure way to discern and put a stop to possible cyber attacks.
- Personnel security: Any personnel given access to data and cloud systems must be trained and trustworthy.
- Secure development: Cloud products/services should be designed from start to finish with security as a core goal and focus.
- Supply chain security: Any third-party supply chain providers should also abide by the same security standards as the product provider.
- Secure user management: Users need to have tools and functions at their disposal to manage the way they use the service securely.
- Identity and authentication: Only authorised users should be able to access the services and data of the cloud product or service.
- External interface protection: External interfaces with access to the product must be spotted and secured, as they could present weaknesses otherwise.
- Secure service administration: Development and management of a service’s admin systems must also be done securely and according to best cloud cyber security practices.
- Audit information and alerting for customers: Products/services should be able to produce logs and alerts of security events that can then be audited.
- Secure use of the service: Providers need to make it straightforward for users to secure their data.
These are just brief outlines of the principles of cloud security. Official NCSC documentation naturally goes much more in-depth, and each principle has its specificities, objectives, etc. Here is an example for the eighth principle, “Supply chain security.”
Those investing in cloud computing need to pay attention to these cloud security principles. Seek out providers that abide by them and tools designed in accordance with them. The Kahootz cloud collaboration platform is a clear example of this. Tools like Kahootz provide peace of mind and the lowest possible risk of cloud cyber security problems.
Why Are the NCSC Cloud Security Principles Important?
They are important for several reasons, beginning with providing a clear and complete framework for safe cloud computing development. When providers want to design and build cloud solutions, they can turn to the NCSC 14 cloud security principles to guide them and show them what to do and what not to do to ensure their end products are as safe as they can be.
The NSCS’s principles are also holistic in nature, covering every aspect of cloud security and management, from data in transit protection to incident responses, etc. #Additionally, these principles foster a sense of collaboration and sharing of responsibilities among cloud providers and consumers – the providers have a framework to follow during development, and consumers can use it to find and invest in the strongest solutions. Together, this makes the entire cloud ecosystem and industry more secure.
Beyond the List – Understanding the Principles in Action
Reading through the NCSC cloud security principles list is a fundamental step in understanding them. But, if you want to fully comprehend the value and importance of each one, it is even more important to see them in action.
So, in the sections below, we will look at real-world examples of some of these cloud security principles, illustrating their practical implications and valuable benefits. We will also provide clear, actionable advice that organisations can use to implement and comply with the principles themselves.
Data Protection and Privacy
The very first of the 14 NCSC cloud security principles is “Data in transit protection.” It is about looking after data as it moves across the cloud from node to node, network to network, etc. Data is more at risk while in transit – during this process, bad actors can use a range of techniques, like “man in the middle” attacks to try and view or steal the data.
The onus is on cloud solution providers, then, to implement protective measures that safeguard data as it travels. The most obvious example of this in action is encryption. All good cloud service providers invest in encryption, like TLS (Transport Layer Security), for data moving across the cloud. Many offer on-site encryption for users to encrypt their data independently, too.
One of the benefits and reasons for using cloud technology in the first place is its accessibility. It allows for the free and fluid flow of data and access from devices in different locations.
Regarding real-world examples, tech giant Amazon offers several secure data transit tools through Amazon Web Services (AWS). AWS DataSync, for example, helps transfer data between on-premises sites and AWS server locations, using both Amazon’s own S3 API encryption, plus TLS encryption, in alignment with the first NCSC principle.
Secure Operations and Management
Entry No. 4 in the NCSC’s cloud security principles is “Governance framework.” In the NCSC’s own words, a framework like this is “vital to coordinate and direct the management of the service.” In other words, this principle urges cloud service providers to establish their own systems and oversight teams to manage their services throughout their lifecycle.
In real terms, this involves naming experienced and qualified people in key roles and essentially setting up a board of overseers for the cloud service. Key roles for the team include Chief Security Officer, Risk Owner, and Information Asset Owner, and each role must be clearly defined with its duties and responsibilities.
It is up to this overseeing team to respond accordingly. The team is also responsible for establishing processes to ensure compliance with any relevant legal frameworks or regulatory bodies, which are very important for tools that could be used in highly regulated industries like healthcare, finance, etc.
A real-world example of this principle in action is Kahootz, the secure collaboration platform of choice among multiple governmental departments, the NHS, Land Registry, and other major authorities and organisations across the UK. Its strong governance framework and comprehensively secured administrative systems have earned this status.
Addressing People-Centric Security Challenges
Many people-centric challenges emerge throughout cloud service development, launch, and maintenance.
This is why several of the NCSC cloud security principles are concerned with the end user. Principle No. 7, for example, is “Secure Development,” to ensure security is a top priority throughout development, while principle No. 9 focuses on “Secure user management.”
“Secure development” is quite a broad and maybe even vague term to some, so the easiest way to comply with it is often to follow an existing, established development policy. ISO 27001-compliant policies, for example, provide clear rules on creating the most secure cloud apps. It also helps if providers regularly test and audit their software and underlying infrastructure to maintain security in the cloud.
The UK government’s platform as a service (PaaS) is a great example of these concepts in action. To comply with “Secure development,” the PaaS has consistently undergone regular dependency monitoring and was developed through a test-driven, security-focused approach with a strict operations policy. It also uses Cloud Foundry’s UAA system for secure user authentication and access.
The Extended Ecosystem
Some of the NCSC cloud security principles also stretch beyond the product or service and to the underlying support and supply chain systems that keep it up and running. For example, the eighth entry in the list is “Supply chain security” and revolves around assessing and managing the security risks that could emerge through the supply chain.
This matters, because a lot of cloud products and services rely at least in part on third-party supply chain providers. Many of them send and receive data to and from different servers and data centres, which can be in various locations around the globe and managed by a range of third-parties. For every additional party and server involved, there are extra security risks to acknowledge and account for.
For a product to comply fully with NCSC cloud security principles, the third parties in question must be just as committed to security as the provider. The provider must take steps to mitigate any possible risks the third-party involvements could present, like external interface protections (outlined in the 11th security principle), secure APIs, etc.
For a case study that illustrates these ideas, we can return to Kahootz. This is the only publicly available cloud collaboration platform approved by the UK’s Ministry of Defence for storing and sharing sensitive data. That means the entire supply chain powering Kahootz is entrusted by the UK’s leading authority on defence – an unparalleled hallmark of security.
Summing Up: NCSC Cloud Security Principles – The Guiding Lights of Cloud Cyber Security
Today’s cloud products and services in the UK is much safer than it once was, thanks to the NCSC 14 cloud security principles. These principles mitigate risks, reduce the likelihood of products launching or persisting in insecure states, and help give those on both sides of the equation – providers and consumers – clear ideas to keep in mind when making or investing in these products.
They also make it much easier to find and choose the best possible cloud products for all your business needs – just look for providers that take the principles seriously and comply with all 14. It is a guaranteed sign of quality and trust, and if you’re looking for a proven cloud collaboration platform designed following NCSC standards, Kahootz is the one to choose.
Built from the ground up with security as a core conceit, Kahootz meets both UK and international standards of cloud cyber security. That includes the NCSC 14 cloud security principles, plus the international ISO 27001 standard. It is even trusted by the UK government and used within the Ministry of Defence and Department of Health, making it a truly secure cloud solution everyone can rely on.