Terminology Index

Glossary

1801 terms

Open concept maps

Showing 481-512 of 1801 terms

C
11

Customer-Implemented Controls

The security controls that, under shared responsibility, the customer must build and operate themselves in the cloud, such as configuring identity, encryption, network rules, and logging, as opposed to controls inherited from the provider.

Cloud providers secure the underlying infrastructure, but many controls are the customer's to implement: setting up least-privilege IAM, enabling encryption and logging, configuring network segmentation, and more. Customer-implemented controls are where the customer's real security and compliance work lives, and they must be operated and evidenced by the customer. Confusing them with inherited controls leaves dangerous gaps.

Introduced in: Cloud Compliance and Frameworks

Examples

  • Configuring least-privilege IAM as a customer-implemented control.
  • Enabling encryption and audit logging the provider does not turn on by default.
  • Evidencing customer-side network controls for an audit.

No related terms linked yet.

D
21