Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To secure sensitive data in the cloud, first identify and classify it, then apply controls across its lifecycle: limit who can access it, protect it with encryption and managed keys, monitor activity, and test that you can recover it. The exact settings depend on whether you use IaaS, PaaS, or SaaS and on which controls your provider operates.

1. Find and classify the data

You cannot protect information consistently if you do not know what it is or where it goes. Inventory both structured data, such as database records, and unstructured data, such as documents, messages, and files. Map where information is created, stored, accessed, shared, transferred, and eventually retired.

Classify each data set by the harm its exposure, alteration, or loss could cause, as well as any obligations that apply to it. Use those classifications to set protection requirements rather than applying the same controls to every workload. CISA’s Cloud Security Technical Reference Architecture emphasizes protection throughout the data lifecycle and for data at rest, in transit, and in use.

  • Identify sensitive data stores, including copies, exports, and shared files.
  • Record which people, applications, and services need access, and why.
  • Define the protection level and retention or deletion requirements for each class.

2. Define shared-responsibility boundaries

Cloud security is shared, but the division of work changes by service and configuration. For every cloud service, document which controls your organization operates and which the provider operates. Do not assume that a provider’s security measures cover your data access policies, sharing decisions, retention, or recovery.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sandisk 2TB Extreme Portable SSD, Up to 1050MB/s, USB-C, USB 3.2 Gen 2, IP65 Water and Dust Resistance, Updated Firmware, External Solid State Drive, SDSSDE61-2T00-G25
  • Get NVMe solid state performance with up to 1050MB/s read and 1000MB/s write speeds in a portable, high-capacity drive(1) (Based on internal testing; performance may be lower depending on host device & other factors. 1MB=1,000,000 bytes.)
  • Up to 3-meter drop protection and IP65 water and dust resistance mean this tough drive can take a beating(3) (Previously rated for 2-meter drop protection and IP55 rating. Now qualified for the higher, stated specs.)
  • Use the handy carabiner loop to secure it to your belt loop or backpack for extra peace of mind.
  • Help keep private content private with the included password protection featuring 256‐bit AES hardware encryption.(3)
  • Easily manage files and automatically free up space with the SanDisk Memory Zone app.(5). Non-Operating Temperature -20°C to 85°C

NIST’s SP 800-210 addresses access control across IaaS, PaaS, and SaaS. The service model helps explain what you can configure, but the actual boundary is service-specific; confirm it in the provider’s documentation and your contract.

Service model What to establish
IaaS Which infrastructure and access controls the provider operates and which configurations, identities, workloads, and data protections remain yours.
PaaS Which platform protections the provider manages and which application, identity, data, and configuration controls you must manage.
SaaS Which service controls the provider manages and which tenant settings, user permissions, sharing rules, retention, and data-handling decisions are yours.

For each service, name who approves data sharing, manages user access, controls encryption keys, handles deletion, and closes out data when the service ends. Revisit the assignment when a service, configuration, contract, or provider capability changes. CISA’s architecture provides guidance on protecting cloud data and managing responsibilities across the lifecycle.

3. Restrict identities and permissions

Give each user, application, and administrator only the permissions needed for their work, and remove or adjust access promptly when responsibilities change. Use granular controls for sensitive data and privileged accounts, and review access regularly for stale accounts, excessive privileges, and risky sharing.

Rank #2
Sale
SSK Portable SSD 500GB External Solid State Hard Drive USB C Up to 1050MB/s
  • Capacity Display Variance: 500GB external ssd often appears as around 465GB on Windows. MacOS can show full 500 GB capacity. This is binary calculation difference and doesn’t affect SSD hard drive actual physical storage
  • 1050 MB/s Speed: Instantly access to your files with blazing-fast 10Gbps external SSD read up to 1050MB/s and write up to 1000MB/s. LED Light indicates USB SSD instant activity
  • Data Security: Solid state drives S.M.A.R.T. health diagnostics​ and adaptive TRIM optimizing data block management ensures consistent write speeds and extends the longevity of the portable SSD
  • USB-C & USB-A Cable: Both cables featuring rapid USB 3.2 Gen2, this USB SSD effortlessly bridges devices, enabling seamless cross-platform file transfers and backup between computers, smartphones, tablets and iPhone
  • Always Fast: No slowdowns for large file transfers. With SLC caching (25% of current available capacity allocated as high-speed cache), this external SSD delivers steady 10Gbps for transfers within the cache capacity

Require multifactor authentication (MFA) for privileged identities. CISA states that “Best practices such as enabling MFA and setting more granular levels of access and permissions for privileged accounts can limit unauthorized access and privilege escalation within the network, directory services, and applications” in its Cloud Security Technical Reference Architecture.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Use role-based permissions where they fit, and more specific rules when access should depend on context, device, or data classification.
  • Check actual features in each IaaS, PaaS, and SaaS service; a control available in one does not necessarily work the same way in another.
  • Consider a hardware security key for MFA on privileged accounts if the identity provider and account support it.

4. Encrypt data and govern the keys

Protect data at rest and in transit. For workloads where the risk warrants it and the service supports it, also assess protection while data is being used. Encryption does not by itself settle who can read the information: that depends on where encryption occurs, who holds the keys, and which systems can access plaintext.

With client-side encryption, data is encrypted before it reaches the cloud service, which can limit the provider’s ability to see plaintext if keys remain outside its control. With server-side encryption, the service encrypts stored data, but the provider or service may process plaintext to deliver its functions. Neither arrangement is universally right; choose based on the threat model, service requirements, and who must be able to access the data.

Rank #3
Sale
Sandisk 1TB Extreme Portable SSD, Up to 2000MB/s Transfer Speeds-New Model
  • NEARLY 2X FASTER THAN OUR PREVIOUS GENERATION(8) – move 1,000 high-res photos in under 60 seconds(6) with up to 2000MB/s transfer speeds(2).
  • IP65 RATING AND UP TO 3M DROP PROTECTION(3) – protects against spills and drops.
  • POCKET-SIZED – fits easily in pockets and small bags.
  • SPACE TO OWN YOUR AI CONTENT – speed and capacity to download your high-res clips and photo edits.
  • 256-BIT AES ENCRYPTION(4) – helps keep private files secure with password protection.

Document who can create, use, rotate, recover, and revoke keys. Restrict key access separately from data access where feasible, and verify the provider’s role and capabilities. NIST’s Guidelines on Security and Privacy in Public Cloud Computing discusses cloud security and privacy considerations, including the importance of understanding provider responsibilities.

5. Back up data and prove recovery works

Maintain backups suited to the value of the data and the recovery needs of the service. Where feasible, isolate backup copies from routine accounts and systems so an attacker or mistaken change cannot easily affect both production data and its backups. An encrypted backup drive or offline storage may be one part of a broader plan, but neither alone guarantees off-site protection or recoverability.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Test restoration regularly and retain evidence that the restored data and service are usable. CISA recommends frequent backup testing; NIST’s storage guidance addresses restoration assurance and isolation. A backup that has never been restored is not proof that recovery will work.

Rank #4
Sale
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
  • Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
  • To get set up, connect the portable hard drive to a computer for automatic recognition no software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.

Set recovery objectives appropriate to the workload, then test the relevant files, databases, or services against them. Include the credentials, keys, dependencies, and permissions required to restore—not only the backup copy itself.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

6. Monitor activity and configuration

Collect and review signals that can reveal unauthorized access, accidental exposure, or risky changes. Monitoring should cover identity events, management-plane activity, service and resource logs, configuration changes, and data-sharing activity.

  • Watch for unusual sign-ins, privilege changes, failed access attempts, and changes to administrator accounts.
  • Review configuration and sharing changes that could expose sensitive data, such as a newly public resource or a broadened permission.
  • Ensure logs are available to the people or systems responsible for detection and response, and retain them according to operational and legal needs.

The Cloud Security Alliance’s Cloud Controls Matrix includes cloud control objectives, while its Cloud Controls Matrix documentation identifies monitoring topics such as cloud telemetry, management-plane logs, service and resource logs, and configuration detection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
Samsung T7 Portable SSD 1TB Titan Gray, USB 3.2 Gen 2, Up to 1,050MB/s
  • MADE FOR THE MAKERS: Create; Explore; Store; The T7 Portable SSD delivers fast speeds and durable features to back up any endeavor; Build your video editing empire, file your photographs or back up your blogs all in an instant
  • SHARE IDEAS IN A FLASH: Don’t waste a second waiting and spend more time doing; The T7 is embedded with PCIe NVMe technology that brings fast read and write speeds up to 1,050/1,000 MB/s¹, making it almost twice as fast as the T5
  • ALWAYS MAKE THE SAVE: Compact design with massive capacity; With capacities up to 4TB, save exactly what you need to your drive – from large working files to game data and everything in between
  • ADAPTS TO EVERY NEED: Whether using a PC or mobile phone, count on the T7 for extensive compatibility²; It’s a true team player when it comes to heavy-duty application usage or file-saving
  • HI RESOLUTION VIDEO RECORDING: Record Ultra High Resolution (4K 60fs) videos directly onto the T7 Portable SSD with your favorite camera or mobile devices; Supports iPhone 15 Pro Res 4K at 60fps video and more³

7. Review the environment and data lifecycle

Review which cloud regions and services are actually in use, including resources that are unused, unsupported, or outside your organization’s approved scope. Confirm that the controls still match each data classification and service responsibility boundary.

Plan what happens when data or a service is no longer needed. Establish how data will be deleted or sanitized, who confirms completion, and what records must be retained. Also reassess protections when the provider changes capabilities or terms, or when your organization changes its configuration or use of the service. CISA’s cloud architecture calls for attention to data through its lifecycle, including disposal.

Quick Recap

SaleBestseller No. 3
Sandisk 1TB Extreme Portable SSD, Up to 2000MB/s Transfer Speeds-New Model
Sandisk 1TB Extreme Portable SSD, Up to 2000MB/s Transfer Speeds-New Model
IP65 RATING AND UP TO 3M DROP PROTECTION(3) – protects against spills and drops.; POCKET-SIZED – fits easily in pockets and small bags.
$209.99
SaleBestseller No. 4
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$119.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.