Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To secure data in cloud services, first identify and classify what you store, then restrict who and what can access it, protect it in transit and at rest, and monitor, back up, and securely retire it. The right controls depend on the data’s sensitivity, the service model, your provider’s features, and the responsibilities set out in your cloud agreement.

Who is responsible for cloud data security?

Cloud security is shared between the customer and provider, but the division of work varies by service model and contract. Providers operate parts of the underlying service; customers remain responsible for choices such as what data they put there, who they authorize to use it, and how they configure the controls available to them. Do not assume that a provider’s security measures automatically meet your organization’s requirements.

Map responsibility to each service and data set. Check the provider’s current documentation and service-level terms for which controls it operates, which you must configure, what its defaults cover, and what happens to data when the service ends. CISA’s Cloud Security Technical Reference Architecture treats data protection as a lifecycle that includes creation, storage, access, movement, sharing, and retirement.

Start by identifying and classifying the data

You cannot choose proportionate protections until you know what data exists and what obligations apply to it. Inventory data stores and the services that handle them, including copies, exports, backups, and data shared with other services. Classify each set according to its sensitivity and your organization’s legal, regulatory, and contractual requirements.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Heavy Duty Lockable Enclosure Box for Security Wiring, Black
  • {Durable Steel Material} This CCTV outdoor enclosure box features high-quality, dust proof metal housing. Its anti-stress base plate and included safety lock ensure safety protection for longer life.17.72"×13.90"×3.86"
  • {Universal Compatibility} Our safety enclosure is not only designed for DVR/NVR recorders, but is also ideal for organizing and protecting electrical cable wiring. It features an safety lock for peace of mind, and includes built-in cable ports to keep wires neatly routed.
  • {Ventilation Design} The electric box Features multiple cooling vents on the front cover and both side panels, promoting air circulation to dissipate heat, lower the internal temperature, and prevent issues caused by overheating cables, such as performance damage.
  • {Reinforced Hinge} This junction box has an openable front panel that offers flexible adjustment, not a fixed cover. Easily flip it open to adjust wiring, clean inside, or check your equipment anytime—no tools needed.
  • {Easy Installation} There are 4 mounting holes on the back of the enclosure box. Simply mount the box and run your cables through the top or bottom. Then close the cover, lock it, and you're done.

For each classification, document who may access the data, who can authorize sharing, where it may be stored or moved, and what protection is required at rest and in transit. Treat classification as an input to technical controls, not just a label: a sensitive data set may need narrower permissions, stronger monitoring, additional encryption controls, or stricter limits on movement than ordinary business data.

Match access controls to the service model

Apply least privilege: give each person, workload, and service only the access it needs, and remove access when the need ends. Review identities, roles, policies, sharing settings, and service components that can reach each data set. Access control is not one setting in a single cloud console; the points you can configure differ across infrastructure, platform, and software services. NIST’s SP 800-210, General Access Control Guidance for Cloud Systems, addresses IaaS, PaaS, and SaaS and explains that their access-control considerations differ.

Service model Typical customer control points What to verify
IaaS Customer-configured identities, permissions, and controls on the infrastructure and workloads they operate. Which infrastructure, workload, and data-layer controls you configure versus those operated by the provider.
PaaS Customer-configured access to applications, data, and platform features exposed by the service. Which platform components and security settings are customer-managed, and how workload identities can access data.
SaaS Customer-configured users, roles, data sharing, and available application security settings. How application roles and sharing work, what the provider operates, and which data-protection options are available.

These are typical areas to check, not a universal responsibility chart: actual controls depend on the specific service. Review access at the level where data can be reached, including through a user account, an application, an automated workload, or a connection between services. NIST also notes that guidance for functional components in lower-level service models can apply to higher-level models.

Protect data in transit and at rest

Use encryption for sensitive data both while it travels and while it is stored. Then verify the details rather than treating an “encryption enabled” indicator as proof that every relevant path is covered. Check which stored data and backups are encrypted, which service-to-service and user connections are protected in transit, and whether the available protections satisfy your organization’s requirements.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Provider defaults and features vary by service and can change. Confirm current behavior in the documentation for the particular service, and identify any data paths or copies that need additional protection. Google Cloud’s security-by-design guidance includes access control, segmentation, residency, auditing, and requirements-based encryption as parts of data protection.

Rank #2
Pomya 2.5In Hard Drive Storage Box 20 Bays 2.5 Inch Hard Disk Box Double Handle Hard Drive Case with Security Lock for 2.5 Inch Hard Drive
  • Double : The hard drive storage box has a built in environmental EVA material buffer pad, which can preserve the hard drive well.
  • Comprehensive : Hard drive storage case has various functions, such as shockproof, external etc.
  • Convenient Handle: The hard drive carrying case adopts ABS high strength sturdy handle, which is easy to carry, and the aluminum alloy corner design is sturdy, anti drop.
  • Security Lock: The hard drive case is designed with a security lock, which firmly secures the box cover, preventing the door from being accidentally opened or stolen, strong and more secure, with a key.
  • 20 Bays: 2.5in hard drive storage box has 20 bays, large capacity, can store hard drives safely, and is highly practical.

Choose encryption and key controls deliberately

Encryption is only part of the decision: consider who controls the keys, who can use them, and whether the arrangement fits operational and compliance needs. CISA distinguishes client-side encryption, in which the organization creates and retains the key so the provider cannot view the stored data, from server-side encryption, in which data is encrypted at its cloud destination. These approaches have different control and operating implications.

Approach Key and data access Trade-off to assess
Client-side encryption The organization creates and retains the key; the provider cannot view data protected this way. Greater organizational control means the organization must manage key availability and related operations.
Server-side encryption Data is encrypted at its cloud destination; key arrangements depend on the service and configuration. Confirm what the service encrypts, who can access or manage keys, and whether the arrangement meets your requirements.

Separately decide whether provider-managed or customer-managed keys are appropriate. Customer-managed keys can offer more control over key access and separation, but they also place key-management responsibilities on your organization and may not work identically across all services. Neither customer-managed keys nor encryption alone prevents exposure through an authorized but compromised account, incorrect sharing, or an application that can access the data. Microsoft’s cloud security benchmark guidance on data protection groups recommendations around discovery and classification, monitoring, encryption in transit and at rest, key and certificate management, and authorized access.

Monitor access, configuration changes, and recovery

Enable logging for data access and relevant configuration changes, review those records, and alert on activity that is unusual for your environment. Monitoring helps surface unintended exposure as well as suspicious access. Also separate resources where doing so reduces the chance that an error or overly broad permission exposes unrelated data. Review account access and keep track of regions and services that are unused or unsupported.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Backups are part of data protection, but an untested backup does not prove you can recover. Test backups regularly and verify that the recovery procedure works for the data and service involved. Keep recovery access and processes within the same access-control and monitoring discipline as production data.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Include data movement and retirement in the protection plan

Data can cross boundaries when users share it, applications call other services, or systems copy it between cloud, on-premises, hybrid, and multi-cloud environments. Map those flows and check that access rules and encryption protect the data along the paths it actually takes, not only in its primary storage location.

Rank #3
Sale
KYODOLED Safe Box with Digital Keypad Lock, Lock Box with Code for Personal Items, Metal Security Box for Cash, Passport, Jewelry, Ideal for Home, Office, Garage Sale, 11.8'' x 9.4'' x 3.5'', Black
  • Robust security: Made of heavy-duty steel, the Security box with code provides rock-solid security for your personal items, whether in your bedroom drawer or checked luggage. The portable carrying handle makes it perfect for home and business trips. Note: The metal casing offers essential protection, its thickness is limited and may be compromised under extreme force, such as with pry tools or blunt impact.
  • Spacious storage: With interior dimensions of 11.7" W x 9.12" D x 2.75" H, exterior dimensions of 11.8" W x 9.4" D x 3.5" H, you can easily store cash, passports, watch, and other items. The spring keeps the lid open securely, keep valuables protected but accessible with this storage safe box.
  • Dual privacy protection: Kyodoled digital lock box with customizable 3-8 digit code and 2 emergency keys protects your sensitive documents safe and prevent privacy from prying eyes. Spare keys allows you to access your belongings even if the batteries die. (Requires 4 No.5 AA batteries, not included)
  • Anti-scratch interior: A soft sponge-lined interior safeguards delicate items, even fragile ones like jewelry or electronics, preventing scratches and damage during transport.
  • Versatile use: As a beginner security box, it's ideal for storing documents, cash, cards, phones, keepsakes, photos. It’s also a handy choice for home, office, festival events, fundraisers, or garage sales. Moderate in size, the safe box can be discreetly placed under a table or locked inside a cabinet—keeping your items safe while you focus on your booth.

For systems with many short-lived or service-to-service connections, NIST’s IR 8505, A Data Protection Approach for Cloud-Native Applications, addresses data categorization and protection in transit in cloud-native, hybrid, and multi-cloud settings, including service-mesh architectures. Its focus is particularly relevant to complex environments; it is not a requirement that every small cloud deployment adopt a service mesh.

Plan how to retire data when it is no longer needed or a service ends. CISA calls attention to sanitizing data, accounts, and machine images as part of service termination. Include exported copies, backups, and associated access paths in that process, and check the provider’s terms and capabilities for deletion and sanitization.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Scale controls to risk and operational capacity

Apply a baseline appropriate to the sensitivity of the data, the threats to the workload, applicable obligations, and your ability to operate the controls reliably. Add stronger measures where the risk or requirements justify them; avoid adopting a complex control that cannot be maintained or verified. Google Cloud describes graduated basic, intermediate, and advanced baseline levels in its minimum viable secure platform guidance. That is one provider’s way of organizing security baselines, not a universal certification or a standard every organization must follow.

Reassess protections when you change services, data uses, provider features, or service-level agreements. A configuration that was suitable for one workload or earlier service version may not cover a new data path or requirement. Make the review part of cloud-service changes rather than waiting for an incident.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.