Understanding the dynamics of security and compliance
Security and compliance are two completely different things, yet they are closely related to each other. Security policies are required to achieve compliance. We will get into the relationship a bit further in this section.
First, let’s get a good definition of security. Security involves all activity to protect assets of a company and the users of their systems. This activity can be defined in security controls: physical, technical, and administrative. Typically, we don’t have to worry about physical controls in cloud. Microsoft, Amazon, Google, Alibaba, and Oracle will make sre that their datacenters and all the hardware that’s in the datacenter is well protected. We do have to worry about the technical and the administrative controls. We need to take action to for instance implement antivirus and antimalware software on workloads that we host in the cloud: these are technical controls. Administrative controls...