Overview of Risks, Threats, and Vulnerabilities Faced in Moving to the Cloud
July 2019 • Technical Report
Timothy Morrow, Kelwyn Pender, Carrie Lee (U.S. Department of Veteran Affairs), Donald Faatz
This report, updated in October 2020, examines the changes to risks, threats, and vulnerabilities when applications are deployed to cloud services.
Software Engineering Institute
CMU/SEI Report Number
DOI (Digital Object Identifier):10.1184/R1/12363569.v2
As organizations develop new applications in or migrate existing applications to cloud services, they face changes in securing their information and applications. This report examines the changes to risks, threats, and vulnerabilities when applications are deployed to cloud services. Five cloud-unique threats and risks are identified along with seven threats and risks that exist on-premises and in cloud computing. For each of these threats and risks, recommendations are made for managing and mitigating the threats and risks when using cloud services.
In October 2020, this report was updated to
- add information about containers and orchestration
- update risk #5 Incomplete Data Deletion
- add new risk #13 Risks Transfer Between CSP and Customers