Learning Objectives:
-
Understand the unique security challenges of cloud adoption.
-
Apply cloud security best practices and the shared responsibility model.
-
Implement secure cloud migration strategies.
-
Recognise the regulatory requirements for cloud security.
7.1 Cloud Security Challenges
The financial sector’s full dependency on ICT providers, especially cloud service providers, core banking vendors, and outsourced AI systems, is a key driver of ICT-related risks . Cloud adoption introduces unique security challenges, including data sovereignty, vendor lock-in, and the shared responsibility model.
Key Cloud Security Challenges:
Data Sovereignty: The requirement to keep data within specific geographic boundaries.
Vendor Lock-in: Difficulty migrating from one cloud provider to another.
Shared Responsibility Model: Understanding which security responsibilities are the cloud provider’s and which are the organisation’s.
Misconfiguration: Cloud misconfigurations are a leading cause of data breaches.
7.2 The Shared Responsibility Model
In cloud computing, security is a shared responsibility between the cloud provider and the customer. Understanding this model is essential for effective cloud security.
Cloud Provider Responsibilities:
-
Security of the cloud infrastructure
-
Physical security of data centres
-
Network and storage security (depending on the service model)
Customer Responsibilities:
-
Identity and access management
-
Data protection (encryption)
-
Security configuration
-
Vulnerability management
-
Incident response
7.3 Secure Cloud Migration
The ECB’s SREP methodology requires that financial entities have an ICT strategic plan aligned with the business strategy . This includes planning for cloud adoption.
Key Cloud Migration Considerations:
Risk Assessment: Assessing the security risks of cloud adoption.
Provider Selection: Selecting cloud providers with appropriate security certifications and controls.
Data Protection: Ensuring data is protected in the cloud, including encryption.
Access Control: Implementing strong access controls for cloud resources.
Monitoring: Monitoring cloud environments for security incidents.
7.4 Regulatory Requirements for Cloud Security
DORA establishes structured, enforceable rules for managing outsourcing and external dependencies, including cloud services :
-
Risk Assessment: Financial institutions must continuously assess the risk level of all ICT service providers.
-
Contractual Requirements: Outsourcing contracts must clearly specify service level objectives, incident response expectations, data access rights, location of data processing, and exit strategies.
-
Access Rights: Institutions and regulators must retain the right to access, audit, and inspect the ICT systems and premises of third-party providers.
-
Internal Register: Each institution must maintain a standardised internal register of all ICT-related contracts, including criticality assessments and subcontracting chains.
The RBI requires that all regulated entities must perform a risk assessment and due diligence before entering into any arrangements with third parties or external entities . Regulated entities should also verify whether the third party has at least an equivalent level of operational resilience to safeguard the regulated entity’s critical operations .