{"id":1229,"date":"2026-09-13T20:38:27","date_gmt":"2026-09-13T20:38:27","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1229"},"modified":"2026-09-13T20:38:27","modified_gmt":"2026-09-13T20:38:27","slug":"cloud-security","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/cloud-security\/","title":{"rendered":"Cloud Security"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: CLOUD SECURITY\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">Cloud providers rarely get breached. Their customers do, on the side of the line the provider was never responsible for.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Cloud<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Cloud security is the set of controls protecting the part of your cloud environment that you configure and operate. The provider secures the physical infrastructure, the hypervisor and the managed services underneath. Everything above that line, meaning your configuration, your identities, your data and your applications, is yours. Almost every publicised cloud incident traces to that upper half.<\/p>\n<\/div>\n\n<p>Knowing where the line sits is the first cloud security control, because you cannot protect an obligation you assumed belonged to someone else.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#responsibility\">The shared responsibility line<\/a><\/li>\n    <li><a href=\"#breaches\">Where cloud security breaches happen<\/a><\/li>\n    <li><a href=\"#layers\">The five cloud security layers<\/a><\/li>\n    <li><a href=\"#identity\">Identity is the cloud security perimeter<\/a><\/li>\n    <li><a href=\"#osto\">Where Osto fits<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"responsibility\">The shared responsibility line<\/h2>\n\n<p>Every cloud security conversation should start here, because the model is contractual rather than technical and most teams have never read where it puts them.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 214\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"The shared responsibility line moves between infrastructure, platform and software services, but customer obligations never disappear.\">\n  <text x=\"14\" y=\"18\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#6b7086\">YOUR RESPONSIBILITY, IN EVERY MODEL<\/text>\n\n  <rect x=\"14\" y=\"28\" width=\"230\" height=\"76\" rx=\"13\" fill=\"#cfd5f2\"\/>\n  <text x=\"129\" y=\"52\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#1c267a\">Infrastructure service<\/text>\n  <text x=\"129\" y=\"72\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Operating system, patching,<\/text>\n  <text x=\"129\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">network rules, identity, data<\/text>\n\n  <rect x=\"258\" y=\"28\" width=\"230\" height=\"76\" rx=\"13\" fill=\"#e2eff7\"\/>\n  <text x=\"373\" y=\"52\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#2f6f96\">Platform service<\/text>\n  <text x=\"373\" y=\"72\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Application code, access<\/text>\n  <text x=\"373\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">configuration, identity, data<\/text>\n\n  <rect x=\"502\" y=\"28\" width=\"244\" height=\"76\" rx=\"13\" fill=\"#e3f0e9\"\/>\n  <text x=\"624\" y=\"52\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#3a6f5d\">Software service<\/text>\n  <text x=\"624\" y=\"72\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Who has access, sharing<\/text>\n  <text x=\"624\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">settings, identity, data<\/text>\n\n  <line x1=\"14\" y1=\"120\" x2=\"746\" y2=\"120\" stroke=\"#b3b8d8\" stroke-width=\"2\" stroke-dasharray=\"6 5\"\/>\n  <text x=\"380\" y=\"138\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" font-weight=\"700\" fill=\"#6b7086\">THE LINE MOVES BY SERVICE TYPE<\/text>\n\n  <rect x=\"14\" y=\"150\" width=\"732\" height=\"52\" rx=\"13\" fill=\"#fbe9dc\"\/>\n  <text x=\"380\" y=\"172\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">Identity and data sit on your side of the line in all three.<\/text>\n  <text x=\"380\" y=\"191\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#a2603a\">Whatever else the provider absorbs, who can reach what, and what happens to it, never transfers.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<p>Moving up the stack transfers work, not accountability. A managed database removes patching from your list and leaves access control, encryption settings and exposure entirely with you.<\/p>\n\n<h2 id=\"breaches\" class=\"c-sage\">Where cloud security breaches happen<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Cause<\/th><th>How it happens<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Storage left public<\/td><td>A bucket or blob opened for a legitimate reason and never closed. No exploit required, because it is simply readable<\/td><\/tr>\n    <tr><td>Over-permissioned identity<\/td><td>A role granted broad rights during setup and never narrowed. One compromised credential then reaches far more than it should<\/td><\/tr>\n    <tr><td>Exposed management interface<\/td><td>A database, dashboard or admin console reachable from the internet, often on a default port with a default password<\/td><\/tr>\n    <tr><td>Leaked keys<\/td><td>Access keys committed to a repository or embedded in a mobile app. Automated scanners find them within minutes of publication<\/td><\/tr>\n    <tr><td>Forgotten resources<\/td><td>A test environment spun up for a prototype, still running months later, unmonitored and unpatched<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>None of these are provider failures, and none require a sophisticated attacker. They are configuration and identity problems, which is why cloud security work concentrates there rather than on exotic threats.<\/p>\n\n<p>It also explains why cloud security spending is often misdirected. A team worried about a sophisticated attacker buys detection tooling while a storage bucket sits open and an unused administrator role from launch week still has full rights. The unglamorous work returns more.<\/p>\n\n<h2 id=\"layers\" class=\"c-plum\">The five cloud security layers<\/h2>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Layer<\/th><th>What it covers<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Posture<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a> continuously checks configuration across accounts and flags what drifted, which addresses the largest single cause above<\/td><\/tr>\n    <tr><td>Identity<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">IAM<\/a> governs who can do what, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pam\/\">PAM<\/a> controls the administrative accounts, and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> stops a stolen password becoming access<\/td><\/tr>\n    <tr><td>Data<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/dspm\/\">DSPM<\/a> locates sensitive data including the copies nobody tracked, with <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest\/\">encryption<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dlp\/\">data loss prevention<\/a> around it<\/td><\/tr>\n    <tr><td>Network and access<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">Zero trust network access<\/a> keeps management interfaces off the public internet entirely, which removes an entire breach category<\/td><\/tr>\n    <tr><td>Workload and application<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">Web application firewall<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API protection<\/a> in front, with <a href=\"https:\/\/www.osto.one\/resources\/glossary\/application-security\/\">application security<\/a> controls in the pipeline behind<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Few teams build all five at once, and they should not. Posture and identity together address the majority of realistic cloud security risk, and they are the two that a small team can maintain without a dedicated hire.<\/p>\n\n<p><a href=\"https:\/\/www.osto.one\/resources\/glossary\/cnapp\/\">CNAPP<\/a> is the industry&#8217;s attempt to sell several of these as one product. The bundle is only worth the premium if it correlates findings across the layers rather than presenting them in adjacent tabs.<\/p>\n\n<h2 id=\"identity\" class=\"c-sky\">Identity is the cloud security perimeter<\/h2>\n\n<div class=\"callout\">\n  <p class=\"k\">There is no network edge to defend<\/p>\n  <p>In a data centre, the firewall marked the boundary and most controls hung off it. In cloud, resources are reachable by design and the boundary is whatever a set of permissions allows. An attacker with valid credentials is not intruding in any technical sense, they are using the platform exactly as configured, which is why so much cloud activity looks normal in logs until someone examines what that identity had no business touching. Permissions granted during a hurried launch and never reviewed are the most common structural weakness in a young cloud estate.<\/p>\n<\/div>\n\n<p>This is also why detection in cloud depends on correlation rather than signatures. A sign-in, a permission change and a large read from storage are unremarkable individually. Together, in that order, from one identity, they are the shape of an incident, and only <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">a system holding all three event types<\/a> can see it.<\/p>\n\n<h2 id=\"osto\">Where Osto fits<\/h2>\n\n<p>Osto covers the customer side of the line across AWS, Azure and GCP from one platform, which for most teams is the entire cloud security requirement in a single place rather than four subscriptions. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">Posture management<\/a> runs continuously against all three, flagging public storage, over-permissive rules and drift as configuration changes. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">Identity and access management<\/a> with enforced <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">multi-factor authentication<\/a> narrows what a stolen credential reaches, and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">zero trust access<\/a> puts cloud servers behind a private domain reachable only from a managed device, which removes exposed management interfaces as a category rather than monitoring for them.<\/p>\n\n<p>In front of the applications, the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">web application firewall<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API protection<\/a> handle live traffic while <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sca\/\">dependency scanning<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sast\/\">static analysis<\/a> work in the pipeline behind them.<\/p>\n\n<p>Because all of it runs in one stack, the correlation described above happens by default rather than requiring integration work. An unusual sign-in, a permission change and an outbound transfer arrive in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">the same SIEM<\/a> and read as one sequence. The evidence produced covers the configuration, access control and monitoring expectations in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">ISO 27001 Annex A<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/hipaa\/\">HIPAA<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Cover your side of the line<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Multi-cloud posture, identity, zero trust access and application protection in one platform, with every event correlated in one SIEM.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Evidence from live controls &middot; 200+ frameworks mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is cloud security?<\/summary>\n  <p>The controls protecting the part of a cloud environment the customer configures and operates, spanning posture, identity, data, network access and the applications running there. The provider secures the infrastructure underneath.<\/p>\n<\/details>\n\n<details>\n  <summary>Is the cloud less secure than on-premise?<\/summary>\n  <p>The infrastructure is generally more secure than most organisations could build themselves. The difference is that configuration mistakes are exposed to the internet immediately, so an error that would have been contained inside a data centre becomes reachable by anyone.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the shared responsibility model?<\/summary>\n  <p>The division between what the provider secures and what you secure. The line moves depending on the service type, but identity, access and data always remain your responsibility.<\/p>\n<\/details>\n\n<details>\n  <summary>What causes most cloud breaches?<\/summary>\n  <p>Misconfiguration and identity, not provider failure. Public storage, over-permissioned roles, exposed management interfaces and leaked access keys account for the majority of publicised incidents.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between cloud security and CSPM?<\/summary>\n  <p>Cloud security is the whole discipline. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a> is one layer within it, focused specifically on finding misconfiguration across accounts. It is usually the right first purchase, but it does not cover identity, data or the applications.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cnapp\/\">CNAPP<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dspm\/\">DSPM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">IAM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">ZTNA<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/application-security\/\">Application Security<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cloud providers rarely get breached. Their customers do, on the side of the line the provider was never responsible for.\u2026<\/p>\n","protected":false},"author":8,"featured_media":1230,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[108,631,630],"class_list":["post-1229","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-cloud-security","tag-cloud-security-layers","tag-shared-responsibility-model"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1229","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1229"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1229\/revisions"}],"predecessor-version":[{"id":1231,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1229\/revisions\/1231"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1230"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1229"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1229"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1229"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}