NIST Cloud Computing Security Reference Architecture

Abstract

The purpose of this document is to define a NIST Cloud Computing Security Reference Architecture (NCC-SRA)--a framework that: i) identifies a core set of Security Components that can be implemented in a Cloud Ecosystem to secure the environment, the operations, and the data migrated to the cloud; ii) provides, for each Cloud Actor, the core set of Security Components that fall under their responsibilities depending on the deployment and service models; iii) defines a security-centric formal architectural model that adds a security layer to the current NIST SP 500-292, "NIST Cloud Computing Reference Architecture"; and iv) provides several approaches for analyzing the collected and aggregated data.

General Information

Publication date: 01 May 2013

Working groups: https://collaborate.nist.gov/twiki-cloud-computing/bin/view/CloudComputing/CloudSecurity

ICT rolling plan topic: Cloud computing

SDO: NIST

Latest publishied version: https://csrc.nist.gov/publications/detail/sp/500-299/draft