Cloud security operates on a shared responsibility model — the provider secures the infrastructure, and the customer secures their configuration, data, and access controls.
Identity and Access Management
AWS IAM is the most granular and the most complex. Policies are JSON documents attached to users, groups, or roles. Every API call is authorized against IAM. AWS Organizations enables policy enforcement across multiple accounts.
Azure Active Directory is the identity backbone — unified across Microsoft 365, Azure services, and third-party applications via SAML/OIDC. Particularly strong for enterprises already running on Windows and Microsoft infrastructure.
Google Cloud IAM uses a simpler resource hierarchy: organization → folder → project → resource. Permissions are inherited down the hierarchy. Workload Identity Federation allows non-GCP workloads to authenticate without service account keys.
Encryption
All major providers encrypt data at rest by default using AES-256 and in transit using TLS 1.2+.
Key management options:
- Provider-managed keys — simplest, sufficient for most workloads
- Customer-managed keys (CMK) — you control rotation and deletion; provider handles HSMs
- Customer-provided keys (BYOK) — you supply the key material; maximum control
Services: AWS KMS, Azure Key Vault, GCP Cloud KMS. Hardware Security Modules (HSMs) are available on all three: AWS CloudHSM, Azure Dedicated HSM, GCP Cloud HSM.
Compliance Certifications
| Standard | AWS | Azure | GCP |
|---|---|---|---|
| SOC 2 Type II | ✅ | ✅ | ✅ |
| ISO 27001 | ✅ | ✅ | ✅ |
| PCI DSS | ✅ | ✅ | ✅ |
| HIPAA | ✅ | ✅ | ✅ |
| FedRAMP High | ✅ | ✅ | ✅ |
| GDPR | ✅ | ✅ | ✅ |
Azure has the broadest government and industry compliance portfolio, which is a key reason it dominates in regulated enterprise sectors.
Threat Detection
- AWS GuardDuty — ML-based threat detection across CloudTrail, VPC Flow Logs, DNS logs
- Azure Defender / Microsoft Sentinel — SIEM and XDR integrated with Azure
- GCP Security Command Center — asset inventory, vulnerability scanning, threat detection
Key Principles
Regardless of provider: enable MFA on all accounts, use least-privilege IAM policies, enable logging (CloudTrail, Azure Monitor, GCP Audit Logs), rotate credentials, and scan for misconfigurations regularly.