Cloud security frameworks: a comprehensive analysis of security controls, governance models, and implementation challenges in modern cloud infrastructures
Abstract Cloud computing has become the preferred technological foundation for modern businesses and governments, offering users unparalleled flexibility, scalability, and cost savings. The complexity of securing distributed cloud environments, which are characterized by shared responsibility, multitenancy models, and expanded attack surfaces, has increased exponentially. This study evaluates and categorizes existing cloud security frameworks into two primary classifications: Industry-Wide Frameworks (vendor-neutral), comprising General Cybersecurity Frameworks (NIST CSF v2.0, ISO/IEC 27017:2015, ISO/IEC 27018:2019, ENISA Cloud Security Framework (Information Assurance Framework, IAF), CSA Cloud Controls Matrix v4.0, CSA STAR Program, CIS Benchmarks and Controls), Government-Mandated Standards (FedRAMP, FISMA, DoD SRG, CMMC 2.0), analyzed alongside FAIR, a complementary vendor-neutral risk-quantification method, Industry-Specific Compliance Models (HIPAA, PCI DSS v4.0, SOC 2, HITRUST CSF v11), Privacy Regulations (GDPR, CCPA), Threat Intelligence Frameworks (MITRE ATT&CK for Cloud, OWASP Cloud Security Top 10), and IT Governance Frameworks (COBIT 2019, ITIL 4). This paper focuses on five major Cloud Service Provider CSP (Platform-Specific) frameworks): the AWS Well-Architected Framework, Microsoft Azure Security Benchmark, Google Cloud Security Framework, Huawei Cloud Security Framework, and IBM Cloud Security Framework. By comparatively analyzing these frameworks, addressing their implementation challenges, and proposing practical solutions, this study elucidates how organizations can operationalize the shared responsibility model, provides a deeper understanding of the different frameworks, and helps inform decisions regarding the choice and deployment of appropriate security measures for cloud-based systems. This study concludes with the recommendation of a multi-framework, defense-in-depth approach that integrates strategic governance, regulatory compliance, and CSP-native tools to ensure the confidentiality, integrity, and availability of the hosted assets.
Authors
- Yunus Özen (ORCID: https://orcid.org/0000-0003-3225-8797)
- Muhammad Mustapha Abubakar
Institutions
- Yalova University (TR)
Publication Details
- Journal
- Journal of Cloud Computing Advances Systems and Applications
- Published
- 2026-09-30
- DOI
- https://doi.org/10.1186/s13677-026-00989-0
- Primary Topic
- Cloud Data Security Solutions
- Type
- article
- Field-Weighted Citation Impact
- 0.00