Cloud security frameworks: a comprehensive analysis of security controls, governance models, and implementation challenges in modern cloud infrastructures

Abstract Cloud computing has become the preferred technological foundation for modern businesses and governments, offering users unparalleled flexibility, scalability, and cost savings. The complexity of securing distributed cloud environments, which are characterized by shared responsibility, multitenancy models, and expanded attack surfaces, has increased exponentially. This study evaluates and categorizes existing cloud security frameworks into two primary classifications: Industry-Wide Frameworks (vendor-neutral), comprising General Cybersecurity Frameworks (NIST CSF v2.0, ISO/IEC 27017:2015, ISO/IEC 27018:2019, ENISA Cloud Security Framework (Information Assurance Framework, IAF), CSA Cloud Controls Matrix v4.0, CSA STAR Program, CIS Benchmarks and Controls), Government-Mandated Standards (FedRAMP, FISMA, DoD SRG, CMMC 2.0), analyzed alongside FAIR, a complementary vendor-neutral risk-quantification method, Industry-Specific Compliance Models (HIPAA, PCI DSS v4.0, SOC 2, HITRUST CSF v11), Privacy Regulations (GDPR, CCPA), Threat Intelligence Frameworks (MITRE ATT&CK for Cloud, OWASP Cloud Security Top 10), and IT Governance Frameworks (COBIT 2019, ITIL 4). This paper focuses on five major Cloud Service Provider CSP (Platform-Specific) frameworks): the AWS Well-Architected Framework, Microsoft Azure Security Benchmark, Google Cloud Security Framework, Huawei Cloud Security Framework, and IBM Cloud Security Framework. By comparatively analyzing these frameworks, addressing their implementation challenges, and proposing practical solutions, this study elucidates how organizations can operationalize the shared responsibility model, provides a deeper understanding of the different frameworks, and helps inform decisions regarding the choice and deployment of appropriate security measures for cloud-based systems. This study concludes with the recommendation of a multi-framework, defense-in-depth approach that integrates strategic governance, regulatory compliance, and CSP-native tools to ensure the confidentiality, integrity, and availability of the hosted assets.

Authors

Institutions

Publication Details

Journal
Journal of Cloud Computing Advances Systems and Applications
Published
2026-09-30
DOI
https://doi.org/10.1186/s13677-026-00989-0
Primary Topic
Cloud Data Security Solutions
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Cloud security frameworks: a comprehensive analysis of security controls, governance models, and implementation challenges in modern cloud infrastructures

Yunus Özen, Muhammad Mustapha Abubakar
Journal of Cloud Computing Advances Systems and Applications
Cloud Data Security Solutions
article

Cloud security frameworks: a comprehensive analysis of security controls, governance models, and implementation challenges in modern cloud infrastructures

Yunus Özen, Muhammad Mustapha Abubakar
article en

Abstract

Abstract Cloud computing has become the preferred technological foundation for modern businesses and governments, offering users unparalleled flexibility, scalability, and cost savings. The complexity of securing distributed cloud environments, which are characterized by shared responsibility, multitenancy models, and expanded attack surfaces, has increased exponentially. This study evaluates and categorizes existing cloud security frameworks into two primary classifications: Industry-Wide Frameworks (vendor-neutral), comprising General Cybersecurity Frameworks (NIST CSF v2.0, ISO/IEC 27017:2015, ISO/IEC 27018:2019, ENISA Cloud Security Framework (Information Assurance Framework, IAF), CSA Cloud Controls Matrix v4.0, CSA STAR Program, CIS Benchmarks and Controls), Government-Mandated Standards (FedRAMP, FISMA, DoD SRG, CMMC 2.0), analyzed alongside FAIR, a complementary vendor-neutral risk-quantification method, Industry-Specific Compliance Models (HIPAA, PCI DSS v4.0, SOC 2, HITRUST CSF v11), Privacy Regulations (GDPR, CCPA), Threat Intelligence Frameworks (MITRE ATT&CK for Cloud, OWASP Cloud Security Top 10), and IT Governance Frameworks (COBIT 2019, ITIL 4). This paper focuses on five major Cloud Service Provider CSP (Platform-Specific) frameworks): the AWS Well-Architected Framework, Microsoft Azure Security Benchmark, Google Cloud Security Framework, Huawei Cloud Security Framework, and IBM Cloud Security Framework. By comparatively analyzing these frameworks, addressing their implementation challenges, and proposing practical solutions, this study elucidates how organizations can operationalize the shared responsibility model, provides a deeper understanding of the different frameworks, and helps inform decisions regarding the choice and deployment of appropriate security measures for cloud-based systems. This study concludes with the recommendation of a multi-framework, defense-in-depth approach that integrates strategic governance, regulatory compliance, and CSP-native tools to ensure the confidentiality, integrity, and availability of the hosted assets.

Journal of Cloud Computing Advances Systems and Applications
Yalova University (TR)
Industry, innovation and infrastructure
Openalex Percentile: Top 4%
Cloud Data Security Solutions
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.