Cloud compliance and governance form the critical oversight framework that ensures cloud infrastructure operates securely within regulatory boundaries while meeting business and legal obligations. As organizations migrate workloads to the cloud, they must navigate an increasingly complex landscape of data privacy laws, industry-specific regulations, security standards, and shared responsibility models that define who owns which security controls. Compliance is not a one-time checkbox β it's a continuous program of policy enforcement, automated monitoring, audit-ready evidence collection, and risk-based decision-making. Understanding the distinction between regulatory requirements (what the law demands), certification standards (what third-party audits validate), and governance frameworks (how you operationalize both) is essential for building resilient, audit-ready cloud environments that scale without sacrificing trust or exposing the organization to regulatory penalties.
What This Cheat Sheet Covers
This topic spans 10 focused tables and 103 indexed concepts, 104 flashcards. Below is a complete table-by-table outline of this topic, spanning foundational concepts through advanced details.
A jump-to index of every table row in this cheat sheet.
An interactive map of every table and concept in this topic.
Table 1: Major Compliance Standards and Regulations
The regulatory landscape for cloud environments has expanded dramatically β spanning U.S. federal and state privacy laws, EU digital regulations, financial-sector resilience mandates, and international AI governance standards. Each framework assigns specific obligations; knowing which applies to your environment and data is the first step of any compliance program.
| Standard | Example | Description | |
|---|---|---|---|
Data processing consent, right to erasure, data portability, breach notification within 72 hours | β’ EU regulation enforcing data privacy and sovereignty for personal data of EU citizens β’ applies globally to any organization processing EU data β’ penalties up to 4% of annual global revenue or β¬20M β’ requires data protection impact assessments (DPIAs) for high-risk processing. | ||
MFA everywhere, encryption at rest/in transit, 72-hour data restoration, annual penetration testing | β’ U.S. healthcare data protection law requiring technical, physical, and administrative safeguards for electronic protected health information (ePHI) β’ 2026 Security Rule updates mandate MFA, annual pentests, and biannual vulnerability scanning β’ Business Associate Agreements (BAAs) required for cloud vendors. | ||
PCI DSS 4.0.1: Tokenization, network segmentation, quarterly ASV scans, targeted risk analysis | β’ Mandates 12 foundational security requirements for any organization that stores, processes, or transmits payment card data β’ non-compliance fines range $5,000β$100,000/month β’ v4.0.1 adds targeted risk analysis, enhanced multi-factor requirements, and expanded e-commerce controls. | ||
6β12 month observation of controls' operational effectiveness against Trust Services Criteria | β’ Evaluates both design and operating effectiveness of controls over a minimum 6-month period β’ covers security, availability, confidentiality, processing integrity, and privacy β’ provides deeper assurance than Type I and is preferred by enterprise customers β’ requires continuous evidence collection. | ||
Risk-based ISMS with 93 controls across 4 themes (2022 edition) | β’ International standard for information security management systems (ISMS) β’ ISO 27001:2022 restructured controls into Organizational, People, Physical, and Technological themes β’ certification involves third-party audit and surveillance audits every 1β3 years. | ||
Low, Moderate, High authorization levels based on data sensitivity | β’ U.S. government cloud security assessment program requiring CSPs to achieve standardized security authorization before handling federal data β’ built on NIST 800-53 controls β’ reduces duplicative audits across agencies β’ FedRAMP 20x modernization (2025) streamlines the authorization process. | ||
Govern, Identify, Protect, Detect, Respond, Recover | β’ Voluntary U.S. framework organizing cybersecurity activities into six functions β’ CSF 2.0 (2024) adds "Govern" function and emphasizes supply chain risk and organizational accountability β’ widely adopted for building risk-based security programs across sectors. | ||
EU bank must maintain tested failover for trading systems; document cloud provider contingency plans | β’ EU regulation effective January 17, 2025 requiring financial entities and their critical ICT providers (including cloud CSPs) to maintain operational resilience β’ five pillars: ICT risk management, operational continuity, third-party oversight, incident reporting, and information sharing β’ extraterritorial: applies to non-EU companies providing ICT services to EU financial firms. | ||
EU cloud provider must report major incidents within 24 hours (early warning) and 72 hours (full notification) | β’ EU cybersecurity law effective October 17, 2024, expanding to 18+ sectors including cloud providers, SaaS, managed services, and healthcare β’ Essential entities: fines up to β¬10M or 2% of global revenue; Important entities: β¬7M or 1.4% β’ executives personally accountable for cybersecurity governance failures. | ||
Opt-out from data sale, deletion requests, sensitive PI protections, risk assessments | β’ California privacy law granting consumer data rights similar to GDPR β’ CPRA amendments require 30-day breach notification, privacy risk assessments, and cybersecurity audits for high-risk businesses β’ California Privacy Protection Agency (CPPA) actively enforcing. | ||
Level 1 (17 practices), Level 2 (110 NIST 800-171 practices), Level 3 (advanced) | β’ U.S. Department of Defense framework for DIB (Defense Industrial Base) cybersecurity β’ phased mandatory certification for DoD contractors began November 2025 β’ enforces NIST 800-171 and 800-172 controls β’ unannounced assessments allowed for Level 3. | ||
Point-in-time audit of access controls and encryption design | β’ Assesses whether security controls are properly designed at a single point in time against TSC β’ does not test operational effectiveness over time β’ useful as a first milestone before pursuing Type II. | ||
Level 1 (self-assessment), Level 2 (third-party audit), Level 3 (continuous monitoring) | β’ Three-tier cloud security certification program using the Cloud Controls Matrix (CCM) β’ Level 2 combines ISO 27001 with CSA-specific controls β’ publicly listed in CSA STAR Registry for customer due diligence. | ||
Hardening guides for AWS, Azure, GCP, Kubernetes, Docker, OS | β’ Prescriptive configuration standards for securing IT systems and cloud platforms β’ two implementation levels: L1 (basic, low risk), L2 (advanced, higher security) β’ continuously updated by consensus; CSPM tools map findings to CIS controls automatically. | ||
AIMS documenting training data provenance, bias testing, human oversight procedures | β’ First international standard for AI management systems (December 2023) β’ provides requirements for organizations that develop, provide, or use AI systems β’ seven pillars: leadership, objectives, AI risk management, data governance, transparency, monitoring, continual improvement β’ aligns with EU AI Act high-risk obligations due August 2026. | ||
Publicly traded company files Form 8-K within 4 business days of material breach | β’ U.S. SEC rules (effective December 2023) requiring public companies to disclose material cybersecurity incidents within four business days β’ annual Form 10-K disclosure of cybersecurity risk management, strategy, governance, and board oversight β’ applies to domestic registrants and foreign private issuers. |