# SP-011 Cloud Computing Pattern

Status: published. Release 26.02. Modified 2026-02-06. Licence: CC BY-SA 4.0.

Scope: Security architecture for organisations consuming or providing cloud services, addressing the shared responsibility model, data sovereignty, identity federation, provider assurance, and the controls required across IaaS, PaaS, and SaaS deployment models.
Use when: Any organisation that consumes cloud services for production workloads, development and testing, data storage, or SaaS applications. This pattern applies whether the organisation uses a single cloud provider or multi-cloud strategy, and regardless of service model (IaaS, PaaS, SaaS).
Not when: Organisations that operate entirely on-premises with no cloud service consumption, including SaaS, may not need this pattern.

## Controls (54, NIST SP 800-53 ids)
- Critical (7): AC-02, AC-03, AU-06, CA-07, CM-02, IA-02, SA-09
- Important (26): AC-04, AC-13, AT-02, AT-03, CA-02, CA-03, CM-03, CM-04, CM-05, IA-03, IA-05, PS-06, PS-07, RA-03, SA-04, SA-10, SA-11, SC-04, SC-05, SC-07, SC-08, SC-09, SC-12, SI-02, SI-03, SI-04
- Standard (21): AC-01, AT-01, CA-01, CA-04, CA-06, CM-01, CP-01, IA-01, IR-01, PL-01, RA-04, SA-01, SA-02, SA-03, SA-05, SC-01, SC-02, SC-03, SC-06, SC-11, SC-18
- Withdrawn from SP 800-53 by NIST: AC-13 (now in AC-02, AU-06); CA-04 (now in CA-02); RA-04 (now in RA-03); SC-09 (now in SC-08)

## What each critical control mitigates (7)
- AC-02 Account Management: T-CC-002, T-CC-007
- AC-03 Access Enforcement: T-CC-002
- AU-06 Audit Record Review, Analysis, and Reporting: T-CC-003, T-CC-004, T-CC-007
- CA-07 Continuous Monitoring: T-CC-001
- CM-02 Baseline Configuration: T-CC-001, T-CC-005, T-CC-008
- IA-02 Identification and Authentication (Organizational Users): T-CC-002, T-CC-007
- SA-09 External System Services: T-CC-006, T-CC-008, T-CC-010

## Threats and the controls that mitigate them (10)
- T-CC-001 Cloud Resource Misconfiguration (Public Storage, Open Security Groups): CM-02, CM-04, CA-07, CM-03
- T-CC-002 Credential Compromise and Unauthorised Management Plane Access: IA-02, IA-05, AC-02, AC-03
- T-CC-003 Data Exfiltration from Cloud Storage or Databases: AC-04, SC-08, SC-09, AU-06
- T-CC-004 Insider Threat (Provider or Customer Personnel): PS-06, PS-07, AC-13, AU-06
- T-CC-005 Supply Chain Attack via Container Images or IaC Modules: SA-10, SA-11, SI-03, CM-02
- T-CC-006 Cross-Tenant Isolation Failure: SC-02, SC-03, SC-04, SA-09
- T-CC-007 Cryptojacking via Compromised Cloud Accounts: IA-02, AC-02, SI-04, AU-06
- T-CC-008 Data Sovereignty Violation from Cross-Region Replication: AC-04, SC-07, SA-09, CM-02
- T-CC-009 Denial of Service Against Cloud-Hosted Applications: SC-05, SC-06, CP-01, SC-07
- T-CC-010 Vendor Lock-In and Cloud Provider Service Disruption: SA-04, CP-01, SA-09, SA-02

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-011/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-011/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 28 KB: /api/v1/patterns/SP-011
- Page for people: /patterns/sp-011/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
- Related: SP-008 Public Web Server Pattern; SP-010 Identity Management Pattern; SP-013 Data Security Pattern; SP-018 Information Security Management System; SP-027 Secure LLM Usage

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
