Cloud Workload
A cloud workload is an application, service, or function that runs in a cloud environment.
A cloud workload is any application or computing power running in a cloud environment. This includes virtual machines, containers, serverless functions, and managed databases.
How it works
Workloads operate on platforms like Azure, AWS, or Google Cloud. The provider takes on more or less responsibility depending on the model. With virtual machines, the customer is responsible for the operating system and patches. For serverless functions, the provider handles the infrastructure. The customer manages the code and permissions. This shared responsibility model is central to security.
For example, a company runs its webshop on virtual machines in the cloud. It assumes the provider will handle the patches. However, this task is the company's own responsibility. A web server vulnerability remains open for months and is eventually exploited. Monitoring detects the unusual process on the VM.
What to look out for
- Clarify your responsibilities for each service.
- Keep an inventory of all workloads, including those in test and development environments.
- Grant workloads only the permissions they need.
- Deploy protection on the workloads, such as EDR or a CWPP.
- Integrate cloud logs and workload signals into your SOC.
Switzerland and regulation
If personal data is processed in the cloud, the revFADP (revised Federal Act on Data Protection) requirements apply. This also covers cross-border processing. For banks and insurers, the use of cloud services can be a material outsourcing in the sense of FINMA's requirements. Several large providers operate data centres in Switzerland.
Why it matters
Workloads in the cloud are often directly accessible from the internet. They change quickly and are sometimes created automatically. Without an inventory and monitoring, this creates unnoticed security gaps.
Typical mistakes
Forgotten test workloads are a common issue. They often continue to run unpatched. Another mistake is giving workloads extensive roles. Attackers can use these to access other resources.
How we implement it
We monitor your cloud workloads using EDR, CWPP, and cloud logs. Containment is performed within the mandate that you define.