ChaptersEventsBlog
We're exploring how organizations adapt IAM to AI. Take the AI Identity and Risk Readiness Survey by September 5 →

Download Publication

Understanding Cloud Attack Vectors
Understanding Cloud Attack Vectors

Understanding Cloud Attack Vectors

Release Date: 06/06/2023

This publication was produced through the efforts of chapters and volunteers but the content development falls outside of the CSA Research Lifecycle. For any questions and feedback, contact research@cloudsecurityalliance.org.

The goal of the document is to map the various attack vectors that are actually being used during cloud-based attacks in IaaS/PaaS and to map the vectors and their mitigating controls to various resources. The motivation for this document came after we analyzed much research around cloud security and realized that they are listing a combination of risks, threats, attack vectors, vulnerabilities, and concerns. And while there are many risks and threats to IaaS/PaaS platforms and applications, most of the risks are associated with a very specific number of attack vectors.
Download this Resource

Prefer to access this resource without an account?
Download the publication. Download the presentation.

Bookmark
Share
View translations
Related resources
Zero Trust Guidance for Small and Medium Size Businesses (SMBs) - Korean Translation
Zero Trust Guidance for Small and Medium Size B...
Zero Trust Automation & Orchestration and Visibility & Analytics Overview
Zero Trust Automation & Orchestration and Visib...
Zero Trust Guidance for IoT
Zero Trust Guidance for IoT
"Set It and Forget It” Access Control is No Longer Enough
"Set It and Forget It” Access Control is No Longer Enough
Published: 08/20/2025
Why You Should Say Goodbye to Manual Identity Processes
Why You Should Say Goodbye to Manual Identity Processes
Published: 08/13/2025
Agentic AI and Zero Trust
Agentic AI and Zero Trust
Published: 08/07/2025
The Ethical and Societal Considerations of an AI Impact Analysis
The Ethical and Societal Considerations of an AI Impact Analysis
Published: 08/05/2025

Acknowledgements

Moshe Ferber
Moshe Ferber
CCSK, CCSP, CCAK official instructor, Chairman at Cloud Security Alliance, Israel

Moshe Ferber

CCSK, CCSP, CCAK official instructor, Chairman at Cloud Security Alliance, Israel

Moshe Ferber is a recognized industry expert and popular public speaker, with over 20 years’ experience at various positions ranging from the largest enterprises to innovative startups. Currently Ferber focuses on cloud security as certified instructor for CCSK, CCSP and CCAK certification and participate in various initiative promoting responsible cloud adoption.

Read more

Michael Roza
Michael Roza
Risk, Audit, Control and Compliance Professional at EVC

Michael Roza

Risk, Audit, Control and Compliance Professional at EVC

Michael Roza is a seasoned risk, audit, control and compliance, and cybersecurity professional with over 20 years of experience across multinational enterprises and startups. As a Cloud Security Alliance (CSA) Research member for over 10 years, he has led and contributed to more than 140 CSA projects spanning Zero Trust, AI, IoT, Top Threats, DecSecOps, Cloud Key Management, Cloud Control Matrix, and many others.

He has co-chaired...

Read more

Eitan Satmary Headshot Missing
Eitan Satmary

Eitan Satmary

Daniel Begimher Headshot Missing
Daniel Begimher
Sr. Security Engineer, AWS

Daniel Begimher

Sr. Security Engineer, AWS

Gidi Farkash
Gidi Farkash
VP Operations, Security & IT, Pipl

Gidi Farkash

VP Operations, Security & IT, Pipl

Gidi Farkash is a seasoned cybersecurity professional with over 25 years of experience in managerial and hands-on roles across various Information and Cyber Security domains. Currently serving as the Head of Security at Pipl, Gidi also holds the esteemed position of President of the (ISC)² Israel Chapter, where he actively contributes to developing and promoting cybersecurity best practices.Throughout his career, Gidi has demonstrated exp...

Read more

Are you a research volunteer? Request to have your profile displayed on the website here.

Related Certificates & Training