CyberzSOC

Publication detail
← Back to advisories & guidance

CSI: Mitigate Risks from Managed Service Providers in Cloud Environments ↗ source

March 7, 2024 NSA Guidance
Co-sealed by: ASD/ACSC, CISA, NSA

Summary

The growth of the public cloud has encouraged the development of numerous MSPs that primarily provide these services within the cloud rather than in customer on-premises networks. Both cloud resellers and other IT vendors offer such third-party services. These MSPs offer a diverse set of Because of their focus and scale, MSPs have the potential to provide services that are better tailored (e.g., higher availability or scalability, improved security, cheaper) than an organization could deliver for itself. Using the capabilities provided by MSPs, organizations can accomplish their business objectives, including their responsibilities related to increased remote work and other changes to operating conditions. However, using an MSP can also increase an enterprise’s attack surface and introduce new factors when managing risk.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.