Capital newspaper releases guide on safe cloud storage use

Capital Ethiopia has released a comprehensive guide on using cloud storage safely and effectively. The article outlines key security practices for teams to protect data without hindering productivity.

Published on January 28, 2026, by Capital Newspaper, this guide details best practices for secure and efficient cloud storage usage. It begins by stressing the shared responsibility model, where providers handle infrastructure security while users manage identities, data, and settings. Teams are advised to document ownership and review assignments after integrations to avoid blind spots.

The article recommends enabling encryption for data at rest and in transit, using TLS for connections, and deciding on key management—either provider-managed for ease or self-controlled for added security. Keys should be rotated regularly, and approved ciphers maintained to keep systems current.

Monitoring and response form another core section, urging the activation of logs for access, changes, and audits. Tools for cloud data security can consolidate signals for quicker threat detection. Rules for risks like public buckets or mass downloads are suggested, alongside incident drills to test recovery from scenarios such as lost devices.

Strong identity controls emphasize least privilege, short-lived tokens, and Zero Trust principles, with references to Microsoft's guidance on the CISA Zero Trust Maturity Model. Monthly reviews of admin roles and enhanced monitoring for high-privilege accounts are highlighted.

Data classification and minimization advise labeling by sensitivity, removing duplicates, and using separate storage for varying risk levels. Automated lifecycle rules ensure timely archiving or deletion.

For resilience, backups in isolated accounts and regions, with immutable storage and regular restore tests, are essential. Standardized runbooks and checklists verify recovery capabilities.

Configurations should be validated against frameworks like the NIST Cybersecurity Framework 2.0, updated in February 2024, as noted in an AWS whitepaper. This alignment aids in demonstrating progress.

Finally, it covers regulatory duties, mapping controls to applicable laws and contracts. The U.S. Binding Operational Directive exemplifies mandatory safeguards for federal systems. The guide encourages starting with simple improvements and quarterly reviews to build secure habits.

Liittyvät artikkelit

U.S. Treasury report illustration showing holographic tech pillars for crypto compliance: AI monitoring, digital ID, blockchain analytics, and data APIs, with privacy mixer endorsement.
AI:n luoma kuva

U.S. Treasury report proposes AI, digital ID pillars for crypto compliance; endorses lawful mixer privacy

Raportoinut AI AI:n luoma kuva

The U.S. Treasury Department submitted a report to Congress on March 9, 2026—commissioned under the GENIUS Act—outlining four technological pillars to enhance transparency in cryptocurrency transactions: artificial intelligence for monitoring, digital identity for onboarding, blockchain analytics for tracing, and interoperable data-sharing APIs. It describes digital assets as key to U.S. innovation leadership while acknowledging lawful users' need for privacy tools like mixers on public blockchains, amid risks from illicit exploitation.

A new Google research report indicates that the cloud security threat landscape is rapidly evolving. Hackers are increasingly targeting third parties and software vulnerabilities to breach systems. The report also notes a decline in cloud misconfigurations.

Raportoinut AI

Cybersecurity has shifted from a purely technical issue to a core element in organizations' strategic decisions. In a digital landscape with systemic risks and AI advancements, it safeguards institutional continuity and social trust. Author Luis Wertman Zaslav emphasizes the need for cyberresilience and collaboration.

South Africa's National Treasury has gazetted the Draft Capital Flow Management Regulations 2026, modernising outdated exchange controls to include cryptocurrencies. The proposals aim to combat money laundering and illicit financial flows but have sparked debate over vague thresholds and restrictions on peer-to-peer transactions. Industry voices criticise the lack of defined limits and potential overreach.

Raportoinut AI

The National Treasury has published the draft Virtual Asset Service Providers (VASP) Regulations 2026 to oversee Kenya's crypto businesses. The measures seek to protect consumers and combat financial crimes such as money laundering. Public consultations are underway through April.

Tämä verkkosivusto käyttää evästeitä

Käytämme evästeitä analyysiä varten parantaaksemme sivustoamme. Lue tietosuojakäytäntömme tietosuojakäytäntö lisätietoja varten.
Hylkää