Legal & compliance centre

HLD Group

Cloud security policy

Cloud governance, hardening, and identity in IaaS/PaaS.

Last updated: 24 July 2026

Version 1.0 · Review cycle: 365 days · View all frameworks

1. Purpose

This policy defines how HLD Group secures its use of cloud services, including the shared responsibility between HLD Group and cloud providers and the controls we apply to cloud infrastructure, platforms, and applications.

2. Scope

This policy applies to all cloud services used by HLD Group, whether infrastructure, platform, or software as a service, and to the personnel who design, operate, and govern them.

3. Shared responsibility

Cloud security is a shared responsibility. The provider secures the underlying cloud; HLD Group secures what we deploy and configure within it — identity, data, configuration, and application security. This division is understood and documented for each service so that no control is assumed to be someone else’s job.

4. Cloud configuration and hardening

  • Secure baselines and benchmarks (such as CIS) are applied to cloud resources
  • Infrastructure is defined as code, reviewed, and version-controlled
  • Cloud security posture management detects and remediates misconfiguration
  • Public exposure of storage, databases, and services is prevented by default

5. Identity and access in the cloud

  • Cloud access follows the Access Control Policy, with MFA and least privilege
  • Human access is federated through the central identity provider; standing privileged access is minimised
  • Workload identity and short-lived credentials are used instead of long-lived keys
  • Cloud administrative actions are logged and monitored

6. Data protection in the cloud

  • Data is encrypted at rest and in transit under the Encryption Policy
  • Data residency and sovereignty requirements are honoured for regulated and customer data
  • Backups and resilience follow the Backup and Recovery and Business Continuity Policies

7. Monitoring and provider assurance

  • Cloud logs feed the logging and monitoring capability
  • Provider certifications and shared-responsibility documentation are assessed under the Vendor Management Policy
  • Provider security bulletins and configuration changes are tracked

8. Framework alignment

  • ISO/IEC 27017 (cloud services security) and ISO/IEC 27018 (PII in public clouds)
  • Cloud Security Alliance Cloud Controls Matrix (CCM)
  • ISO/IEC 27001:2022 Annex A controls 5.23 (information security for use of cloud services) and 8.9 (configuration management)
  • SOC 2 Trust Services Criteria CC6.x and CC7.x

9. Roles, exceptions, and review

Cloud platform teams own cloud security under the CISO. Exceptions require documented CISO approval with compensating controls and an expiry date. This policy is reviewed at least annually.

Related frameworks

For contractual attestations or audit packs, contact [email protected].