Skip to content
Cloudreason

The NCSC Cloud Security Principles, applied to a real estate

The framework UK public sector buyers will actually measure you against.

NCSC Cloud Security Principles · AWS + Azure + Google Cloud

Published

If you sell to the UK public sector, or you are a public body assessing your own estate, the National Cyber Security Centre’s Cloud Security Principles are the yardstick you will be measured against. They appear in procurement questionnaires, security assurance cases and G-Cloud submissions, and unlike a certification such as ISO 27001 or Cyber Essentials Plus, they have no badge you can buy: you evidence them, or you cannot answer the question.

The 14 principles

The NCSC frames cloud security as fourteen principles. Briefly:

  1. Data in transit protection. Data moving over networks is protected against tampering and eavesdropping.
  2. Asset protection and resilience. Data and the assets processing it are protected against physical loss, damage and seizure, including knowing where data is stored and processed.
  3. Separation between customers. One customer of a shared service cannot access or affect another.
  4. Governance framework. A security governance framework directs how the service is managed.
  5. Operational security. The service is operated to impede, detect and prevent attacks: vulnerability management, protective monitoring, configuration and change management, incident management.
  6. Personnel security. Staff with access are screened and trained.
  7. Secure development. The service is designed and developed to identify and mitigate threats.
  8. Supply chain security. The provider’s own suppliers meet the same standards.
  9. Secure user management. The provider gives you the tools to manage your use of the service securely.
  10. Identity and authentication. Access is limited to authenticated, authorised individuals.
  11. External interface protection. External and less-trusted interfaces are identified and defended.
  12. Secure service administration. The systems used to administer the service are highly privileged and protected accordingly.
  13. Audit information and alerting for users. You can collect the records needed to detect and investigate misuse.
  14. Secure use of the service. You configure and operate the service so that your data stays protected.

Why principle 14 is where it goes wrong

For the first thirteen principles, the major clouds do most of the heavy lifting, and AWS, Microsoft and Google all publish detailed statements of how their platforms meet them. A procurement reviewer will accept those statements. What they will then probe is principle 14, because it is the one nobody can answer for you.

Secure use of the service means your identity model, your network exposure, your encryption configuration, your logging and your operational discipline. It is the principle under which an estate with a world-class provider and a wide-open storage bucket fails. In our experience it is also the principle that decays fastest: estates are usually configured well at go-live and then drift as teams change, workloads move and exceptions accumulate.

The NCSC’s cloud security guidance is deliberately outcome-based rather than a checklist, which is both its strength and the reason organisations struggle to evidence it. “We have protective monitoring” is an assertion. Ninety days of triaged alerts, with owners and resolution times, is evidence.

Turning principles into an assurance case

The practical approach we take is to translate each principle into concrete, checkable statements about the estate: which controls implement it, where the configuration lives, and what record proves it was working last month, not just on the day someone wrote the document. On AWS that draws on services such as CloudTrail, Config, GuardDuty and IAM; on Azure, Microsoft Defender for Cloud, Entra ID and Azure Policy; on Google Cloud, Security Command Center and organisation policies. The tooling differs; the principles do not.

Done once, that produces a strong questionnaire answer. Done continuously, it produces something better: an estate that actually holds the posture it claims, with the evidence accumulating as a by-product. That continuous version is what Cloudreason’s cloud compliance service provides, with monitoring against the principles, remediation carried out by our engineers, and an assurance case that stays current between procurements. If a bid or an assessment date is approaching, get in touch before the questionnaire arrives.

← Cloud Compliance at Cloudreason

Frequently asked questions

Are the NCSC Cloud Security Principles mandatory?

They are not law, but UK public sector buyers use them as the standard framework for assessing cloud services, and they appear throughout procurement questionnaires and security assurance cases. If you sell to the public sector, or are part of it, you will be measured against them.

How many NCSC Cloud Security Principles are there?

Fourteen, covering everything from data in transit protection and separation between customers through to audit information and secure use of the service.

Which NCSC principle do organisations most often fail?

Principle 14, secure use of the service. The major cloud providers publish statements covering the first thirteen, but how you configure and operate the platform is yours alone, and it is where estates drift after go-live.

Got an audit date?

Tell us the date and the framework, and we'll tell you honestly what stands between your estate and passing.