Security Best Practices
安全最佳實踐
A comprehensive security framework to protect your cloud environment — from identity to encryption to monitoring.
一套全面的安全框架,從身分、加密到監控,全面保護您的雲端環境。
Security in the cloud is a shared responsibility. Your provider secures the underlying infrastructure, but you remain accountable for the configuration, the data, and the access controls inside your own environment. This guide presents a practical, layered security framework aligned with the Hong Kong Personal Data (Privacy) Ordinance (PDPO) and international standards such as ISO 27001 and SOC 2 — principles we follow at Hong Kong Info Cloud and recommend to every customer.
雲端安全是一項共同責任。您的服務供應商保障底層基礎設施的安全,但您仍然要為自身環境中的配置、數據和存取控制負責。本指南提供一套切實可行、多層式的安全框架,對齊香港《個人資料(私隱)條例》(PDPO)以及 ISO 27001、SOC 2 等國際標準——這些正是香港資訊雲所遵循、並向每一位客戶推薦的原則。
1. Identity and Access Management
一、身分與存取管理
Identity is the new security perimeter. Enforce multi-factor authentication (MFA) on every administrative account, and apply the principle of least privilege so each user and service receives only the minimum permissions required. Review access rights regularly, promptly remove accounts for departing staff, and manage API keys as carefully as passwords — store them securely, rotate them periodically, and never embed them in code or logs.
身分猶如新一代的安全邊界。在每個管理帳戶上強制執行多重身分驗證(MFA),並遵循最小權限原則,讓每位用戶和服務只獲得所需的最低權限。定期檢視存取權限,即時移除離職員工的帳戶,並像管理密碼一樣謹慎管理 API 金鑰——安全存放、定期輪換,且絕不寫入程式碼或日誌。
🛡️ Zero Trust Model / 零信任模型
Never trust, always verify. Treat every request as if it originates from an untrusted network, even from inside your own environment. Authenticate, authorize, and encrypt every connection regardless of where it comes from.
從不信任,始終驗證。將每一個請求都視為來自不受信任的網絡,即使是來自您自身環境內部亦然。無論請求來自何處,都必須經過驗證身分、授權並加密連接。
2. Encryption Everywhere
二、處處加密
Encrypt data in transit and at rest. Use industry-standard algorithms such as AES-256 for stored data and TLS 1.2 or higher for data moving across networks. For maximum control, use Bring Your Own Key (BYOK): keep your own encryption keys in your own hardware security module (HSM) or key management service, so that even the platform operator cannot decrypt your data without your authorization. Manage key rotation and revocation carefully, and never share keys through unsecured channels.
加密傳輸中的數據和靜態存儲的數據。使用 AES-256 等業界標準演算法保護靜態數據,並以 TLS 1.2 或以上版本保護網絡傳輸中的數據。如需最大控制權,請使用自攜密鑰(BYOK):將您的加密密鑰存放在您自己的硬件安全模組(HSM)或金鑰管理服務中,如此即使平台營運商在未獲您授權時也無法解密您的數據。謹慎管理密鑰的輪換與撤銷,且切勿透過不安全的渠道分享密鑰。
3. Network Security
三、網絡安全
Segment your network into zones with different trust levels, and keep sensitive workloads isolated from public-facing systems. Use firewalls, virtual private clouds, and security groups to enforce inbound and outbound rules. Harden every internet-facing entry point, close unused ports, protect against DDoS attacks with scrubbing or managed mitigation services, and restrict management interfaces to trusted IP ranges or business VPNs.
將網絡劃分為不同信任等級的區域,並讓敏感工作負載與面向公眾的系統保持隔離。使用防火牆、虛擬私有雲和安全群組來執行進出站規則。強化每一個對外暴露的入口、關閉不使用的連接埠、以防禦或託管緩解服務抵禦 DDoS 攻擊,並將管理介面限制在受信任的 IP 範圍或企業 VPN 內。
4. Monitoring and Incident Response
四、監控與事故應變
You cannot protect what you cannot see. Centralize logs, enable real-time alerting on suspicious behavior, and define metrics and thresholds that trigger automated responses. Build an incident response plan before you need it: define roles, communication channels, evidence capture procedures, and escalation paths. Run regular tabletop exercises and post-incident reviews so each response gets better than the last.
看不見的,便無法保護。集中管理日誌、對可疑行為啟用即時告警,並定義觸發自動化回應的指標與臨界值。在需要之前就先制定事故應變計劃:界定角色、溝通渠道、證據保全程序和升級路徑。定期進行桌面演練與事後檢討,讓每次回應都比上一次更完善。
5. Backups and Disaster Recovery
五、備份與災難恢復
Automate backups for every critical dataset and application. Follow the 3-2-1 rule: keep at least three copies of your data, store them on at least two different media types, and keep at least one copy offsite. Test restores regularly, because an unverified backup is no backup at all. Define recovery time and recovery point objectives for each workload and verify that your cloud provider's architecture can meet them.
為每個關鍵數據集和應用程式自動化備份。遵循 3-2-1 原則:至少保留三份數據副本、存放於至少兩種不同媒介,並至少保留一份異地副本。定期測試還原,因為未經驗證的備份不算真正的備份。為每項工作負載界定恢復時間目標與恢復點目標,並確認您雲端供應商的架構能滿足這些要求。
6. PDPO and Compliance
六、PDPO 與合規
For organizations handling personal data in Hong Kong, PDPO compliance is non-negotiable. Collect only the personal data you need, for a lawful purpose; keep it accurate and up to date; and retain it only as long as necessary. Ensure data stays within Hong Kong data centers where required, and honor individuals' rights to access and correct their data. Document your security measures, keep records of compliance efforts, and seek qualified legal advice where the obligations apply to your business.
對於在香港處理個人數據的機構而言,遵守 PDPO 是硬性要求。只為合法目的收集所需的個人數據、保持其準確及最新,並只保留必要的時間。在需要時確保數據存放在香港數據中心內,並保障個人查閱及更正其數據的權利。記錄您的安全措施、保存合規工作的紀錄,並在適用時尋求專業法律意見。
Recommended Baseline Checklist
建議的基準檢查清單
- MFA enforced on all admin and privileged accounts 所有管理及特權帳戶均已啟用多重身分驗證
- Least-privilege IAM roles reviewed within the last quarter 最近一季內已檢視最小權限 IAM 角色
- AES-256 encryption at rest and TLS 1.2+ in transit 靜態數據 AES-256 加密,傳輸使用 TLS 1.2 或以上
- BYOK or customer-managed keys configured where required 在需要處已配置 BYOK 或客戶管理密鑰
- Logs centralized with alerting on critical events 日誌已集中管理,並對關鍵事件配置告警
- Automated backups with tested, documented restores 自動化備份,且已測試並記錄還原程序
- PDPO compliance measures documented and current PDPO 合規措施已記錄並保持最新