Cloudera Powers the Agentic AI Era with Cloudera Anywhere Cloud™

Read the press release

To help you manage your security obligations, we provide key resources on our Trust Portal, such as system configuration guides, the PCI DSS Responsibility Matrix, and SOC 2 CUECs. These documents are designed to clarify our respective roles and ensure your environment meets all necessary regulatory requirements.Security & Compliance

 

Diagram: Shared responsibility model for Cloudera Trust Center

Cloudera’s responsibility "Security of the  Cloudera on cloud Service": Cloudera is responsible for the Public Cloud control plane that customers use to launch, manage, and configure their workloads. The Cloudera on cloud Control Plane and its corresponding infrastructure, security, and compliance are fully managed by Cloudera, allowing customers to simply focus on launching the workloads of their choice into their public cloud accounts.

 

Customer’s responsibility "Security of the Workload Environment": A Workload Environment is a customer-owned public cloud account where Cloudera on cloud services run. When customers use Cloudera to run their data warehousing, advanced analytics, and machine learning workloads, new cloud resources are provisioned into their public cloud account. Customers are responsible for the security of the resources in their cloud account. To simplify complying with a customer's Information Security guidelines and best practices, Cloudera on cloud provides extensible features including our support for SAML providers, private subnets with restricted outbound internet access, as well as auditing for the Cloudera Control Plane.

Joint Cloudera and public cloud customer’s responsibilities
Certain activities require coordination between Cloudera and public cloud customers and are shared responsibilities. Examples include:

  • Patch Management - Cloudera continuously releases software updates with new functionality, security patches, and bug fixes, but it is the customer’s responsibility to apply those updates.
  • Virtual Machines (VMs) and Containers - Cloudera regularly offers updated VMs and containers and it is the customer’s responsibility to upgrade in order to take advantage of these updates.
  • TLS Certificates - Cloudera renews TLS certificates, but customers must use the Control Plane to initiate this process.
  • Audit Logs - Cloudera stores 90 days of system events in an encrypted database managed by Cloudera. It's the customer's responsibility to configure the automatic export of audit logs to their Amazon S3 or Microsoft ADLS Gen2 cloud object store.

Cloudera’s shared responsibility model for Cloudera on cloud provides customers with the flexibility, control, and ownership they need to manage their data and run their analytics workloads in the public cloud. For more details on our shared responsibility model, please reach out to your Cloudera account executive to get access to our Cloudera on cloud compliance package, or schedule a conversation with our security and compliance team.
 

To help you manage your security obligations, we provide key resources on our Trust Portal, such as system configuration guides, the PCI DSS Responsibility Matrix, and SOC 2 CUECs. These documents are designed to clarify our respective roles and ensure your environment meets all necessary regulatory requirements.

Diagram: Shared responsibility model for Cloudera Trust Center

Ready to Get Started?

Your form submission has failed.

This may have been caused by one of the following:

  • Your request timed out
  • A plugin/browser extension blocked the submission. If you have an ad blocking plugin please disable it and close this message to reload the page.