Security Frequently Asked Questions
Security Frequently Asked Questions
-
What Is Huawei Cloud infrastructure security?
Infrastructure security is a core component of Huawei Cloud's multi-dimensional, full-stack cloud security system. We have enhanced the security and compliance of our data centers, networks, and other infrastructure based on industry best practices, so that you can migrate services to the cloud, stay focused on your business, and leave the security to us.
Huawei Cloud is deployed in multiple regions and availability zones (AZs) around the world. You can check the services available at each site and on the Huawei Cloud home page. Our data centers are located in geographically secure locations. We take appropriate access control, monitoring, and service continuity assurance measures to improve the security and reliability of Huawei Cloud infrastructure. Visit the Data Center page for more details.
We divide and isolate security zones and network planes in compliance with ITU-T E.408 standards and industry best practices.
For more information about the security design and practices of Huawei Cloud infrastructure, see Huawei Cloud Security White Paper.
-
How does Huawei Cloud secure its platform and applications?
Combining more than 30 years of security experience with existing technologies, Huawei Cloud actively promotes the rapid iteration of today's DevOps processes while also integrating Huawei's security development lifecycle (SDL) into the process to develop platforms and applications, ensuring the security and reliability of the entire development process.
● Huawei Cloud servers have earned Five Star+ certification, the highest level available, from China's Trusted Cloud Services (TRUCS). To ensure platform security, Huawei Cloud minimizes the server OS and hardens services. We implement strict controls over who can access the platform and what resource they can access. We have a comprehensive system for auditing O&M activities on our platforms. All O&M accounts and their access to the platform are managed with CBH, and MFA is configured for each account. Huawei unified virtualization platform (UVP), the OS of our cloud computing platform, isolates resources by CPU, memory, and I/O. For details, see section "Platform Security" in Huawei Cloud Security White Paper.
● APIs are critical security borders for cloud services, so we use multiple measures to protect them. Huawei Cloud provides open APIs through Huawei-developed API Gateway. API Gateway can authenticate identities, protect transmission and borders, and limit API traffic, providing comprehensive protection for APIs.
-
How does Huawei Cloud secure my data on the cloud?
We consider data asset protection as the core of our security policies. Huawei Cloud complies with industry-leading standards on data security lifecycle management and adopts excellent technologies, practices, and processes for identity authentication, permissions management, access control, data isolation, transmission security, storage security, data deletion, and physical device destruction. You can find more information on these practices in the Huawei Cloud Data Security White Paper.
You own all the content data generated when you use services on Huawei Cloud, and have full control over the data. You are responsible for configuring security measures for specific data and ensuring the confidentiality, integrity, availability, and data access identity authentication and authorization. For example, if you use Identity and Access Management (IAM) and Data Encryption Workshop (DEW), you are responsible for keeping your accounts, passwords, and keys safe, and shall comply with industry best practices in configuring, updating, and resetting passwords and keys. You can check more data security products on the Security page.
Huawei Cloud will never access your content data without you express authorization. We comply with all applicable laws and regulations, regularly update services to meet internal and external compliance requirements, evaluate security status based on industry standards, and share our compliance practices to maintain transparency.
-
Does Huawei Cloud Transfer My Data to Other Regions or Countries?
Content data: You can decide where your content data is stored. Huawei Cloud will not transfer your content data to other regions without your explicit consent or unless required by legal obligations. If you plan to transfer content data across borders and need assistance from Huawei Cloud, contact and authorize Huawei Cloud support to transfer data.
Personal data: We provide products and services for you through our global resources and servers. Any personal data we collect may be stored in the countries or regions where we, our affiliates, service providers, and subcontractors are located. This means that your personal data may be transferred to other jurisdictions outside the country or region where the product or service you use is located, or may be accessed from these jurisdictions.
The laws protecting personal data vary by jurisdiction. Different jurisdictions may have laws protecting personal information to varying degrees or may not have personal data protection laws. Huawei Cloud ensures that your personal data is protected in compliance with applicable laws, regulations, and the Privacy Policy Statement. If you are a user in the Chinese mainland, your personal data will be stored on servers in the Chinese mainland.
-
What services can I use to improve cloud security?
With years of security experience and data security as the core, Huawei Cloud provides a series of multi-dimensional and in-depth security services that integrate hardware and software. For instance, there are services to manage the security posture of your system, such as Situation Awareness (SA) and Managed Threat Detection (MTD). You can also find Host Security Service (HSS) and Web Application Firewall, which can protect your cloud workloads and applications. There are also many data security services that can protect your data assets on the cloud, including Data Security Center (DSC), Data Encryption Workshop (DEW), and Data Lake Governance Center (DGC). You can check out more data security products under Huawei Cloud's [Security & Compliance] category.
You can easily build a comprehensive security system based on Huawei Cloud infrastructure and security services.
-
How does Huawei Cloud help me enhance security for operations and maintenance?
In the DevOps or DevSecOps process, operations and maintenance are as important as R&D. Huawei Cloud attaches great importance to O&M and has abundant practices in O&M security, vulnerability management, security event management, business continuity, and disaster recovery management. Take O&M access as an example. Huawei Cloud uses the VPN and CBH deployed in your data center to manage and audit your server O&M in a unified manner, and takes different security control measures for different operations. For more information, see "Operational Security" in Huawei Cloud Security White Paper.
You can also learn about secure and intelligent O&M from Huawei Cloud courses. For details about services recommended for O&M security, go to the O&M Security page.
-
What do I do to meet security and compliance requirements?
Security and compliance is a shared responsibility between Huawei Cloud and customers. That is, Huawei Cloud is responsible for the security compliance of cloud services, and you assume the responsibilities of the service security and compliance inside your organization.
Huawei Cloud keeps updating to meet the changing internal and external compliance requirements, ensures the legal and regulatory compliance of cloud services, strictly enforces security standard evaluations in a range of industries, and shares compliance practices with tenants to keep services transparent.
You need to check the applications and services that you deployed on Huawei Cloud but do not belong to Huawei Cloud against the applicable security laws and regulations.
For more information about Huawei Cloud certifications and regulation compliance, check our Compliance Center and Resources.
-
How do I get notified from Huawei Cloud of security events?
We will notify you of security events by email or SMS within the time require to comply with applicable laws and regulations. We will make every effort to minimize impacts on your services. In addition, we will post the latest security events and vulnerabilities on the security bulletin page on our website.
-
What security tests does Huawei Cloud perform to ensure the security of cloud services?
In the development and coding phase, we introduce static code scanning tools to check the code on a daily basis. All alarms generated during static code scans are cleared before the product or service can be release.
All cloud services have passed multiple rounds of security tests before being released. Those tests include but are not limited to API security testing, code and vulnerability scanning, and penetration testing.
After a cloud service is rolled out, our security O&M team will perform security tests such as periodic vulnerability scans and penetration testing to ensure product security and eliminate data breach risks.
We provide Rules for Customer Penetration Testing on Huawei Cloud. You are welcome to test the security of your cloud services on Huawei Cloud in accordance with these rules.
-
How can I report security vulnerabilities?
If you suspect that Huawei Cloud resources are being used inappropriately or encounter any security vulnerabilities in the Huawei Cloud website, products, or services, please email hwssecurity@huaweicloud.com. For a more effective response to your report, please provide supporting materials (such as vulnerability reproduction conditions, proof-of-concept code, the IP address of the resource being used inappropriately, and suspicious behavior logs) to help the security response team understand the issue thoroughly. We will reply to all feedback. You will receive a confirmation email within one working day of your initial feedback.
You can also send emails to psirt@huawei.com. We encourage global vulnerability coordination organizations, suppliers, security companies, organizations, security researchers, and Huawei employees to report vulnerabilities in our products or solutions.
Resources
Huawei Cloud Security White Paper
White Paper for Huawei Cloud Data Security