Cloud computing is one of the most disruptive new technologies since the Internet. One of the fastest-growing sectors of cloud computing is infrastructure-as-a-service (IaaS). Cloud-based IaaS offers tremendous scalability, flexibility and speed in deploying information processing compute resources. Security and compliance remain major challenges to adoption of public cloud infrastructure hosting. Technical differences in public cloud environments render many established security models and controls inoperable. In this sesson, Carson Sweet will discuss why security and compliance is different in the cloud, outline a model for securing cloud-based hosting environments and explain best practices for implementing this model.