In addition to NIST’s efforts , the industry itself can affect an enterprise approach to cloud security. If it applies due diligence and develops a policy of selfregulation to ensure that security is effectively implemented throughout all clouds, then this policy can serve to facilitate lawmaking as well. By combining industry best practices with the oversight NIST and other entities are developing , we can effectively address cloud computing’s future security needs . To achieve a recognized and actionable security policy , SCAP recommends that organizations demonstrate compliance with security requirements in mandates such as the US Federal Information Security Management Act(FISMA). By adhering to this approach, the policy needed to ensure cloud security can provide effective governance to both industry and lawmakers