This document provides a summary of practices for secure development of cloud applications. It was created by a working group from the Software Assurance Forum for Excellence in Code (SAFECode) and Cloud Security Alliance (CSA) to identify additional security practices needed to address unique threats to cloud computing. The document analyzes security considerations for the Platform as a Service (PaaS) cloud computing model and provides recommendations in 6 areas: multitenancy, trusted compute pools, tokenization of sensitive data, data encryption and key management, authentication and identity management, and securing APIs.