Skip to main content
CLOUD COMPUTING SECURITY
By
AMBRISH GANGAL
FOCUS POINTS
• Cloud computing security or, more simply,
cloud security refers to a broad set of policies,
technologies, and controls deployed to
protect data, applications, and the associated
infrastructure of cloud computing.
• It is a sub-domain of computer security,
network security, and, more broadly,
information security.
WHO IS RESPONSIBLE ?
NOTE : Security is a shared responsibility
CSA Enterprise Security Architecture
Which deployment model can be
trusted ??
Areas of Critical Focus (current
scenario)
Areas of Critical Focus (current
scenario)
Areas of Critical Focus (current
scenario)
Areas of Critical Focus (current
scenario)
Dimensions of cloud security
• Security and privacy
– Identity
management
– Physical security
– Personnel security
– Privacy
• Data security
– Confidentiality
– Access controllability
– Integrity
•Compliance
—Business continuity and
data recovery
—Log and audit trail
—Unique compliance
requirements
•Legal and contractual
issues
CLOUD SECURITY CONTROLS
Deterrent controls
These controls are intended to reduce attacks on a cloud system. Much like a
warning sign on a fence or a property, deterrent controls typically reduce the
threat level by informing potential attackers that there will be adverse
consequences for them if they proceed. (Some consider them a subset of
preventive controls.)
Preventive controls
Preventive controls strengthen the system against incidents, generally by
reducing if not actually eliminating vulnerabilities. Strong authentication of cloud
users, for instance, makes it less likely that unauthorized users can access
cloud systems, and more likely that cloud users are positively identified.
Detective controls
Detective controls are intended to detect and react appropriately to
any incidents that occur. In the event of an attack, a detective control will
signal the preventative or corrective controls to address the issue.
System and network security monitoring, including intrusion detection
and prevention arrangements, are typically employed to detect attacks
on cloud systems and the supporting communications infrastructure.
Corrective controls
Corrective controls reduce the consequences of an incident, normally by
limiting the damage. They come into effect during or after an incident. Restoring
system backups in order to rebuild a compromised system is an example of a
corrective control.
• Cloud security architecture is effective only if the
correct defensive implementations are in place.
References :
• Cloud computing security. (2018, January 20). In Wikipedia, The Free
Encyclopedia. Retrieved 05:09, February 16, 2018, from
https://en.wikipedia.org/w/index.php?title=Cloud_computing_security&ol
did=821439982
• Security Guidance v4.0, Cloud Security Alliance. , February 2, 2018