CC Unit 5 Notes by DK?

Download as pdf or txt
Download as pdf or txt
You are on page 1of 7

clAsSMAte

Date
Page

Secusity in Cloud Computing


t Tupes of Risk in Cloud Computing.
4 L) Loss oF data:
Daba stoxed ancoud
cloud eiuers
seuers can be lost
thiough natuual disaste malicious attacks, etc.
t Tnceased customer aqitation:
to
Gaouwing
see which
ot cloud seuiceCxitics axe keen
seuiceprouiders
a CUstomers to auoidthem
are weak & encOurage

Im Maluaxe Attacks:
Claud seuices can be a yectax for data
exfiltaation

Threats identfied by Cloud Secuntty Alliance Ccsa):


il Insecuie inteitaces API:
Malicious Tnsides :
Th1eat af mallcious insiders is well-knoun to
most arganigations
Romediation - Deteumin! secuit4 bieach.
notiication piacesses

-By Dk
Date
Page

i) Shaed Techncoloqs ssues in


theis seuices
aaS vendoxs delivexinlastuctune
salabe Las by shaing 4

Remediation- Tmplement sec ueity best


piactices x installationL cantiquatian
DataLassOX Leaknge
data
There ae man uaus to compLomise
nie Deletion ateation af Kecords wrthout backup
Oxiainalcontent bisn cbiaus example.
Remediation - Tnplement stong APr acess cohel
Account hijackinq ntb
Attack methads such phishing iaud
eto sill achieve Kesults

Remediatian - Paahibit shanng of account


CKedentials between Useis Seuices.
Date
Page

t Content LeyelSecuityCcLs)--

’ . Content - based secuityfeatunes include


xestictinq usho can optn Email pint or edit
ontent place hme imit an houw long user
Can accesS
gixenpiece of content
Cantent ca Qxpie fiom a qiren xepasitoiy and.
longer be viewable
iewable by anyone
It etens to p1otection at data at qianular
level ensuing that sensitive intomation Kemains
SeCure uhethe t's in tansiat rest a being

Usesot content lexel secunity ae maniold.


Thhndustiies ike healthcae
indvidual pieces o data
foance
Such as patient
fnance otecting
secords o Anancial tansactions is Cucial.

Content Level Secuits also Suppoits secale data


shaing s collaboation enabling businesses to
satily exchange Sensitive infomafion
By embedding secuity directls inta data
Organigatians Can enhance
their oueial security
postune 8 malntain tust wth stakehalde1s
&
Date
Page

be IsetolL fox
Cantent - basedsecmlty cat Can

aganizatians that extensivelu USe CC enterpiise


h mabiliBs technologjes.

t Chud Skcuity Seuces


Diag1am -
Public
CoadHybiidtota
cloud Cloud
Piivate
Cloud Data Tntegity
Sortune
Data conde ntìality
Dato Secuity &Piiracy
Dato quolability
Harduat
hoa Data piYacy

T) Tnteqiits
" This seiuice. psotects data tiommalcious
modification

Tnteqitsan extend to how data ts stated


Lprocessed B setxiered by claud seuices
Oata Tntgity
Trnteo in cloud systtm Means
pxeSeing intoxmaion
intosmation integiky
CIASSN

Date
Page

Data inteq1ts is the basis to pIovide


claud computting seluices ike Saas Paas & TaaS.
claud
T) Confidentiality
Canfidenti aly xefers to limiting infoumatian.
access.

Stnsitlve inraumatian shouldbe kept sczet tiom


indhviduals uha. not authoiged to See
ioLmation
Data conidentialitys impctantfo uses to
stoie theixplvate orcontidentialdata in
cloud.

T) Auailabilty-
. This seuiceassuiesthat data stoed in
cloud auailable each User xetaieral
equest
This seuice ispaiticula1lsimpostant o dato
at xestoin cloud seueis E elated to tuluGtmeot
of seuice evel g1ement

The claud se\uice piauider shauld ensuue the


data Secutty T pasticula1ly
pasticulally data contidentialits
and intequlty
Data
Paga

Cloud seuice paauìder should shaie althe


x build txst selationshio
ceuns
oncens wth client
in this Connection.
o

t laud Tetinq
claud & Types
isOne type o Sattwax
daud Testing
testing in hich the soware applications.
axe tested by using claud Camputing seiuices

cloud Tosting otte1s useIS pay= per- use


picng flexibilitus & educed ine -to-maxket.

Cloud Tesing ensues taster auailability


Scalability 6 flexibility thdtSaues hme &
cost farscthuaie testinq
Types of Testing These ae xealtypes
il Functional Bsting -
Functiooal sotuanetestng checks all the
featuxes K fincthons osofhuae and ts.
intoxaction nth haxduaxe
"Fox conducting Finctianal testing testers
toals ike Rapise Rapise SaucR Labs, etc
Sauco
Date
Page

i Nlon - Functional Testing


.It is also Rnown
as peifaumance testing
all.ausuou to check non - tunctional
aspects ot softuae like its peifomance usability,
xeliability ete
Fox canducting this type aF testing., yau can
uSe tools ike CloudTest CloudTest Go Apolaaden,ttc
) Ability Testing
Ability testing is necessaly to veity whether
USels exeally secelve aplication Seluices gn demand

The uhale claud testiag is segmented into 4


main cateqaaies:
d Testing whole
cloud
The cloud ls uieued uhole entits and
based on its featunes testing is catied aut

A)B) Testing wthin a cloud


By checking each o its inteinal eatumes.
testhng isis caskied out

c)Tosting gcoss claud


Tosting s casaied Out
dffenent
hybid claud
types
like paivate public
A Soas Testingin cloud
Finctional x Non- kunchanal testing is canaied
out basis of applica fion x9quire ments

You might also like