Lee Newcombe, Capgemini “Security threats associated with cloud computing”

1,674 views
1,533 views

Published on

Lightning talk at CloudCamp London #5

Published in: Technology, Business
0 Comments
3 Likes
Statistics
Notes
  • Be the first to comment

No Downloads
Views
Total views
1,674
On SlideShare
0
From Embeds
0
Number of Embeds
55
Actions
Shares
0
Downloads
0
Comments
0
Likes
3
Embeds 0
No embeds

No notes for slide

Lee Newcombe, Capgemini “Security threats associated with cloud computing”

  1. 1. Cloud Computing: The Security Threats associated with Cloud Computing Lee Newcombe Ph.D M.Inst.ISP CISSP
  2. 2. Agenda <ul><li>What is a security threat? </li></ul><ul><li>What threats are relevant to cloud? </li></ul><ul><li>What threats are more relevant to cloud? </li></ul><ul><li>Relax, it’s not so bad. </li></ul>
  3. 3. HMG Definition of a Threat “ A potential cause of an incident that may result in harm to a system or organisation” HMG Information Assurance Standard No 2
  4. 4. Cloud Model Cloud Service Provider Internet/PSN /… Software Platform Infrastructure Consumer
  5. 5. Cloud Threats Cloud Service Provider Internet/PSN /… Software Platform Infrastructure Consumer <ul><li>Service Provider Staff </li></ul><ul><li>Access to data (?) </li></ul><ul><li>Control over service availability and integrity </li></ul><ul><li>Image/Application Vendors </li></ul>
  6. 6. Cloud Threats Internet/PSN /… Software Platform Infrastructure Consumer Cloud Service Provider <ul><li>Competitors </li></ul><ul><li>Multi-tenant environment </li></ul><ul><li>Same tin. Same SAN. Same… </li></ul>
  7. 7. Cloud Threats Software Platform Infrastructure Consumer Cloud Service Provider Internet/PSN /… <ul><li>Crackers/Hackers </li></ul><ul><li>Always a threat </li></ul><ul><li>Clouds: a new area to play in </li></ul><ul><li>Internet: old area to play in </li></ul>
  8. 8. Cloud Threats Software Platform Infrastructure Consumer Cloud Service Provider Internet/PSN /… <ul><li>Insiders </li></ul><ul><li>Always a threat </li></ul><ul><li>Cloud services easy to access: </li></ul><ul><ul><li>Credit card? </li></ul></ul><ul><ul><li>Network connectivity? </li></ul></ul><ul><ul><li>Sorted! </li></ul></ul>
  9. 9. Cloud Threats Software Platform Infrastructure Consumer Cloud Service Provider Internet/PSN/… <ul><li>Availability </li></ul><ul><li>You’re now fully reliant on your provider </li></ul><ul><ul><li>What happens if it’s not there? </li></ul></ul>
  10. 10. Cloud Threats COMPLIANCE
  11. 11. What’s new? <ul><li>Not a lot! </li></ul>Most risks also associated with traditional outsourcing. <ul><li>New (or increased) risks: </li></ul><ul><li>Virtualisation and multi-tenancy </li></ul><ul><li>Compliance </li></ul>
  12. 12. Relax, it’s not so bad
  13. 13. Lee Newcombe, Ph.D M.Inst.ISP CISSP Email: [email_address] Web: http://www.uk.capgemini.com Blog: http://securitylifemusings.blogspot.com

×