SlideShare a Scribd company logo
C11-1
CASE STUDY 11
CLOUD COMPUTING (IN)SECURITY
Cloud computing is reshaping enterprise network architectures
and
infrastructures. It refers to applications delivered as services
over the
Internet as well as the hardware and systems software in data
centers that
provide those services. The services themselves have long been
referred to
as Software as a Service (SaaS) which had its roots in Software-
Oriented
Architecture (SOA) concepts that began shaping enterprise
network
roadmaps in the early 2000s. IaaS (Infrastructure as a Service)
and PaaS
(Platform as a Service) are other types of cloud computing
services that are
available to business customers.
Cloud computing fosters the notion of computing as a utility
that can be
consumed by businesses on demand in a manner that is similar
to other
services (e.g. electricity, municipal water) from traditional
utilities. It has the
potential to reshape much of the IT industry by giving
businesses the option
of running business software applications fully on-premises,
fully in “the
cloud” or some combination of these two extremes. These are
choices that
businesses have not had until recently and many companies are
still coming
to grips with this new computing landscape.
Security is important to any computing infrastructure.
Companies go to
great lengths to secure on-premises computing systems, so it is
not
surprising that security looms as a major consideration when
augmenting or
replacing on-premises systems with cloud services. Allaying
security
C11-2
concerns is frequently a prerequisite for further discussions
about migrating
part or all of an organization’s computing architecture to the
cloud.
Availability is another major concern: “How will we operate if
we can’t access
the Internet? What if our customers can’t access the cloud to
place orders?”
are common questions [AMBR10].
Generally speaking, such questions only arise when businesses
contemplating moving core transaction processing, such as ERP
systems,
and other mission critical applications to the cloud. Companies
have
traditionally demonstrated less concern about migrating high
maintenance
applications such as e-mail and payroll to cloud service
providers even
though such applications hold sensitive information.
Security Issues and Concerns
Auditability is a concern for many organizations, especially
those who must
comply with Sarbanes-Oxley and/or Health and Human Services
Health
Insurance Portability and Accountability Act (HIPAA)
regulations [IBM11].
The auditability of their data must be ensured whether it is
stored on-
premises or moved to the cloud.
Before moving critical infrastructure to the cloud, businesses
should do
diligence on security threats both from outside and inside the
cloud
[BADG11]. Many of the security issues associated with
protecting clouds
from outside threats are similar to those that have traditionally
faced
centralized data centers. In the cloud, however, responsibility
for assuring
adequate security is frequently shared among users, vendors,
and any third-
party firms that users rely on for security-sensitive software or
configurations. Cloud users are responsible for application-level
security.
Cloud vendors are responsible for physical security and some
software
security such as enforcing external firewall policies. Security
for intermediate
layers of the software stack is shared between users and
vendors.
C11-3
A security risk that can be overlooked by companies
considering a
migration to the cloud is that posed by sharing vendor resources
with other
cloud users. Cloud providers must guard against theft or denial-
of-service
attacks by their users and users need to be protected from one
another.
Virtualization can be a powerful mechanism for addressing
these potential
risks because it protects against most attempts by users to attack
one
another or the provider’s infrastructure. However, not all
resources are
virtualized and not all virtualization environments are bug-free.
Incorrect
virtualization may allow user code to access to sensitive
portions of the
provider’s infrastructure or the resources of other users. Once
again, these
security issues are not unique to the cloud and are similar to
those involved
in managing non-cloud data centers, where different
applications need to be
protected from one another.
Another security concern that businesses should consider is the
extent
to which subscribers are protected against the provider,
especially in the
area of inadvertent data loss. For example, in the event of
provider
infrastructure improvements, what happens to hardware that is
retired or
replaced? It is easy to imagine a hard disk being disposed of
without being
properly wiped clean of subscriber data. It is also easy to
imagine
permissions bugs or errors that make subscriber data visible to
unauthorized
users. User-level encryption may be an important self-help
mechanism for
subscribers, but businesses should ensure that other protections
are in place
to avoid inadvertent data loss.
Addressing Cloud Computer Security Concerns
Numerous documents have been developed to guide business
thinking
about the security issues associated with cloud computing. Even
NIST has
weighed in on these issues [BADG11]. NIST’s
recommendations
systematically consider each of the major types of cloud
services consumed
C11-4
by businesses including Software as a Service (SaaS),
Infrastructure as a
Service (IaaS), and Platform as a Service (PaaS). While security
issues vary
somewhat depending on the type of cloud service, there are
multiple NIST
recommendations that are independent of service type. Several
of these are
summarized in Table C11.1. Not surprisingly, NIST
recommends selecting
cloud providers that support strong encryption, have appropriate
redundancy
mechanisms in place, employ authentication mechanisms, and
offer
subscribers sufficient visibility about mechanisms used to
protect subscribers
from other subscribers and the provider.
As more businesses incorporate cloud services into their
enterprise
network infrastructures, cloud computing security will persist as
an
important issue. Examples of cloud computing security failures
have to
potential to have a chilling effect on business interest in cloud
services and
this is inspiring service providers to be serious about
incorporating security
mechanisms that will allay concerns of potential subscribers.
Some service
providers have moved their operations to Tier 4 data centers to
address user
concerns about availability and redundancy. Because so many
businesses
remain reluctant to embrace cloud computing in a big way,
cloud service
providers will have to continue to work hard to convince
potential customers
that computing support for core business processes and mission
critical
applications can be moved safely and securely to the cloud
[HEAV11].
Discussion Points
1. Do some Internet research to identify businesses who have
suffered
because of cloud security weaknesses or failures. What can
companies
who are contemplating cloud computing services learn from the
negative experiences of these businesses?
2. Do some Internet research on security mechanisms associated
with
virtualization. How can virtualization be used by cloud service
providers to protect subscriber data?
C11-5
3. Choose one of the following cloud services categories: SaaS,
IaaS,
PaaS. Do some Internet research that focuses the security issues
associated with the selected cloud service category. Summarize
the
major security risks associated with the cloud service category
and
identify mechanisms that can be used to address these risks.
Sources
[ARMB10] Armbrust, M., Fox, A., Griffith, R, Joseph, A.D.,
Katz, R.,
Konwinski, A., Lee, G., Patterson, D., Rabkin, A., Stoica, I.,
and Zaharia, M.
“A View of Cloud Computing.” Communications of the ACM,
Vol. 53, No. 4,
April 2010, pp. 50-58.
[BADG11] Badger, L., Grance, T., Patt-Comer, R., and Voas, J.
Draft Cloud
Computing Synopsis and Recommendations: Recommendations
of the
National Institute of Standards and Technology, Special
Publication 800-146,
May 2011.
[HEAV11] Heavey, J. “Cloud Computing: Secure or Security
Risk?”
Technorati.com, November 28, 2011. Retrieved online from:
http://technorati.com/technology/cloud-computing/article/cloud-
computing-
secure-or-a-security1/.
[IBM11] IBM Global Technology Services. Security and
Availability in Cloud
Computing Environments, Technical White Paper, June 2011.
http://technorati.com/technology/cloud-computing/article/cloud-
computing-secure-or-a-security1/
http://technorati.com/technology/cloud-computing/article/cloud-
computing-secure-or-a-security1/
C11-6
CASE STUDY 11Security Issues and ConcernsAddressing
Cloud Computer Security ConcernsDiscussion PointsSources

More Related Content

Similar to C11-1 CASE STUDY 11 CLOUD COMPUTING (IN)SECURITY .docx

SECURITY AND PRIVACY SOLUTIONS IN CLOUD COMPUTING AT OPENSTACK TO SUSTAIN USE...
SECURITY AND PRIVACY SOLUTIONS IN CLOUD COMPUTING AT OPENSTACK TO SUSTAIN USE...SECURITY AND PRIVACY SOLUTIONS IN CLOUD COMPUTING AT OPENSTACK TO SUSTAIN USE...
SECURITY AND PRIVACY SOLUTIONS IN CLOUD COMPUTING AT OPENSTACK TO SUSTAIN USE...
Zac Darcy
 
Cloud computing seminar report
Cloud computing seminar reportCloud computing seminar report
Cloud computing seminar report
shafzonly
 
SECURE CLOUD ARCHITECTURE
SECURE CLOUD ARCHITECTURESECURE CLOUD ARCHITECTURE
SECURE CLOUD ARCHITECTURE
acijjournal
 
Ad4502189193
Ad4502189193Ad4502189193
Ad4502189193
IJERA Editor
 
The Management of Security in Cloud Computing Ramgovind.docx
The Management of Security in Cloud Computing  Ramgovind.docxThe Management of Security in Cloud Computing  Ramgovind.docx
The Management of Security in Cloud Computing Ramgovind.docx
cherry686017
 
Trends in the IT Profession Annotated BibliographyAdemola Adeleke.docx
Trends in the IT Profession Annotated BibliographyAdemola Adeleke.docxTrends in the IT Profession Annotated BibliographyAdemola Adeleke.docx
Trends in the IT Profession Annotated BibliographyAdemola Adeleke.docx
willcoxjanay
 
INFORMATION SECURITY IN CLOUD COMPUTING
INFORMATION SECURITY IN CLOUD COMPUTINGINFORMATION SECURITY IN CLOUD COMPUTING
INFORMATION SECURITY IN CLOUD COMPUTING
ijitcs
 
Cloud Computing Security Issues and Challenges
Cloud Computing Security Issues and ChallengesCloud Computing Security Issues and Challenges
Cloud Computing Security Issues and Challenges
CSCJournals
 
Ijaprr vol1-1-1-5dr tejinder
Ijaprr vol1-1-1-5dr tejinderIjaprr vol1-1-1-5dr tejinder
Ijaprr vol1-1-1-5dr tejinder
ijaprr_editor
 
Ijaprr vol1-1-1-5dr tejinder
Ijaprr vol1-1-1-5dr tejinderIjaprr vol1-1-1-5dr tejinder
Ijaprr vol1-1-1-5dr tejinder
ijaprr
 
A Review on Data Protection of Cloud Computing Security, Benefits, Risks and ...
A Review on Data Protection of Cloud Computing Security, Benefits, Risks and ...A Review on Data Protection of Cloud Computing Security, Benefits, Risks and ...
A Review on Data Protection of Cloud Computing Security, Benefits, Risks and ...
United International Journal for Research & Technology
 
Security in Cloud Computing For Service Delivery Models: Challenges and Solut...
Security in Cloud Computing For Service Delivery Models: Challenges and Solut...Security in Cloud Computing For Service Delivery Models: Challenges and Solut...
Security in Cloud Computing For Service Delivery Models: Challenges and Solut...
IJERA Editor
 
Cloud Computing: Business Trends and the Challenges
Cloud Computing: Business Trends and the ChallengesCloud Computing: Business Trends and the Challenges
Cloud Computing: Business Trends and the Challenges
idescitation
 
A Detailed Analysis of the Issues and Solutions for Securing Data in Cloud
A Detailed Analysis of the Issues and Solutions for Securing Data  in CloudA Detailed Analysis of the Issues and Solutions for Securing Data  in Cloud
A Detailed Analysis of the Issues and Solutions for Securing Data in Cloud
IOSR Journals
 
Cloud Computing Security Issues in Infrastructure as a Service” report
Cloud Computing Security Issues in Infrastructure as a Service” reportCloud Computing Security Issues in Infrastructure as a Service” report
Cloud Computing Security Issues in Infrastructure as a Service” reportVivek Maurya
 
Literature Review: Security on cloud computing
Literature Review: Security on cloud computingLiterature Review: Security on cloud computing
Literature Review: Security on cloud computing
Suranga Nisiwasala
 
wp-security-dbsec-cloud-3225125
wp-security-dbsec-cloud-3225125wp-security-dbsec-cloud-3225125
wp-security-dbsec-cloud-3225125Gabor Bokor
 
Security of Data in Cloud Environment Using DPaaS
Security of Data in Cloud Environment Using DPaaSSecurity of Data in Cloud Environment Using DPaaS
Security of Data in Cloud Environment Using DPaaS
IJMER
 
Ijirsm poornima-km-a-survey-on-security-circumstances-for-mobile-cloud-computing
Ijirsm poornima-km-a-survey-on-security-circumstances-for-mobile-cloud-computingIjirsm poornima-km-a-survey-on-security-circumstances-for-mobile-cloud-computing
Ijirsm poornima-km-a-survey-on-security-circumstances-for-mobile-cloud-computing
IJIR JOURNALS IJIRUSA
 
Legal And Regulatory Issues Cloud Computing...V2.0
Legal And Regulatory Issues Cloud Computing...V2.0Legal And Regulatory Issues Cloud Computing...V2.0
Legal And Regulatory Issues Cloud Computing...V2.0David Spinks
 

Similar to C11-1 CASE STUDY 11 CLOUD COMPUTING (IN)SECURITY .docx (20)

SECURITY AND PRIVACY SOLUTIONS IN CLOUD COMPUTING AT OPENSTACK TO SUSTAIN USE...
SECURITY AND PRIVACY SOLUTIONS IN CLOUD COMPUTING AT OPENSTACK TO SUSTAIN USE...SECURITY AND PRIVACY SOLUTIONS IN CLOUD COMPUTING AT OPENSTACK TO SUSTAIN USE...
SECURITY AND PRIVACY SOLUTIONS IN CLOUD COMPUTING AT OPENSTACK TO SUSTAIN USE...
 
Cloud computing seminar report
Cloud computing seminar reportCloud computing seminar report
Cloud computing seminar report
 
SECURE CLOUD ARCHITECTURE
SECURE CLOUD ARCHITECTURESECURE CLOUD ARCHITECTURE
SECURE CLOUD ARCHITECTURE
 
Ad4502189193
Ad4502189193Ad4502189193
Ad4502189193
 
The Management of Security in Cloud Computing Ramgovind.docx
The Management of Security in Cloud Computing  Ramgovind.docxThe Management of Security in Cloud Computing  Ramgovind.docx
The Management of Security in Cloud Computing Ramgovind.docx
 
Trends in the IT Profession Annotated BibliographyAdemola Adeleke.docx
Trends in the IT Profession Annotated BibliographyAdemola Adeleke.docxTrends in the IT Profession Annotated BibliographyAdemola Adeleke.docx
Trends in the IT Profession Annotated BibliographyAdemola Adeleke.docx
 
INFORMATION SECURITY IN CLOUD COMPUTING
INFORMATION SECURITY IN CLOUD COMPUTINGINFORMATION SECURITY IN CLOUD COMPUTING
INFORMATION SECURITY IN CLOUD COMPUTING
 
Cloud Computing Security Issues and Challenges
Cloud Computing Security Issues and ChallengesCloud Computing Security Issues and Challenges
Cloud Computing Security Issues and Challenges
 
Ijaprr vol1-1-1-5dr tejinder
Ijaprr vol1-1-1-5dr tejinderIjaprr vol1-1-1-5dr tejinder
Ijaprr vol1-1-1-5dr tejinder
 
Ijaprr vol1-1-1-5dr tejinder
Ijaprr vol1-1-1-5dr tejinderIjaprr vol1-1-1-5dr tejinder
Ijaprr vol1-1-1-5dr tejinder
 
A Review on Data Protection of Cloud Computing Security, Benefits, Risks and ...
A Review on Data Protection of Cloud Computing Security, Benefits, Risks and ...A Review on Data Protection of Cloud Computing Security, Benefits, Risks and ...
A Review on Data Protection of Cloud Computing Security, Benefits, Risks and ...
 
Security in Cloud Computing For Service Delivery Models: Challenges and Solut...
Security in Cloud Computing For Service Delivery Models: Challenges and Solut...Security in Cloud Computing For Service Delivery Models: Challenges and Solut...
Security in Cloud Computing For Service Delivery Models: Challenges and Solut...
 
Cloud Computing: Business Trends and the Challenges
Cloud Computing: Business Trends and the ChallengesCloud Computing: Business Trends and the Challenges
Cloud Computing: Business Trends and the Challenges
 
A Detailed Analysis of the Issues and Solutions for Securing Data in Cloud
A Detailed Analysis of the Issues and Solutions for Securing Data  in CloudA Detailed Analysis of the Issues and Solutions for Securing Data  in Cloud
A Detailed Analysis of the Issues and Solutions for Securing Data in Cloud
 
Cloud Computing Security Issues in Infrastructure as a Service” report
Cloud Computing Security Issues in Infrastructure as a Service” reportCloud Computing Security Issues in Infrastructure as a Service” report
Cloud Computing Security Issues in Infrastructure as a Service” report
 
Literature Review: Security on cloud computing
Literature Review: Security on cloud computingLiterature Review: Security on cloud computing
Literature Review: Security on cloud computing
 
wp-security-dbsec-cloud-3225125
wp-security-dbsec-cloud-3225125wp-security-dbsec-cloud-3225125
wp-security-dbsec-cloud-3225125
 
Security of Data in Cloud Environment Using DPaaS
Security of Data in Cloud Environment Using DPaaSSecurity of Data in Cloud Environment Using DPaaS
Security of Data in Cloud Environment Using DPaaS
 
Ijirsm poornima-km-a-survey-on-security-circumstances-for-mobile-cloud-computing
Ijirsm poornima-km-a-survey-on-security-circumstances-for-mobile-cloud-computingIjirsm poornima-km-a-survey-on-security-circumstances-for-mobile-cloud-computing
Ijirsm poornima-km-a-survey-on-security-circumstances-for-mobile-cloud-computing
 
Legal And Regulatory Issues Cloud Computing...V2.0
Legal And Regulatory Issues Cloud Computing...V2.0Legal And Regulatory Issues Cloud Computing...V2.0
Legal And Regulatory Issues Cloud Computing...V2.0
 

More from clairbycraft

Calculus Quiz 2 (Derivatives)Covers Units 9-13. This is a 10 quest.docx
Calculus Quiz 2 (Derivatives)Covers Units 9-13. This is a 10 quest.docxCalculus Quiz 2 (Derivatives)Covers Units 9-13. This is a 10 quest.docx
Calculus Quiz 2 (Derivatives)Covers Units 9-13. This is a 10 quest.docx
clairbycraft
 
Calculus IDirections (10 pts. each) Answer each of the followin.docx
Calculus IDirections (10 pts. each) Answer each of the followin.docxCalculus IDirections (10 pts. each) Answer each of the followin.docx
Calculus IDirections (10 pts. each) Answer each of the followin.docx
clairbycraft
 
Cadence Publishes Comprehensive Book onMixed-Signal Method.docx
Cadence Publishes Comprehensive Book onMixed-Signal Method.docxCadence Publishes Comprehensive Book onMixed-Signal Method.docx
Cadence Publishes Comprehensive Book onMixed-Signal Method.docx
clairbycraft
 
Calculate the energy in the form of heat (in kJ) required to change .docx
Calculate the energy in the form of heat (in kJ) required to change .docxCalculate the energy in the form of heat (in kJ) required to change .docx
Calculate the energy in the form of heat (in kJ) required to change .docx
clairbycraft
 
CAHIIM Competencies Assessed Subdomain VI.D. Human Resources Ma.docx
CAHIIM Competencies Assessed Subdomain VI.D. Human Resources Ma.docxCAHIIM Competencies Assessed Subdomain VI.D. Human Resources Ma.docx
CAHIIM Competencies Assessed Subdomain VI.D. Human Resources Ma.docx
clairbycraft
 
C8-1 CASE STUDY 8 CARLSON COMPANIES STORAGE SOLUT.docx
C8-1 CASE STUDY 8    CARLSON COMPANIES STORAGE SOLUT.docxC8-1 CASE STUDY 8    CARLSON COMPANIES STORAGE SOLUT.docx
C8-1 CASE STUDY 8 CARLSON COMPANIES STORAGE SOLUT.docx
clairbycraft
 
Caffeine intake in children in the United States and 10-ytre.docx
Caffeine intake in children in the United States and 10-ytre.docxCaffeine intake in children in the United States and 10-ytre.docx
Caffeine intake in children in the United States and 10-ytre.docx
clairbycraft
 
Cabbage patch hip dance move, The running man hip hop dance move, th.docx
Cabbage patch hip dance move, The running man hip hop dance move, th.docxCabbage patch hip dance move, The running man hip hop dance move, th.docx
Cabbage patch hip dance move, The running man hip hop dance move, th.docx
clairbycraft
 
CA4Leading TeamsAre we a teamHi, my name is Jenny .docx
CA4Leading TeamsAre we a teamHi, my name is Jenny .docxCA4Leading TeamsAre we a teamHi, my name is Jenny .docx
CA4Leading TeamsAre we a teamHi, my name is Jenny .docx
clairbycraft
 
C7-1 CASE STUDY 7 DATA CENTER CONSOLIDATION AT GUARDI.docx
C7-1 CASE STUDY 7  DATA CENTER CONSOLIDATION AT GUARDI.docxC7-1 CASE STUDY 7  DATA CENTER CONSOLIDATION AT GUARDI.docx
C7-1 CASE STUDY 7 DATA CENTER CONSOLIDATION AT GUARDI.docx
clairbycraft
 
C9-1 CASE STUDY 9 ST. LUKES HEALTH CARE SYSTEM Hospitals have been .docx
C9-1 CASE STUDY 9 ST. LUKES HEALTH CARE SYSTEM Hospitals have been .docxC9-1 CASE STUDY 9 ST. LUKES HEALTH CARE SYSTEM Hospitals have been .docx
C9-1 CASE STUDY 9 ST. LUKES HEALTH CARE SYSTEM Hospitals have been .docx
clairbycraft
 
C9-1 CASE STUDY 9 ST. LUKES HEALTH CARE SYSTEM .docx
C9-1 CASE STUDY 9   ST. LUKES HEALTH CARE SYSTEM .docxC9-1 CASE STUDY 9   ST. LUKES HEALTH CARE SYSTEM .docx
C9-1 CASE STUDY 9 ST. LUKES HEALTH CARE SYSTEM .docx
clairbycraft
 
C361 TASK 22C361 TASK 22C361 Task 2WGUEv.docx
C361 TASK 22C361 TASK 22C361 Task 2WGUEv.docxC361 TASK 22C361 TASK 22C361 Task 2WGUEv.docx
C361 TASK 22C361 TASK 22C361 Task 2WGUEv.docx
clairbycraft
 
C6-1 CASE STUDY 6 CHEVRON’S INFRASTRUCTURE EVOLUT.docx
C6-1 CASE STUDY 6 CHEVRON’S INFRASTRUCTURE  EVOLUT.docxC6-1 CASE STUDY 6 CHEVRON’S INFRASTRUCTURE  EVOLUT.docx
C6-1 CASE STUDY 6 CHEVRON’S INFRASTRUCTURE EVOLUT.docx
clairbycraft
 
C125C126 FORMAL LAB REPORTFORMAL LAB REPORT, GeneralA f.docx
C125C126 FORMAL LAB REPORTFORMAL LAB REPORT, GeneralA f.docxC125C126 FORMAL LAB REPORTFORMAL LAB REPORT, GeneralA f.docx
C125C126 FORMAL LAB REPORTFORMAL LAB REPORT, GeneralA f.docx
clairbycraft
 
C10-1 CASE STUDY 10 CHOICE HOTELS INTERNATIONAL .docx
C10-1 CASE STUDY 10     CHOICE HOTELS INTERNATIONAL .docxC10-1 CASE STUDY 10     CHOICE HOTELS INTERNATIONAL .docx
C10-1 CASE STUDY 10 CHOICE HOTELS INTERNATIONAL .docx
clairbycraft
 
C1-1 CASE STUDY 1 UNIFIED COMMUNICATIONS AT BOEING .docx
C1-1 CASE STUDY 1  UNIFIED COMMUNICATIONS AT BOEING .docxC1-1 CASE STUDY 1  UNIFIED COMMUNICATIONS AT BOEING .docx
C1-1 CASE STUDY 1 UNIFIED COMMUNICATIONS AT BOEING .docx
clairbycraft
 
C09 07222011 101525 Page 88IT leader who had just been.docx
C09 07222011 101525 Page 88IT leader who had just been.docxC09 07222011 101525 Page 88IT leader who had just been.docx
C09 07222011 101525 Page 88IT leader who had just been.docx
clairbycraft
 
C053GXML 10192012 214425 Page 131cC H A P T E R.docx
C053GXML 10192012 214425 Page 131cC H A P T E R.docxC053GXML 10192012 214425 Page 131cC H A P T E R.docx
C053GXML 10192012 214425 Page 131cC H A P T E R.docx
clairbycraft
 
c04.DS_Storec04comparison-operator.htmlBullseyec04com.docx
c04.DS_Storec04comparison-operator.htmlBullseyec04com.docxc04.DS_Storec04comparison-operator.htmlBullseyec04com.docx
c04.DS_Storec04comparison-operator.htmlBullseyec04com.docx
clairbycraft
 

More from clairbycraft (20)

Calculus Quiz 2 (Derivatives)Covers Units 9-13. This is a 10 quest.docx
Calculus Quiz 2 (Derivatives)Covers Units 9-13. This is a 10 quest.docxCalculus Quiz 2 (Derivatives)Covers Units 9-13. This is a 10 quest.docx
Calculus Quiz 2 (Derivatives)Covers Units 9-13. This is a 10 quest.docx
 
Calculus IDirections (10 pts. each) Answer each of the followin.docx
Calculus IDirections (10 pts. each) Answer each of the followin.docxCalculus IDirections (10 pts. each) Answer each of the followin.docx
Calculus IDirections (10 pts. each) Answer each of the followin.docx
 
Cadence Publishes Comprehensive Book onMixed-Signal Method.docx
Cadence Publishes Comprehensive Book onMixed-Signal Method.docxCadence Publishes Comprehensive Book onMixed-Signal Method.docx
Cadence Publishes Comprehensive Book onMixed-Signal Method.docx
 
Calculate the energy in the form of heat (in kJ) required to change .docx
Calculate the energy in the form of heat (in kJ) required to change .docxCalculate the energy in the form of heat (in kJ) required to change .docx
Calculate the energy in the form of heat (in kJ) required to change .docx
 
CAHIIM Competencies Assessed Subdomain VI.D. Human Resources Ma.docx
CAHIIM Competencies Assessed Subdomain VI.D. Human Resources Ma.docxCAHIIM Competencies Assessed Subdomain VI.D. Human Resources Ma.docx
CAHIIM Competencies Assessed Subdomain VI.D. Human Resources Ma.docx
 
C8-1 CASE STUDY 8 CARLSON COMPANIES STORAGE SOLUT.docx
C8-1 CASE STUDY 8    CARLSON COMPANIES STORAGE SOLUT.docxC8-1 CASE STUDY 8    CARLSON COMPANIES STORAGE SOLUT.docx
C8-1 CASE STUDY 8 CARLSON COMPANIES STORAGE SOLUT.docx
 
Caffeine intake in children in the United States and 10-ytre.docx
Caffeine intake in children in the United States and 10-ytre.docxCaffeine intake in children in the United States and 10-ytre.docx
Caffeine intake in children in the United States and 10-ytre.docx
 
Cabbage patch hip dance move, The running man hip hop dance move, th.docx
Cabbage patch hip dance move, The running man hip hop dance move, th.docxCabbage patch hip dance move, The running man hip hop dance move, th.docx
Cabbage patch hip dance move, The running man hip hop dance move, th.docx
 
CA4Leading TeamsAre we a teamHi, my name is Jenny .docx
CA4Leading TeamsAre we a teamHi, my name is Jenny .docxCA4Leading TeamsAre we a teamHi, my name is Jenny .docx
CA4Leading TeamsAre we a teamHi, my name is Jenny .docx
 
C7-1 CASE STUDY 7 DATA CENTER CONSOLIDATION AT GUARDI.docx
C7-1 CASE STUDY 7  DATA CENTER CONSOLIDATION AT GUARDI.docxC7-1 CASE STUDY 7  DATA CENTER CONSOLIDATION AT GUARDI.docx
C7-1 CASE STUDY 7 DATA CENTER CONSOLIDATION AT GUARDI.docx
 
C9-1 CASE STUDY 9 ST. LUKES HEALTH CARE SYSTEM Hospitals have been .docx
C9-1 CASE STUDY 9 ST. LUKES HEALTH CARE SYSTEM Hospitals have been .docxC9-1 CASE STUDY 9 ST. LUKES HEALTH CARE SYSTEM Hospitals have been .docx
C9-1 CASE STUDY 9 ST. LUKES HEALTH CARE SYSTEM Hospitals have been .docx
 
C9-1 CASE STUDY 9 ST. LUKES HEALTH CARE SYSTEM .docx
C9-1 CASE STUDY 9   ST. LUKES HEALTH CARE SYSTEM .docxC9-1 CASE STUDY 9   ST. LUKES HEALTH CARE SYSTEM .docx
C9-1 CASE STUDY 9 ST. LUKES HEALTH CARE SYSTEM .docx
 
C361 TASK 22C361 TASK 22C361 Task 2WGUEv.docx
C361 TASK 22C361 TASK 22C361 Task 2WGUEv.docxC361 TASK 22C361 TASK 22C361 Task 2WGUEv.docx
C361 TASK 22C361 TASK 22C361 Task 2WGUEv.docx
 
C6-1 CASE STUDY 6 CHEVRON’S INFRASTRUCTURE EVOLUT.docx
C6-1 CASE STUDY 6 CHEVRON’S INFRASTRUCTURE  EVOLUT.docxC6-1 CASE STUDY 6 CHEVRON’S INFRASTRUCTURE  EVOLUT.docx
C6-1 CASE STUDY 6 CHEVRON’S INFRASTRUCTURE EVOLUT.docx
 
C125C126 FORMAL LAB REPORTFORMAL LAB REPORT, GeneralA f.docx
C125C126 FORMAL LAB REPORTFORMAL LAB REPORT, GeneralA f.docxC125C126 FORMAL LAB REPORTFORMAL LAB REPORT, GeneralA f.docx
C125C126 FORMAL LAB REPORTFORMAL LAB REPORT, GeneralA f.docx
 
C10-1 CASE STUDY 10 CHOICE HOTELS INTERNATIONAL .docx
C10-1 CASE STUDY 10     CHOICE HOTELS INTERNATIONAL .docxC10-1 CASE STUDY 10     CHOICE HOTELS INTERNATIONAL .docx
C10-1 CASE STUDY 10 CHOICE HOTELS INTERNATIONAL .docx
 
C1-1 CASE STUDY 1 UNIFIED COMMUNICATIONS AT BOEING .docx
C1-1 CASE STUDY 1  UNIFIED COMMUNICATIONS AT BOEING .docxC1-1 CASE STUDY 1  UNIFIED COMMUNICATIONS AT BOEING .docx
C1-1 CASE STUDY 1 UNIFIED COMMUNICATIONS AT BOEING .docx
 
C09 07222011 101525 Page 88IT leader who had just been.docx
C09 07222011 101525 Page 88IT leader who had just been.docxC09 07222011 101525 Page 88IT leader who had just been.docx
C09 07222011 101525 Page 88IT leader who had just been.docx
 
C053GXML 10192012 214425 Page 131cC H A P T E R.docx
C053GXML 10192012 214425 Page 131cC H A P T E R.docxC053GXML 10192012 214425 Page 131cC H A P T E R.docx
C053GXML 10192012 214425 Page 131cC H A P T E R.docx
 
c04.DS_Storec04comparison-operator.htmlBullseyec04com.docx
c04.DS_Storec04comparison-operator.htmlBullseyec04com.docxc04.DS_Storec04comparison-operator.htmlBullseyec04com.docx
c04.DS_Storec04comparison-operator.htmlBullseyec04com.docx
 

Recently uploaded

Home assignment II on Spectroscopy 2024 Answers.pdf
Home assignment II on Spectroscopy 2024 Answers.pdfHome assignment II on Spectroscopy 2024 Answers.pdf
Home assignment II on Spectroscopy 2024 Answers.pdf
Tamralipta Mahavidyalaya
 
1.4 modern child centered education - mahatma gandhi-2.pptx
1.4 modern child centered education - mahatma gandhi-2.pptx1.4 modern child centered education - mahatma gandhi-2.pptx
1.4 modern child centered education - mahatma gandhi-2.pptx
JosvitaDsouza2
 
Guidance_and_Counselling.pdf B.Ed. 4th Semester
Guidance_and_Counselling.pdf B.Ed. 4th SemesterGuidance_and_Counselling.pdf B.Ed. 4th Semester
Guidance_and_Counselling.pdf B.Ed. 4th Semester
Atul Kumar Singh
 
Sha'Carri Richardson Presentation 202345
Sha'Carri Richardson Presentation 202345Sha'Carri Richardson Presentation 202345
Sha'Carri Richardson Presentation 202345
beazzy04
 
How to Make a Field invisible in Odoo 17
How to Make a Field invisible in Odoo 17How to Make a Field invisible in Odoo 17
How to Make a Field invisible in Odoo 17
Celine George
 
Synthetic Fiber Construction in lab .pptx
Synthetic Fiber Construction in lab .pptxSynthetic Fiber Construction in lab .pptx
Synthetic Fiber Construction in lab .pptx
Pavel ( NSTU)
 
The Accursed House by Émile Gaboriau.pptx
The Accursed House by Émile Gaboriau.pptxThe Accursed House by Émile Gaboriau.pptx
The Accursed House by Émile Gaboriau.pptx
DhatriParmar
 
Welcome to TechSoup New Member Orientation and Q&A (May 2024).pdf
Welcome to TechSoup   New Member Orientation and Q&A (May 2024).pdfWelcome to TechSoup   New Member Orientation and Q&A (May 2024).pdf
Welcome to TechSoup New Member Orientation and Q&A (May 2024).pdf
TechSoup
 
Model Attribute Check Company Auto Property
Model Attribute  Check Company Auto PropertyModel Attribute  Check Company Auto Property
Model Attribute Check Company Auto Property
Celine George
 
Operation Blue Star - Saka Neela Tara
Operation Blue Star   -  Saka Neela TaraOperation Blue Star   -  Saka Neela Tara
Operation Blue Star - Saka Neela Tara
Balvir Singh
 
Francesca Gottschalk - How can education support child empowerment.pptx
Francesca Gottschalk - How can education support child empowerment.pptxFrancesca Gottschalk - How can education support child empowerment.pptx
Francesca Gottschalk - How can education support child empowerment.pptx
EduSkills OECD
 
Phrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXX
Phrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXXPhrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXX
Phrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXX
MIRIAMSALINAS13
 
CLASS 11 CBSE B.St Project AIDS TO TRADE - INSURANCE
CLASS 11 CBSE B.St Project AIDS TO TRADE - INSURANCECLASS 11 CBSE B.St Project AIDS TO TRADE - INSURANCE
CLASS 11 CBSE B.St Project AIDS TO TRADE - INSURANCE
BhavyaRajput3
 
2024.06.01 Introducing a competency framework for languag learning materials ...
2024.06.01 Introducing a competency framework for languag learning materials ...2024.06.01 Introducing a competency framework for languag learning materials ...
2024.06.01 Introducing a competency framework for languag learning materials ...
Sandy Millin
 
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
Levi Shapiro
 
Chapter 3 - Islamic Banking Products and Services.pptx
Chapter 3 - Islamic Banking Products and Services.pptxChapter 3 - Islamic Banking Products and Services.pptx
Chapter 3 - Islamic Banking Products and Services.pptx
Mohd Adib Abd Muin, Senior Lecturer at Universiti Utara Malaysia
 
Embracing GenAI - A Strategic Imperative
Embracing GenAI - A Strategic ImperativeEmbracing GenAI - A Strategic Imperative
Embracing GenAI - A Strategic Imperative
Peter Windle
 
Palestine last event orientationfvgnh .pptx
Palestine last event orientationfvgnh .pptxPalestine last event orientationfvgnh .pptx
Palestine last event orientationfvgnh .pptx
RaedMohamed3
 
Overview on Edible Vaccine: Pros & Cons with Mechanism
Overview on Edible Vaccine: Pros & Cons with MechanismOverview on Edible Vaccine: Pros & Cons with Mechanism
Overview on Edible Vaccine: Pros & Cons with Mechanism
DeeptiGupta154
 
The basics of sentences session 5pptx.pptx
The basics of sentences session 5pptx.pptxThe basics of sentences session 5pptx.pptx
The basics of sentences session 5pptx.pptx
heathfieldcps1
 

Recently uploaded (20)

Home assignment II on Spectroscopy 2024 Answers.pdf
Home assignment II on Spectroscopy 2024 Answers.pdfHome assignment II on Spectroscopy 2024 Answers.pdf
Home assignment II on Spectroscopy 2024 Answers.pdf
 
1.4 modern child centered education - mahatma gandhi-2.pptx
1.4 modern child centered education - mahatma gandhi-2.pptx1.4 modern child centered education - mahatma gandhi-2.pptx
1.4 modern child centered education - mahatma gandhi-2.pptx
 
Guidance_and_Counselling.pdf B.Ed. 4th Semester
Guidance_and_Counselling.pdf B.Ed. 4th SemesterGuidance_and_Counselling.pdf B.Ed. 4th Semester
Guidance_and_Counselling.pdf B.Ed. 4th Semester
 
Sha'Carri Richardson Presentation 202345
Sha'Carri Richardson Presentation 202345Sha'Carri Richardson Presentation 202345
Sha'Carri Richardson Presentation 202345
 
How to Make a Field invisible in Odoo 17
How to Make a Field invisible in Odoo 17How to Make a Field invisible in Odoo 17
How to Make a Field invisible in Odoo 17
 
Synthetic Fiber Construction in lab .pptx
Synthetic Fiber Construction in lab .pptxSynthetic Fiber Construction in lab .pptx
Synthetic Fiber Construction in lab .pptx
 
The Accursed House by Émile Gaboriau.pptx
The Accursed House by Émile Gaboriau.pptxThe Accursed House by Émile Gaboriau.pptx
The Accursed House by Émile Gaboriau.pptx
 
Welcome to TechSoup New Member Orientation and Q&A (May 2024).pdf
Welcome to TechSoup   New Member Orientation and Q&A (May 2024).pdfWelcome to TechSoup   New Member Orientation and Q&A (May 2024).pdf
Welcome to TechSoup New Member Orientation and Q&A (May 2024).pdf
 
Model Attribute Check Company Auto Property
Model Attribute  Check Company Auto PropertyModel Attribute  Check Company Auto Property
Model Attribute Check Company Auto Property
 
Operation Blue Star - Saka Neela Tara
Operation Blue Star   -  Saka Neela TaraOperation Blue Star   -  Saka Neela Tara
Operation Blue Star - Saka Neela Tara
 
Francesca Gottschalk - How can education support child empowerment.pptx
Francesca Gottschalk - How can education support child empowerment.pptxFrancesca Gottschalk - How can education support child empowerment.pptx
Francesca Gottschalk - How can education support child empowerment.pptx
 
Phrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXX
Phrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXXPhrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXX
Phrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXX
 
CLASS 11 CBSE B.St Project AIDS TO TRADE - INSURANCE
CLASS 11 CBSE B.St Project AIDS TO TRADE - INSURANCECLASS 11 CBSE B.St Project AIDS TO TRADE - INSURANCE
CLASS 11 CBSE B.St Project AIDS TO TRADE - INSURANCE
 
2024.06.01 Introducing a competency framework for languag learning materials ...
2024.06.01 Introducing a competency framework for languag learning materials ...2024.06.01 Introducing a competency framework for languag learning materials ...
2024.06.01 Introducing a competency framework for languag learning materials ...
 
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
 
Chapter 3 - Islamic Banking Products and Services.pptx
Chapter 3 - Islamic Banking Products and Services.pptxChapter 3 - Islamic Banking Products and Services.pptx
Chapter 3 - Islamic Banking Products and Services.pptx
 
Embracing GenAI - A Strategic Imperative
Embracing GenAI - A Strategic ImperativeEmbracing GenAI - A Strategic Imperative
Embracing GenAI - A Strategic Imperative
 
Palestine last event orientationfvgnh .pptx
Palestine last event orientationfvgnh .pptxPalestine last event orientationfvgnh .pptx
Palestine last event orientationfvgnh .pptx
 
Overview on Edible Vaccine: Pros & Cons with Mechanism
Overview on Edible Vaccine: Pros & Cons with MechanismOverview on Edible Vaccine: Pros & Cons with Mechanism
Overview on Edible Vaccine: Pros & Cons with Mechanism
 
The basics of sentences session 5pptx.pptx
The basics of sentences session 5pptx.pptxThe basics of sentences session 5pptx.pptx
The basics of sentences session 5pptx.pptx
 

C11-1 CASE STUDY 11 CLOUD COMPUTING (IN)SECURITY .docx

  • 1. C11-1 CASE STUDY 11 CLOUD COMPUTING (IN)SECURITY Cloud computing is reshaping enterprise network architectures and infrastructures. It refers to applications delivered as services over the Internet as well as the hardware and systems software in data centers that provide those services. The services themselves have long been referred to as Software as a Service (SaaS) which had its roots in Software- Oriented Architecture (SOA) concepts that began shaping enterprise network roadmaps in the early 2000s. IaaS (Infrastructure as a Service) and PaaS (Platform as a Service) are other types of cloud computing services that are
  • 2. available to business customers. Cloud computing fosters the notion of computing as a utility that can be consumed by businesses on demand in a manner that is similar to other services (e.g. electricity, municipal water) from traditional utilities. It has the potential to reshape much of the IT industry by giving businesses the option of running business software applications fully on-premises, fully in “the cloud” or some combination of these two extremes. These are choices that businesses have not had until recently and many companies are still coming to grips with this new computing landscape. Security is important to any computing infrastructure. Companies go to great lengths to secure on-premises computing systems, so it is not surprising that security looms as a major consideration when augmenting or replacing on-premises systems with cloud services. Allaying security
  • 3. C11-2 concerns is frequently a prerequisite for further discussions about migrating part or all of an organization’s computing architecture to the cloud. Availability is another major concern: “How will we operate if we can’t access the Internet? What if our customers can’t access the cloud to place orders?” are common questions [AMBR10]. Generally speaking, such questions only arise when businesses contemplating moving core transaction processing, such as ERP systems, and other mission critical applications to the cloud. Companies have traditionally demonstrated less concern about migrating high maintenance applications such as e-mail and payroll to cloud service providers even though such applications hold sensitive information.
  • 4. Security Issues and Concerns Auditability is a concern for many organizations, especially those who must comply with Sarbanes-Oxley and/or Health and Human Services Health Insurance Portability and Accountability Act (HIPAA) regulations [IBM11]. The auditability of their data must be ensured whether it is stored on- premises or moved to the cloud. Before moving critical infrastructure to the cloud, businesses should do diligence on security threats both from outside and inside the cloud [BADG11]. Many of the security issues associated with protecting clouds from outside threats are similar to those that have traditionally faced centralized data centers. In the cloud, however, responsibility for assuring adequate security is frequently shared among users, vendors, and any third- party firms that users rely on for security-sensitive software or configurations. Cloud users are responsible for application-level
  • 5. security. Cloud vendors are responsible for physical security and some software security such as enforcing external firewall policies. Security for intermediate layers of the software stack is shared between users and vendors. C11-3 A security risk that can be overlooked by companies considering a migration to the cloud is that posed by sharing vendor resources with other cloud users. Cloud providers must guard against theft or denial- of-service attacks by their users and users need to be protected from one another. Virtualization can be a powerful mechanism for addressing these potential risks because it protects against most attempts by users to attack one another or the provider’s infrastructure. However, not all resources are
  • 6. virtualized and not all virtualization environments are bug-free. Incorrect virtualization may allow user code to access to sensitive portions of the provider’s infrastructure or the resources of other users. Once again, these security issues are not unique to the cloud and are similar to those involved in managing non-cloud data centers, where different applications need to be protected from one another. Another security concern that businesses should consider is the extent to which subscribers are protected against the provider, especially in the area of inadvertent data loss. For example, in the event of provider infrastructure improvements, what happens to hardware that is retired or replaced? It is easy to imagine a hard disk being disposed of without being properly wiped clean of subscriber data. It is also easy to imagine permissions bugs or errors that make subscriber data visible to
  • 7. unauthorized users. User-level encryption may be an important self-help mechanism for subscribers, but businesses should ensure that other protections are in place to avoid inadvertent data loss. Addressing Cloud Computer Security Concerns Numerous documents have been developed to guide business thinking about the security issues associated with cloud computing. Even NIST has weighed in on these issues [BADG11]. NIST’s recommendations systematically consider each of the major types of cloud services consumed C11-4 by businesses including Software as a Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS). While security issues vary somewhat depending on the type of cloud service, there are multiple NIST
  • 8. recommendations that are independent of service type. Several of these are summarized in Table C11.1. Not surprisingly, NIST recommends selecting cloud providers that support strong encryption, have appropriate redundancy mechanisms in place, employ authentication mechanisms, and offer subscribers sufficient visibility about mechanisms used to protect subscribers from other subscribers and the provider. As more businesses incorporate cloud services into their enterprise network infrastructures, cloud computing security will persist as an important issue. Examples of cloud computing security failures have to potential to have a chilling effect on business interest in cloud services and this is inspiring service providers to be serious about incorporating security mechanisms that will allay concerns of potential subscribers. Some service
  • 9. providers have moved their operations to Tier 4 data centers to address user concerns about availability and redundancy. Because so many businesses remain reluctant to embrace cloud computing in a big way, cloud service providers will have to continue to work hard to convince potential customers that computing support for core business processes and mission critical applications can be moved safely and securely to the cloud [HEAV11]. Discussion Points 1. Do some Internet research to identify businesses who have suffered because of cloud security weaknesses or failures. What can companies who are contemplating cloud computing services learn from the negative experiences of these businesses? 2. Do some Internet research on security mechanisms associated with virtualization. How can virtualization be used by cloud service providers to protect subscriber data?
  • 10. C11-5 3. Choose one of the following cloud services categories: SaaS, IaaS, PaaS. Do some Internet research that focuses the security issues associated with the selected cloud service category. Summarize the major security risks associated with the cloud service category and identify mechanisms that can be used to address these risks. Sources [ARMB10] Armbrust, M., Fox, A., Griffith, R, Joseph, A.D., Katz, R., Konwinski, A., Lee, G., Patterson, D., Rabkin, A., Stoica, I., and Zaharia, M. “A View of Cloud Computing.” Communications of the ACM, Vol. 53, No. 4, April 2010, pp. 50-58. [BADG11] Badger, L., Grance, T., Patt-Comer, R., and Voas, J. Draft Cloud Computing Synopsis and Recommendations: Recommendations of the National Institute of Standards and Technology, Special Publication 800-146, May 2011. [HEAV11] Heavey, J. “Cloud Computing: Secure or Security Risk?” Technorati.com, November 28, 2011. Retrieved online from:
  • 11. http://technorati.com/technology/cloud-computing/article/cloud- computing- secure-or-a-security1/. [IBM11] IBM Global Technology Services. Security and Availability in Cloud Computing Environments, Technical White Paper, June 2011. http://technorati.com/technology/cloud-computing/article/cloud- computing-secure-or-a-security1/ http://technorati.com/technology/cloud-computing/article/cloud- computing-secure-or-a-security1/ C11-6 CASE STUDY 11Security Issues and ConcernsAddressing Cloud Computer Security ConcernsDiscussion PointsSources