Exhaustive Guide to Cloud Computing, Information Security, and Enterprise Systems

Fundamentals of Cloud Computing and Deployment Models

Cloud computing is defined as a model that allows access from anywhere and at any time to a shared group of computing resources, including networks, servers, storage, and applications. These resources are provisioned and distributed with minimal management effort by the service provider. The essential characteristics of this model include broad network access, elasticity and rapidity, supervised service, on-demand self-service, and the pooling of resources.

There are three primary service models within cloud computing. Infrastructure as a Service (IaaS) involves the provider granting access to servers, storage, and networks while the client companies utilize their own platforms and applications. Platform as a Service (PaaS) allows users to develop, manage, and distribute applications; the provider offers a suite of tools for developing, customizing, and testing these applications. Software as a Service (SaaS) removes the need for users to install applications on their devices, as access is provided via the web or through an API for data storage and analysis. This model also facilitates having the application synchronized across all devices simultaneously.

Deployment models categorize how the cloud is hosted and accessed. Public clouds involve resources shared among users from different organizations, offering less margin for customization and being managed entirely by the provider. Private clouds consist of resources assigned to and administered by a single organization. Community clouds involve multiple organizations sharing the same infrastructure. Hybrid clouds are a combination of public and private cloud services; while their administration is more complex, they allow for specific security management and offer cost advantages.

Data Center Infrastructure and Information Storage Strategies

Data centers (DC) are specialized facilities designed to house critical computing resources. They prioritize security by utilizing maximum security measures to monitor access and guarantee a completely protected space. Power supply is maintained through the use of generating sets (grupos electrógenos) to ensure continuity. Furthermore, they maintain a controlled environment with air conditioning systems running 2424 hours a day to guarantee the correct operation of servers.

In terms of services offered within a data center, Housing or Co-location refers to providing space in the DC so the client can install their own servers. Hosting involves providing space on a server that is owned by the provider. Companies generally have three ways to store and process information: On-premise (on the company's own site), Co-located (the company's equipment located in a third-party data center), or Cloud computing (everything hosted in the cloud).

When migrating to the cloud, several aspects must be considered. A strategy must be defined by analyzing advantages and disadvantages. A new culture must be established among people and processes as individuals need to understand and align with the change in paradigm. Technology integration is necessary to identify which technologies will remain valid and how they will integrate. Finally, risk and compliance management must be addressed to handle operations, services, security, and establish adequate control schemes. Crucially, while a provider manages security tasks, the ultimate responsibility for information security lies with the organization.

Objectives and Principles of Information Security

The fundamental objectives of information security are built around five core pillars. Confidentiality is the capacity to guarantee that information stored in a system or transmitted over a network is available only to authorized persons; if intercepted, others should not be able to interpret it. Availability ensures that the system and data are accessible to the user at all times. Integrity guarantees that data has not been modified without authorization since its creation. Non-repudiation ensures the participation of parties in a communication: in origin, the sender cannot deny being the emitter because the receiver has proof of sending; in destination, the receiver cannot deny receipt because the sender has proof of reception. Lastly, Auditability involves the review and evaluation of all aspects of automatic information processing systems, including related non-automatic processes.

Cryptology, Key Models, and Digital Signatures

Cryptology arose from the need to prevent communications from being easily intercepted. Its origins date back to ancient Egypt in the year 20002000 B.C. The term is derived from Kriptos (hidden/occult) and Logos (discourse). Cryptology played a key role during World War I, World War II, and the Cold War, with significant progress made by figures such as Alan Turing. Modern cryptology is increasingly complex, blending physics, mathematics, and computation, but it relies on the same ancient principles.

Key models in cryptology include Symmetric keys, which use identical keys available only to the sender and receiver (viewed as less secure), and Asymmetric (public) keys, where the sender and receiver use different keys. Asymmetric encryption is more advanced and provides high security but is slower. The Hybrid model combines both: it uses asymmetric encryption to share a symmetric key, which provides the security of public keys with the agility of symmetric keys. If an attacker discovers the key in a hybrid system, they can only view one message.

Hash functions take an input such as text, a password, or a file and create a fixed-length alphanumeric output representing a summary of the input. They are unidirectional, meaning the original data cannot be recovered from the hash. Systems often store the hash of a password rather than the password itself for increased security. A Digital Signature is a procedure that authenticates the sender and confirms the message has not been altered. Its properties include being unique (generated only by the signer), unforgeable (requiring the resolution of complex mathematical problems), verifiable by authorities, undeniable by the signer, and viable (easy for the signer to generate).

Security Management, Threats, and Vulnerabilities

Security management seeks to protect and safeguard all processes and resources within information systems, balancing efficient functionality with security norms. Central challenges include viruses, vulnerabilities, contingency policies, and backups. A virus is defined as a software program out of control that is difficult to detect and spreads rapidly. A threat is any danger to which a system is exposed, which can be internal or external, and intentional or unintentional.

Vulnerabilities represent the possibility of a system being damaged by a threat. Key concepts include Hackers (those accessing networks without authorization), Spyware (applications collecting data without knowledge), and Cookies (files storing user info, sometimes transmitted without consent). Other vulnerabilities include Spamming (unsolicited email), Bugs (code defects), and Denial of Service (DoS) attacks, which overwhelm web servers with thousands of communications to take them out of service. Identity theft, Phishing (fake websites for data solicitation), Pharming (redirecting users via DNS modification), and Click fraud (fraudulent ad clicking) are also prominent risks.

Specialized Malware and Social Engineering

Malware types vary in behavior and intent. A Worm is a virus that requires no human intervention, reproducing itself and living in memory to seek out other computer addresses. A Trojan is a program disguised as normal software that grants an attacker integral access to a system through a server installed on the infected machine. Ransomware is malware that blocks a device or encrypts data, with the attacker demanding a cryptocurrency ransom. Adware refers to programs that force users to view advertisements via pop-up windows.

Social Engineering involves social conduct intended to obtain info through deception or manipulation by exploiting feelings of trust, innocence, curiosity, or the desire to collaborate. Phishing is a common social engineering modality where a "phisher" poses as a trusted entity. Scamming involves fake websites offering products or services, often with a sense of urgency. Denegation of Service (DoS) typically consumes bandwidth to cause a loss of connectivity. While a standard DoS comes from a single IP, a Distributed Denial of Service (DDoS) uses many IP addresses simultaneously, making it much harder to detect.

E-commerce Models and Usability

E-commerce is the buying and selling of products or services via the internet. A priority in web design for e-commerce is usability, which ensures pages are easy to use through simple text reading, intuitive navigation, and functional downloads. There are several types of e-commerce: Business to Business (B2B), involving transactions between companies; Business to Consumer (B2C), where price and support are adjusted for the end client; Business to Employee (B2E), intended to improve labor experience and productivity; Consumer to Consumer (C2C), for second-hand sales; and Government to Consumer (G2C), allowing citizens to perform legal procedures online.

Internet technology reduces information asymmetry, which occurs when one party in a transaction has more information than the other. Digital markets allow for dynamic price adjustment based on demand and enable direct sales to consumers, reducing intermediary costs. Revenue models for these platforms include Advertising (content is free, advertisers pay), Sales (selling products or downloads), Subscription (fees for high-value content like Netflix), Freemium (basic services are free, advanced ones cost), and Transaction fees (fees per successful sale, such as Mercadolibre).

Ethical, Social, and Legal Implications

Ethics in information systems refers to the principles of right and wrong that guide behavior. While technology fosters social progress, it also presents threats to privacy and property. Major ethical trends include the fact that computing power doubles every 1818 months, data storage costs are plummeting, and advances in data analysis/networking make profiling and copying personal data easier. Ethical analysis involves identifying facts, defining dilemmas, identifying stakeholders, and assessing options and consequences.

In Argentina, computer crimes are governed by Law 26.38826.388 (Computer Crimes) and Law 11.72311.723 (Legal Regime of Intellectual Property). The Association of Information Technology Professionals (AITP) defines computer crimes as unauthorized access, modification, or destruction of resources, as well as unauthorized software copying or denying a user access to their own data.

Enterprise Applications: ERP and CRM

Enterprise Resource Planning (ERP) systems integrate information across a company, including finance, HR, and supply chain. Historically, these evolved from custom developments in the 19601960s to Material Resource Planning (MRP) in the 19701970s, integrated ERPs in the 19901990s, and collaborative, mobile ERPs in the 20102010s. ERPs automate business processes based on "best practices." Implementation requires hardware, software, connectivity infrastructure, and human resources. Companies often must change their work methods to adapt to the software's predefined processes to avoid performance degradation from excessive customization.

Customer Relationship Management (CRM) aligns corporate strategy around the customer rather than products. It involves dynamic information exchange to understand, anticipate, and satisfy customer needs to generate loyalty. The pillars of CRM are service, marketing, and sales. Implementation failure often stems from a lack of leadership from high management, inadequate corporate culture, or an excessive focus on technology over alignment and training.