Cybersecurity Governance: Cloud Security

UT DALLAS Cybersecurity Governance

Course Information

  • Course Code: ITSS 4362

  • Topic: Cloud Security

  • Instructor: Professor Khan

Introduction

  • Learning Objectives:

    • Understand and apply Cloud Technology:

    • Definition of Cloud Technology

    • Application methods

    • Advantages and disadvantages

    • Understand and apply Cloud Security Principles:

    • Key security concepts

    • Strategies for protection

    • Identification of threat vectors

Cloud Computing

  • Definition:

    • Cloud computing refers to the on-demand availability of computer system resources, particularly data storage and computing power, without users having to engage in active management.

    • It is characterized by the accessibility of data centers for multiple users over the Internet.

Cloud Computing Potential Advantages

  • Increased Reliability:

    • Duplicated data, comprehensive logs, and superior maintenance practices improve reliability.

  • Reduction in IT Operating Costs:

    • Pay-as-you-go model decreases overhead costs.

  • Scalability and Agility:

    • Resource allocation can easily adjust to meet user demand.

  • Ubiquitous Accessibility:

    • Services can be accessed over the Internet from any device, enhancing convenience and flexibility.

  • Levels the Playing Field:

    • Small and large businesses can leverage the same resources.

  • Fast Request-driven Provisioning:

    • On-demand resource availability to handle immediate needs.

  • Improved Collaboration:

    • Enables seamless teamwork through shared resources.

  • Security:

    • Potentially enhanced security due to professional management and infrastructure.

Cloud Computing Potential Disadvantages

  • Governance Challenges:

    • Difficulty in establishing clear governance frameworks for cloud operations.

  • Unclear Documentation:

    • Lack of clear specifications can lead to confusion.

  • Vendor Lock-in:

    • Challenges associated with migrating away from a cloud service provider.

  • Limited User Control:

    • Users have reduced visibility and direct management of their data and resources.

  • Security Challenges:

    • Concerns regarding the security of data and applications in the cloud.

Security Advantages of Using the Cloud

  • Platform Unity:

    • Similar applications and resources come from a unified source, enhancing coherence.

  • Platform Strength:

    • Robust infrastructure and protocols safeguard against threats.

  • Specialized Technical Resources:

    • Access to specialized know-how and technologies that might not be feasible in-house.

  • Resource Availability:

    • Continuous resource availability through managed environments.

  • Backup and Recovery Processes:

    • Established procedures to protect data integrity and availability.

  • Uniform, Secured Endpoints:

    • Consistent security measures across devices allow for easier management.

  • Data Concentration for Mobile Users:

    • Centralized data access simplifies mobility for users.

What Comprises Cloud Computing?

  • NIST Definition of Cloud Computing:

    • Five Essential Characteristics:

    1. On-Demand Self-Service

    2. Broad Network Access

    3. Resource Pooling

    4. Rapid Elasticity

    5. Measured Service

    • Three Cloud Service Models:

    • Software as a Service (SaaS)

    • Platform as a Service (PaaS)

    • Infrastructure as a Service (IaaS)

    • Four Cloud Deployment Models:

    • Public

    • Private

    • Hybrid

    • Community

Elements of Cloud Computing

  • Five Cloud Computing Elements:

    1. Broad Network Access:

    • Capabilities accessible over the network through standard mechanisms.

    1. Rapid Elasticity:

    • Ability to rapidly adjust resources in response to service demands.

    1. Measured Service:

    • Automatic control and optimization of resource usage through metering capabilities.

    1. On-Demand Self-Service:

    • Consumers can provision computing capabilities as needed without human interaction from the service provider.

    1. Resource Pooling:

    • Computing resources are pooled to serve multiple consumers using a multitenant model, with dynamic resource assignment based on demand.

Cloud Service Models

  • Infrastructure as a Service (IaaS):

    • Provides fundamental computing resources such as processing, storage, and networks on a pay-per-use basis.

  • Platform as a Service (PaaS):

    • Offers a platform and solution stack allowing customers to develop, run, and manage applications without dealing with infrastructure complexities.

  • Software as a Service (SaaS):

    • Delivers software applications over the internet, mitigating installation and management responsibilities for users.

Cloud Deployment Models

  • Public Cloud:

    • Operated by third parties, great for rapid scalability but poses greater control challenges.

  • Private Cloud:

    • Exclusive to single organizations, offering more control and customization.

  • Hybrid Cloud:

    • Combines public and private resources for flexibility in data management and regulatory compliance.

  • Community Cloud:

    • Shared infrastructure among multiple organizations with similar interests or compliance requirements.

Market Insights

  • Market Domination:

    • As of Q4 2021, AWS holds 33% of the market share in cloud infrastructure, followed by Azure (21%), Google Cloud (10%), and others.

Challenges in Cloud Computing Adoption

  • Uncertainty and Lack of Control:

    • Users operate within a metaphorical black box without insight into cloud operations.

  • Malicious Actors and Threats:

    • Potential internal threats from employees and external attacks can compromise integrity and confidentiality.

Security Threats to Consider

  • Loss of Control:

    • Clients relinquish management of resources to providers, including user identities and access policies.

  • Taxonomy of Fear:

    • Confidentiality: Concerns over data exposure and breach of sensitive information.

    • Integrity: Questions about the accuracy of computations performed by cloud providers.

    • Availability: Risks of service disruption affecting client operations.

Model for Holistic Cloud Security

  • Key Components:

    • Logical segmentation, configuration hardening, access controls, secondary approvals, key management, encryption, user behavior analytics.

Addressing Cloud Security Issues

  • Core Delivery Models:

    • Individual responsibility levels vary across service models (SaaS, PaaS, IaaS).

    • Security responsibility shifts more towards providers as the service layer abstraction increases.

The Notorious Nine Threats Identified by CSA

  1. Data Breaches

  2. Data Loss

  3. Account Hijacking

  4. Insecure APIs

  5. Denial of Service

  6. Malicious Insiders

  7. Abuse of Cloud Services

  8. Insufficient Due Diligence

  9. Shared Technology Issues

Threat Mitigation Strategies

  • Data Loss Remediation:

    • Implementation of strong access controls and robust encryption practices.

  • Account Hijacking Prevention:

    • Strong password policies and multi-factor authentication.

  • API Security:

    • Analyze provider API security models and enforce strong access controls.

  • Denial of Service Mitigation:

    • Employ anomaly detection mechanisms for traffic control.

  • Insider Threats Management:

    • Contractual security specifications for personnel working with clouds.

  • Abuse Mitigation:

    • Strict registration, monitoring, and fraud prevention practices.

  • Due Diligence:

    • Comprehensive understanding and continuous monitoring of the cloud provider’s security organizational environment.

  • Shared Technology Security:

    • Implement stringent access controls, continuous vulnerability assessments, and environment monitoring to protect shared resources.

Conclusion

  • Future Outlook:

    • Cloud computing and security form a rapidly evolving field with complex challenges and strong growth potential. Solid information security practices are essential for mitigating the risks associated with loss of control, trust deficits, and multi-tenancy issues.