Cyberstudy
PDF p.169 In progress

Cloud Security Considerations

Open PDF at p.169 14 flashcards

Summary

PDF p.169

Cloud security involves protecting data and applications stored outside an organization's private infrastructure. Key considerations include data protection, patching, secure communication, and access. Technologies like SD-WAN and SASE enhance security by providing encryption, intelligent routing, and centralized management.

In plain words

Supplementary — not from your PDF

Cloud security covers protecting data (access control, encryption, disaster recovery plans), patching (with less control over the underlying platform), and secure communication and access. SD-WAN securely links branches, datacenters and cloud with encryption and central policy. SASE combines networking with cloud-delivered security (IPS, malware protection, content filtering) under a zero trust, identity-based model.

Detailed explanation

PDF p.169
  • Data Protection
    • Definition: Ensuring data and applications stored on the cloud are secure.
    • Precautions: Use access controls and encryption to protect data.
    • Disaster Recovery: Develop plans to respond to catastrophic events impacting cloud resources.
  • Patching
    • Policy: Cloud providers should have clear patch management policies.
    • Features: Automated patch management, regular updates, centralized management, security monitoring.
    • Challenges: Complexity of cloud systems, lack of control over underlying infrastructure, legal and regulatory requirements.
  • Secure Communication and Access
    • SD-WAN (Software-Defined Wide Area Network)
      • Definition: Connects branch offices, datacenters, and cloud infrastructure over a WAN.
      • Security: Uses encryption, segments network traffic, integrates with firewalls, centralizes security policy management.
    • SASE (Secure Access Service Edge)
      • Definition: Combines WAN technologies and cloud-based security services.
      • Security Model: Operates under a zero trust model, incorporating Identity and Access Management (IAM).
      • Features: Intrusion prevention, malware protection, content filtering, centralized security and access management.

Important terms

taken from the text above
Data Protection
Ensuring data and applications stored on the cloud are secure.
Precautions
Use access controls and encryption to protect data.
Disaster Recovery
Develop plans to respond to catastrophic events impacting cloud resources.
Policy
Cloud providers should have clear patch management policies.
SD-WAN (Software-Defined Wide Area Network)
Connects branch offices, datacenters, and cloud infrastructure over a WAN.
SASE (Secure Access Service Edge)
Combines WAN technologies and cloud-based security services.
Security Model
Operates under a zero trust model, incorporating Identity and Access Management (IAM).
IAM Identity and Access Management

Examples & real-world scenarios

Supplementary — not from your PDF
  • Encrypting cloud storage with customer-managed keys.
  • SD-WAN linking 40 branch offices to cloud apps.
  • SASE applying the same web filtering to office and remote users.

Scenario

A company's remote staff connect straight to SaaS apps, bypassing the office firewall. SASE applies security policy in the cloud, wherever the user is.

Common mistakes

Supplementary — not from your PDF
  • Thinking SD-WAN and SASE are the same. SASE adds cloud-delivered security services and zero trust.
  • Forgetting legal and regulatory constraints on cloud patching and data location.

Practical skills

Supplementary — not from your PDF
  • Recommend SD-WAN or SASE for a scenario.

What I should remember

Key Points PDF p.169
  • Data Protection
    • Access Controls: Essential for securing data.
    • Encryption: Protects data in transit and at rest.
    • Disaster Recovery: Plans for catastrophic events.
  • Patching
    • Clear Policies: Regular and responsive patch management.
    • Automated Management: Reduces manual intervention.
    • Challenges: Complexity and control issues.
  • Secure Communication and Access
    • SD-WAN
      • Encryption: Protects data across the network.
      • Traffic Segmentation: Prioritizes critical data.
      • Firewall Integration: Enhances threat protection.
      • Centralized Management: Simplifies policy enforcement.
    • SASE
      • Zero Trust Model: Assumes all users/devices are untrusted until authenticated.
      • IAM Integration: Manages identities and access.
      • Threat Prevention: Intrusion prevention, malware protection, content filtering.