Cloud Security Considerations
Summary
PDF p.169Cloud security involves protecting data and applications stored outside an organization's private infrastructure. Key considerations include data protection, patching, secure communication, and access. Technologies like SD-WAN and SASE enhance security by providing encryption, intelligent routing, and centralized management.
In plain words
Supplementary — not from your PDFCloud security covers protecting data (access control, encryption, disaster recovery plans), patching (with less control over the underlying platform), and secure communication and access. SD-WAN securely links branches, datacenters and cloud with encryption and central policy. SASE combines networking with cloud-delivered security (IPS, malware protection, content filtering) under a zero trust, identity-based model.
Detailed explanation
PDF p.169-
Data Protection
- Definition: Ensuring data and applications stored on the cloud are secure.
- Precautions: Use access controls and encryption to protect data.
- Disaster Recovery: Develop plans to respond to catastrophic events impacting cloud resources.
-
Patching
- Policy: Cloud providers should have clear patch management policies.
- Features: Automated patch management, regular updates, centralized management, security monitoring.
- Challenges: Complexity of cloud systems, lack of control over underlying infrastructure, legal and regulatory requirements.
-
Secure Communication and Access
-
SD-WAN (Software-Defined Wide Area Network)
- Definition: Connects branch offices, datacenters, and cloud infrastructure over a WAN.
- Security: Uses encryption, segments network traffic, integrates with firewalls, centralizes security policy management.
-
SASE (Secure Access Service Edge)
- Definition: Combines WAN technologies and cloud-based security services.
- Security Model: Operates under a zero trust model, incorporating Identity and Access Management (IAM).
- Features: Intrusion prevention, malware protection, content filtering, centralized security and access management.
-
SD-WAN (Software-Defined Wide Area Network)
Important terms
taken from the text above- Data Protection
- Ensuring data and applications stored on the cloud are secure.
- Precautions
- Use access controls and encryption to protect data.
- Disaster Recovery
- Develop plans to respond to catastrophic events impacting cloud resources.
- Policy
- Cloud providers should have clear patch management policies.
- SD-WAN (Software-Defined Wide Area Network)
- Connects branch offices, datacenters, and cloud infrastructure over a WAN.
- SASE (Secure Access Service Edge)
- Combines WAN technologies and cloud-based security services.
- Security Model
- Operates under a zero trust model, incorporating Identity and Access Management (IAM).
Examples & real-world scenarios
Supplementary — not from your PDF- Encrypting cloud storage with customer-managed keys.
- SD-WAN linking 40 branch offices to cloud apps.
- SASE applying the same web filtering to office and remote users.
Scenario
A company's remote staff connect straight to SaaS apps, bypassing the office firewall. SASE applies security policy in the cloud, wherever the user is.
Common mistakes
Supplementary — not from your PDF- Thinking SD-WAN and SASE are the same. SASE adds cloud-delivered security services and zero trust.
- Forgetting legal and regulatory constraints on cloud patching and data location.
Practical skills
Supplementary — not from your PDF- Recommend SD-WAN or SASE for a scenario.
What I should remember
Key Points PDF p.169-
Data Protection
- Access Controls: Essential for securing data.
- Encryption: Protects data in transit and at rest.
- Disaster Recovery: Plans for catastrophic events.
-
Patching
- Clear Policies: Regular and responsive patch management.
- Automated Management: Reduces manual intervention.
- Challenges: Complexity and control issues.
-
Secure Communication and Access
-
SD-WAN
- Encryption: Protects data across the network.
- Traffic Segmentation: Prioritizes critical data.
- Firewall Integration: Enhances threat protection.
- Centralized Management: Simplifies policy enforcement.
-
SASE
- Zero Trust Model: Assumes all users/devices are untrusted until authenticated.
- IAM Integration: Manages identities and access.
- Threat Prevention: Intrusion prevention, malware protection, content filtering.
-
SD-WAN