Shared Responsibility Flashcards
Describe Shared Responsibility Model in Cloud Computing WRT Security
Security of the cloud is the CSPs responsibility
Security in the cloud is the CSCs responsibility
Who’s responsibility is it to provide Physical Security in Cloud relative to service models?
IaaS, PaaS and SaaS - All CSP
Who’s responsibility is it to provide Infrastructure Security in Cloud relative to service models?
IaaS - Shared Responsibility
PaaS and SaaS - CSP
Who’s responsibility is it to provide Platform Security in Cloud relative to service models?
IaaS - Customer
PaaS - Shared
SaaS - CSP
Who’s responsibility is it to provide Application Security in Cloud relative to service models?
IaaS - Customer
PaaS - Customer
SaaS - Shared
Who’s responsibility is it to provide Data Security in Cloud relative to service models?
IaaS, PaaS and SaaS - All Customer
Who’s responsibility is it to provide Governance, Risk and Compliance in Cloud relative to service models?
IaaS, PaaS and SaaS - All Customer
Who’s responsible for Physical Networks in Cloud relative to service models?
IaaS, PaaS, SaaS - All CSP
Who’s responsible for Servers and Storage in Cloud relative to service models?
IaaS, PaaS, SaaS - All CSP
Who’s responsible for Hypervisor in Cloud relative to service models?
IaaS, PaaS, SaaS - All CSP
Who’s responsibile for Virtual Networks in Cloud relative to service models?
IaaS - Customer
PaaS, SaaS - CSP
Who’s responsibility is the Operating System in Cloud relative to service models?
IaaS - Customer
PaaS, SaaS - CSP
Who’s responsibility is the Application in Cloud relative to service models?
IaaS, PaaS - Customer
SaaS - CSP
Who’s responsible for Data in Cloud relative to service models?
IaaS, PaaS, SaaS - Customer
Who’s responsible for what people do in Cloud relative to service models?
IaaS, PaaS, SaaS - Customer
What are the Shared Responsibility items between the CSP and CSC?
- Auditability
- Availability
- Compliance
- Governance
- Interoperability
- Maintenance & Versioning
- Performance
- Portability
- Privacy
- Protection of PII
- Regulatory
- Resiliency
- Reversibility
- Security
- Service-Levels
What does Auditability mean in the context of Shared Responsibility in the cloud between CSP and CSC?
Giving senior management assurance and evidence that we are doing things the correct way or due dligence.
What does Compliance mean in the context of Shared Responsibility in the cloud between CSP and CSC?
A business requirement to conform to relevant laws, internal governance and external regulations. ex. PCI-DSS, HIPAA, FISMA, SOX
What does Governance mean in the context of Shared Responsibility in the cloud between CSP and CSC?
Relating to processes and decisions, the business is defining actions, assigning roles and responsibilities and verifying performance.
After migration to the cloud, there may be a need to revise procedures, processes, and activities.
What does Interoperability mean in the context of Shared Responsibility in the cloud between CSP and CSC?
The requirement of all the cloud components to work together to achieve the intended goal. These components need to be replaceable by new/different components from different providers and continue to work. Just as the exchange of data between systems should as well.
What does Maintenance and Versioning mean in the context of Shared Responsibility in the cloud between CSP and CSC?
Maintenance refers to maintaining, upgrading, or fixing cloud services
Versioning refers to the CSP provides proper labeling of a service to the cloud service customer, so the customer knows what particular version is being used.
What does Resiliency mean in the context of Shared Responsibility in the cloud between CSP and CSC?
The cloud data center and its components’ ability to continue to operate in the event of a disruption e.g. equipment failure, power outage, natural disaster
What does Security mean in the context of Shared Responsibility in the cloud between CSP and CSC?
Security is the biggest concern for using the cloud and must be shared responsibility
Cloud Service Agreement (CSA)
Describes the relationship between the provider and the customer that the customer must agree to
Should include explicit definitions of the roles and responsibilities and execution of processes
Provided by the CSP to the cloud customer