Responsibilities in the Cloud
Goals
- Analyze cloud infrastructure components.
- Analyze risks associated with cloud infrastructure.
- Critique security controls.
- Critique disaster recovery and business continuity management plans.
- Outline the physical infrastructure for the cloud environment.
- Manage the physical infrastructure for the cloud environment.
- Outline the logical infrastructure for the cloud environment.
- Manage the logical infrastructure for the cloud environment.
- Outline compliance requirements with regulations and controls.
- Apply risk assessment to the logical and physical infrastructure.
- Analyze the collection, acquisition, and preservation of digital evidence.
Foundations of Managed Services
Shared Responsibilities by Service Type
- IaaS
- physical security of facility and systems
- provider & customer share responsibility of infrastructure security
- customer is responsible for all other security
- PaaS
- customer shares responsibility for platform security
- customer fully responsible for security of applications, data, risk management
- SaaS
- provider has responsibility for most security