6: 5 Cloud Security Controls Flashcards
Network Security Groups
Takes place of firewall to segment networks in an IaaS
Who controls firewalls in a cloud environment
Cloud Providers
Network Security Groups
Control traffic that passes from internet to system, for the customer
Cloud Controls
can map directly to on-prem security controls sometimes, sometimes are unique
TLS
Transport Layer Security - Encrypts data in transit
Full Disk Encryption
Encrypts data at rest
Application Virtualization
Centralizes sensitive data
Secure Web Gateway
Filters web traffic - allows users to surf the web safely
Defense in-depth
Having controls overlap so that if one fails, another one can cover that scope.
Cloud-Native Controls
Security controls offered by cloud provider, tightly integrated with provider’s service offerings.
Third-Party Controls
Security controls offered by third-party vendors that integrate with cloud providers through their API, may work across multiple cloud platforms
Resource Policy
Limits Cloud service usage
Transit Gateway
Links on premises and cloud networks (secure connections, cloud routers that provide strongly encrypted connections)
Secret Management
Protects keys and other credentials