CCSP Domain 3: Cloud-Specific Risks Flashcards
The cloud security alliance details the top cloud-specific security threats in what document?
The CSA Egregious 11
What threats does The CSA Egregious 11 contain?
- data breaches
- misconfigured and inadequate change control
- lack of cloud security architecture and strategy
- insufficient identity, credential access and key management
- account hijacking
- insider threat
- insecure interfaces and APIs
- weak control plane
- “metastructure” and “applistructure” failures
- limited cloud usage visibility
- abuse and nefarious use of cloud services
What is a data breach?
loss of sensitive data (PI, PII, PHI, IP) due to a security breach, that is intentional and malicious
What is a data leak?
unintentional loss/oversharing of sensitive data
Which controls help to mitigate insecure interfaces and APIs?
MFA, RBAC, key-based access
What is metastructure?
protocols and mechanisms that provide the interface between the cloud layers, enabling management and configuration
What is applistructure?
applications deployed in the cloud and the underlying application services used to build them
What is applistructure and metastructure failures?
vulnerabilities in the operational capabilities that CSPs make available, like APIs for accessing various cloud services; if CSPs inadequately secure these interfaces, any resulting solutions built on top of those services will inherit these weaknesses