Chapter 8 - Security in Cloud Computing Flashcards
Infrastructure as a Service (IAAS)
good choice for day to day infrastructure and for temporary or experimental workloads that change unexpectedly
Typically paid for on a per-use basis
Platform as a Service (PAAS)
geard to software development. Provides development platform so subscribers don’t have to build their own infrastructure
Software as a Service (SAAS)
provides on-demand applications to subscribers over the internet (like Salesforce).
removes headaches of patch management and security , administration, version control
4 deployment models for the cloud
public
private
community
hybrid
public cloud
services are provided over a public network like the internet
used when security and compliance requirements aren’t a major issue
private cloud
operated solely for a single organization, usually not pay-as-you-go. Hardware is dedicated, compliance more easily met
community cloud
infrastructure is shared by multiple organizations, usually with same compliance and policy considerations.
hybrid cloud
2 or more of the cloud deployment models
NIST Publication 500-292
Cloud Computing Reference Architecture
Defines 5 Major Roles in a cloud architecture
cloud carrier
cloud consumer
cloud provider
cloud broker
cloud auditor
cloud carrier
provides connectivity between subscriber and provider
responsible for transferring data
cloud consumer
entity that acquires and uses cloud products and services
cloud provider
provider of products and services
cloud broker
acts as intermediary between consumer and provider, helps consumers through complexity of cloud service offerings
cloud auditor
conducts independent performance and security monitoring of cloud services
FedRAMP
Federal Risk and Authorization Mgmt Program
government program that provides standardized approach to security assessment, authorization, continuous monitoring for cloud products and services