Cloud Due Diligence Overview Flashcards
Cloud Due Diligence
-Cloud security for third parties is often the most important for executive leadership to understand for cyber professionals to review.
-You are trusting your data and processes to run outside your systems and environment.
-Reviewing cloud security controls can include a bit more than what is provided to you on an information security questionnaire (as your organization has a role to play within a shared responsibility model).
-Therefore, it is important to specially discuss cloud due diligence.
Cloud Due Diligence Overview
-Define Cloud
-Shared Responsibility Model
-Security Reporting
-Patterns
-Cloud Software
Cloud
Definition
-Your data stored by a third party and accessible over the internet.
-Anything that is no in your data center, not in your network. Could be in a Co-Lo facility CSP
CSP - Cloud Service Provider
Types of Cloud
-Concentration Risk
-Shared Responsibility Model
Types of Cloud:
-Concentration Risk
-Large number of SaaS products running in the US east
Types of Cloud:
-Shared Responsibility Model
-Cloud service provider is essentially a 4th party