Reference Models Flashcards
What are the (5) Cloud Reference Model standards?
Reference Models … (5)
NIST Cloud Compute Ref IBM Cloud Ref Architecture ISO/IEDC 17789:2014 Ref Architecture Open Group Cloud Eco Sys Ref Model Microsoft Private Cloud Ref Model
InfoSec IS Mgmt includes (5) CIANA
Confidentiality – Encrypt/hide info for unauthorized access
Integrity – Protect from modification/deletion
Availability – Accessible to authorized users
Non-Repudiation – Cant deny actions
Authentication – Prove identity to access
Security Mgmt means?
___ & ____ for securing Mgmt
Policy & Procedures for securing & mgmt
Security Mgmt = (3)
_____ Mgmt
Security _________
_____
RISK MGMT
SECURITY Assessmt
Calculated Return on Investmt (ROI)
Finish the equation: RISK = (3)
Risk = ____ X ____ X _____
RISK = Asset x Threat x Vulnerability
What is an example of Threat? (4)
Angry Employee, Hacker, Malware, Rogue Software
What is an example of Vulnerability? (5)
SW bugs, Broken process, Bad Cntl, HW malfunction, Human error
What is example of Risk: (5)
Fin loss, privacy loss, reputation damage, legal penalties, Business disruption
When you hear Security Assessment, you should think of this word?
AUDIT!
How do you address a Security GAP? (3) choices
- (DENY) Cancel Project
- (Allocate) necessary resources to correct sec gaps
- (Accept) RISK
What are (6) Data Sec Standards?
ISO 27001 – (FISMA) Establish, implement maintain ISMS
ISO 27017 – (Cloud Security) IT Sec/IS Cntl for Cloud
customers and providers
ISO 27018 – (PII) Protection in Cloud –How to protect PII
(PII – Cloud)
ISO 27036 – (Info Risk of Goods/Svcs – Cloud)Supplier
relationships – Overview, Requirements,
ICT Supply chain, Sec, Cloud Svcs
NIST 800-144 (NIST) Guidelines Sec / Privacy in Public
Cloud (NIST Sec/Policy – Cloud)
PCI-DSS – (Payment card Industry) – Data Sec Std- Sec
Assessment Procedure / Cloud Guidelines (Paymt
card Cloud Stds)
Name the (6) Data Standards: ISO 27001 ISO 27017 ISO 27018 ISO 27036 NIST 800-144 PCI-DSS
ISO 27001 FISMA
ISO 27017 IT Sec / IS Control Cloud Customer/providers
ISO 27018 PII - Cloud
ISO 27036 Supplier relationships in Cloud, Svc, Risk
NIST 800-144 NIST Sec / Policy Cloud
PCI-DSS Paymt card Cloud standards and guidelines
What are the International Data Protections? (3) categories
- EU – US Privacy Shield – protects Europeans basic
right when data is transferred to US - USA Patriot ACT – US Law
FISA Foreign Intel Survellience Act
ECPA Electronic Communication Privacy Act
Money Laundering Control Act
Bank Secrecy Act
Immigration National Act - PRISM surveillance data mining program used by
NSA / British Govt
Is Safe Harbor applicable to cloud svc provider agreements?
Yes. Safe Harbor & Commission’s adequacy decision apply to such agreements that involve the transfer of personal data from the EU to org established in US
What is SAFE HARBOR?
EU – US.
European Commission Directive on Data Protection. Oct 1998. Prohibits transfer of personal data to non-European Union countries that don’t meet the (EU) European Union adequacy standard for privacy protection. US & EU share goal. Must join program to participate!