Unit 3: Risk Assessment Flashcards
Policy and Organization Risk example
- Loss of Governance - which refers to the consumer not being able to implement all required contorls. This can lead to the consumers not realizing their required level of security
Technical Risk example
The consolidation of IT infrastructure leads to consolidation risks, where a single point of failure can have a bigger impact.
Virtualization Risk example
The portability of images and snapshots makes us forget that they can contain sensitive information and need protecting.
Specific Technical Risks Example
Management plane breach - arguably, the most important risk is management plane (management interface) compromise (breach). Malicious users, whether internal or external, can impact the entire infrastructure that is controlled by the management interface.
Legal Risks example
Cloud customers may have legal requirementws on the way they protect data, in particular personally identifiable data. The contorls and actions of the cloud provider may not be sufficient for the customer.
Non-cloud Specific Risks example
natural disasters, unauthorized facility access etc.