10
SECURITY IN THE CLOUD By: Fred Rathweg Instructor: Charlie O’Neal SECR5000 Security Management Sunday, February 28, 2010

Security In The Cloud Timed

  • Upload
    rathweg

  • View
    1.254

  • Download
    1

Embed Size (px)

DESCRIPTION

 

Citation preview

Page 1: Security In The Cloud Timed

SECURITY IN THE CLOUD

By: Fred Rathweg

Instructor: Charlie O’Neal

SECR5000 Security Management

Sunday, February 28, 2010

Page 2: Security In The Cloud Timed

2

What is cloud computing

It is not so simple a question. The internet has seen exponential growth in the last decade to bring us to today where everyone is connecting on a global scale. In the past business had their data in house in the company data center and only had to worry about physical security Today business pressures are mounting to exploit the financial benefits of cloud computing.

Security in the Cloud by Fred Rathweg Webster University (SECR5000 Security Management - Instructor: Charlie O’Neal)

04/10/2023

Page 3: Security In The Cloud Timed

3

Definitions of cloud computing

04/10/2023

Security in the Cloud by Fred Rathweg Webster University (SECR5000 Security Management - Instructor: Charlie O’Neal)

Cloud computing is a general term for anything that involves delivering hosted services over the Internet. These services are broadly divided into three categories:

Software-as-a-Service (SaaS).

Platform-as-a-Service (PaaS),

Infrastructure-as-a-Service (IaaS),

Cloud solutions includes these technologies but is more comprehensive.

Page 4: Security In The Cloud Timed

4

ANATOMY OF A CLOUD04/10/2023

Security in the Cloud by Fred Rathweg Webster University (SECR5000 Security Management - Instructor: Charlie O’Neal)

The application services layer hosts applications that fit the SaaS model.

Platform services provide application infrastructure based on demand (Amazon Web Services and Google Apps).

The bottom layer of the cloud are physical assets such as servers, network devices, and storage. Virtualization, as with platform services, provides on-demand resources.

Page 5: Security In The Cloud Timed

5

Public and Private Clouds

Public clouds are cloud services provided by a third party (vendor). They exist beyond the company firewall, and they are fully hosted and managed by the cloud provider. Amazon Web Services is the largest public cloud provider

Security in the Cloud by Fred Rathweg Webster University (SECR5000 Security Management - Instructor: Charlie O’Neal)

04/10/2023

Page 6: Security In The Cloud Timed

6

Why cloud computing?04/10/2023

Security in the Cloud by Fred Rathweg Webster University (SECR5000 Security Management - Instructor: Charlie O’Neal)

It's now feasible to open a business in the cloud without having to purchase a single piece of hardware. The entrepreneurial CIO is already looking at ways to take advantage. The opportunity to achieve the truly flexible, agile, cheap, manageable, e-business has arrived.

But is it all secure?

Page 7: Security In The Cloud Timed

04/10/2023 7

Google to enlist NSA to help it ward off cyber attacks

Security in the Cloud by Fred Rathweg Webster University (SECR5000 Security Management - Instructor: Charlie O’Neal)

On Jan. 12, 2010 Google said that its systems and 34 other large tech, defense, energy, financial and media companies had been hacked in a series of intrusions beginning in December.

The Gmail accounts of human rights activists in Europe, China and the United States were also compromised. Google’s future in China is in question depending on the outcome of the talks

04/10/2023

Page 8: Security In The Cloud Timed

8

Broad New Hacking Attack Detected A global offensive snagged corporate and personal data at nearly 2,500 companies and the operation is still running. The Department of Homeland Security said that ZeuS was among the top five malware infections.

Security in the Cloud by Fred Rathweg Webster University (SECR5000 Security Management - Instructor: Charlie O’Neal)

04/10/2023

Page 9: Security In The Cloud Timed

9

Where are the wholes in the cloud?There are 7 security risks in

cloud computing for the enterprise that an entrepreneurial CIO should assess before entering the cloud arena.

1.Data integrity and segregation.

2.Data location. 3.Recovery, 4.Privacy5.Investigative support.6.Regulatory compliance, 7.Auditing

Security in the Cloud by Fred Rathweg Webster University (SECR5000 Security Management - Instructor: Charlie O’Neal)

04/10/2023

Page 10: Security In The Cloud Timed

Conclusion:

There are many reasons why companies shift toward a cloud computing solution.

Increase Return On Investment, Increase Cash Flow Increased value for the stockholders.

Security is more cost-effective in the cloud.

04/10/2023

Security in the Cloud by Fred Rathweg Webster University (SECR5000 Security Management - Instructor: Charlie O’Neal)10