Cloud security considerations

11
Senior Technical Specialist, Microsoft

description

 

Transcript of Cloud security considerations

Page 1: Cloud security considerations

Senior Technical

Specialist, Microsoft

Sheena.Graham
Stamp
Page 2: Cloud security considerations

Abstraction: Hardware Abstraction: Everything

Abstraction: OS

Page 3: Cloud security considerations

On-Premise

Storage

Servers

Networking

O/S

HA/DR

Virtualization

Data

Applications

Runtime

IaaS

Storage

Servers

Networking

O/S

HA/DR

Virtualization

Data

Applications

Runtime

PaaS

Storage

Servers

Networking

O/S

HA/DR

Virtualization

Applications

Runtime

Data

SaaS

Storage

Servers

Networking

O/S

HA/DR

Virtualization

Applications

Runtime

Data

More Less

Page 4: Cloud security considerations
Page 5: Cloud security considerations

Surface Area

Physical Plant

Network/Firewalls

Computing Elements (OS, Runtimes, etc.)

Storage

RDBMS

Bus or Other Access Components

Page 6: Cloud security considerations

Example

Page 7: Cloud security considerations
Page 8: Cloud security considerations

Jane Doe

<Role = Comptroller>

<Role = User>

<Locale = UK>

Page 9: Cloud security considerations

• Physical/Identity

• Certificates/Encryption

• Protocols/Ports

• Viri/spyware/Keyloggers • Encryption Support

• Protocols/Ports

• Firewalls

• Certificate Support

• Encryption Support – Data at rest

• Protocols/Ports

• Firewalls

• Segregation

• Certifications (components)

• Certificates/Encryption

• Protocols/Ports

• Endpoints

• Firewalls

• Certificates/Encryption

• Protocols/Ports

• Viri/spyware/Sniffers

Page 10: Cloud security considerations

Secure Development Lifecycle

Windows and SQL Azure Mitigations

Create Periodic and Automated Reviews

Independent Verifications and Tools

Document Path/Risks, Write tests

Microsoft Data Center Physical Plant and Safeguards

Page 11: Cloud security considerations

Windows Azure Trust Center (Web Search Term)

http://tinyurl.com/27t2bqu (Security References for Azure)

References