| 1 |
Introduction to Cloud Computing and Architectural Concepts |
Section 1: Cloud Computing Terminology<br />Key Cloud Computing Terminology<br />Terminology Mapped to the Cloud<br />Other Terms<br />Section 2: Cloud Computing Definition<br />Cloud Computing Defined<br />NIST Five Essential Characteristics<br />NIST Three Service Models<br />SaaS Pros and Cons<br />PaaS Pros and Cons<br />IaaS Pros and Cons<br />NIST Four Deployment Models<br />Cloud Computing Characteristics<br />Section 3: Cloud Computing Benefits<br />Why move to the Cloud?<br />Cost Benefit Analysis<br />ROI Calculation<br />TCO Calculation<br />Ease of Deployment – Security Risks<br />Introductory Security Risks and Benefits<br />Section 4: Cloud Computing Reference Model<br />Cloud Computing Architecture<br />Potential Pitfalls and Confusion<br />Cloud Computing Deployment Models<br />Jericho Cloud Cube Model<br />Example of Service Model Mapped to Controls<br />Section 5: What is Security for the Cloud<br />The Security Impact of Cloud Architecture<br />Where is the security added?<br />Cloud Technology Road Map<br />NIST Cloud Technology Road Map<br />Cloud Cross<br />Cutting Aspects<br />Architecture Overview<br />Business Security Architecture<br />Jericho Key Principles (11 Commandments)<br />ENISA<br />Questions |
| 2 |
Cloud Risks |
Section 1: Cloud Migration Security Evaluation<br />Challenges in Decision Making Process of Moving to the Cloud<br />Quick Method for Evaluation<br />Evaluate the Asset<br />Map the Asset to Cloud<br />Finalizing the Decision<br />Section 2: ENISA Risk Evaluation<br />ENISA – Cloud Computing Security Risk Assessment<br />ENISA– Top Security Benefits<br />Probability vs. Impact of Identified Risks<br />ENISA– Top Security Risks<br />Top Risks No. 1<br />Top Risks No. 2<br />Top Risks No. 3<br />Top Risks No. 9<br />Top Risks No. 10<br />Top Risks No. 21<br />Top Risks No. 22<br />Top Risks No. 23<br />Top Risks No. 26<br />Assets<br />Section 3: Cloud Controls Matrix<br />Cloud Controls Matrix (CCM)<br />The Control Domains<br />Example<br />Example Continued<br />Section 4: Relevant CCM Controls<br />TVM 01 AntiVirus / Malicious Software<br />TVM 02 Vulnerability and Patch Management<br />TVM 03 Mobile Code<br />Questions |
| 3 |
ERM and Governance |
Section 1: Application of Governance and Risk Management to the Cloud<br />Corporate Governance<br />Customer Expectations<br />Four Areas Impacted<br />Tools of the Trade<br />Who is responsible? Not Accountable!<br />Cloud Computing Governance Resources<br />Information/Data Governance Types<br />Enterprise Risk Management<br />Risk Response in the Cloud<br />Where do we start?<br />Must do items<br />Section 2: Importance of the SLA<br />Contracts/SLAs<br />Contracts/SLAs: Change Your Thinking<br />Important SLA Components<br />Metrics for Risk Management/Service Level Agreement (SLA)<br />Section 3: CCM Relevant Controls<br />GRM-01 – Baseline Requirements<br />GRM-02 – Data Focus Risk Assessments<br />GRM-03 – Management Oversight<br />GRM-04 – Management Program<br />GRM-05 – Management Support/Involvement<br />GRM-06 – Policy<br />GRM-07 – Policy Enforcement<br />GRM-08 – Policy Impact on Risk Assessments<br />GRM-09 – Policy Reviews<br />GRM-10 – Risk Assessments<br />GRM-11 – Risk <br />Management Framework<br />Questions |
| 4 |
Legal Implications |
Section 1: Understanding Unique Risks in the Cloud<br />Understand Legal Requirements & Unique Risks Within the Cloud Environment<br />Section 2: International Legislation and Potential Conflicts<br />International Legislation Conflicts<br />GDPR<br />Appraisal of Legal Risks Specific to Cloud Computing<br />Legal Controls<br />Section 3: eDiscovery<br />eDiscovery<br />Special Issues<br />Forensics Requirements<br />Section 4: Contract Considerations<br />Contract Considerations<br />Contractual & Regulated PII: The Differences<br />Contractual & Regulated PII: The Similarities<br />Country-specific Legislation Related to PII/Data Privacy/Data Protection<br />Section 5: Relevant CCM Controls<br />SEF-01 – Contract / Authority Maintenance<br />Questions |
| 5 |
Virtualization and Technical Design |
Section 1: Virtualization Principles<br />Virtualization Definition<br />How Does Virtualization Work?<br />What is a Virtual Machine (VM)?<br />What is a Hypervisor?<br />Type 1 and Type 2 Hypervisors<br />Virtualization Layer<br />CPU Hardware Virtualization<br />Section 2: Key Components Mapped to Cloud Layer<br />vSphere 6.x Virtual Switches<br />VMware vSwitch Terminology<br />Storage Terminology<br />Overview of Virtual Appliances<br />Clones and Templates<br />Customization Specifications Manager<br />vSphere Content Libraries<br />VM Snapshots<br />vMotion – Hot Migration<br />Storage vMotion<br />Distributed Resource Scheduler Overview<br />Distributed Power Management (DPM)<br />VM Swapfile Location<br />Host Profiles Overview<br />Storage DRS (SDRS) Overview<br />Profile Driven Storage Overview<br />VSAN Architecture<br />Resource Pools Overview<br />High Availability Overview<br />Fault Tolerance<br />Section 3: Key Security Concerns<br />Virtualization Risks and Challenges<br />Network Security and Perimeter<br />Virtualization Security<br />Common Architecture Concerns<br />vSphere Hardening Guide<br />Section 4: Other Technologies Used in the Cloud<br />Network Security<br />Network and Communications in the Cloud<br />Cloud Networking VXLAN<br />Section 5: The Layers<br />Logical Design Considerations<br />Physical Virtual and vCloud Layers<br />Software Defined Data Center (SDDC) Components<br />SDDC– Physical Configuration<br />SDDC– vCenter Cluster Layout<br />SDDC– The Big Ugly Picture<br />SDDC– The Big Ugly Picture but not as bad!<br />Section 6: Relevant CCM Controls<br />IVS-01 Audit Logging / Intrusion Detection<br />IVS-02 Change Detection<br />IVS-03 Clock Synchronization<br />IVS-04 Information System Documentation<br />IVS-05 Vulnerability Management<br />IVS-06 Network Security<br />IVS-07 OS Hardening and Base Controls<br />IVS-08 Production / Non Production Environments<br />IVS-09 Segmentation<br />IVS-10 VM Security Data Protection<br />IVS-11 Hypervisor Hardening<br />IVS-12 Wireless Security<br />IVS-13 Network Architecture<br />Questions |
| 6 |
Managing Information and Securing Data |
Section 1: Cloud/Data Life Cycle<br />Data Security Lifecycle<br />Locations and Access<br />Functions Actors and Controls<br />Section 2: Data Security Architectures and Strategies<br />Pillars of Functionality<br />Storage Types IaaS<br />Storage Types PaaS<br />Storage Types SaaS<br />Top Threats to Storage<br />Technologies available to address the threats<br />Data Dispersion<br />Data Loss Prevention (DLP)<br />Encryption<br />Encryption Challenges<br />Encryption Architecture<br />IaaS Data Encryption<br />Database Encryption<br />Encryption Review<br />Key Management<br />Key Management Considerations<br />Storing keys in the cloud<br />Data Masking/Obfuscation<br />Data Anonymization<br />Tokenization<br />Data Security Strategies<br />Emerging Technologies<br />Section 3: Data Discovery and Classification<br />Data Discovery<br />Data Classification<br />Data Classification Categories<br />Cloud Data Challenges<br />Section 4: Jurisdictional Data Protection for Personally Identifiable Information (PII)<br />Terms<br />Implementation of Data Discovery<br />Main Input Entities<br />Privacy Level Agreement<br />Controls for PII<br />Typical Security Measures<br />Section 5: Data/Information Rights Management<br />Data Rights Management<br />Information Rights Management<br />IRM Cloud Difficulties<br />IRM Solutions <br />Section 6: Data Retention Deletion and Archival Policies<br />Data Protection Policies<br />Data Retention Policies<br />Data Deletion<br />Data Archiving<br />Section 7: Accountability of Data Events<br />SaaS Potential Event Sources<br />PaaS Potential Event Sources<br />IaaS Potential Event Sources<br />Data Event Logging and Event Attributes<br />What to do with data events?<br />Security Information and Event Management<br />Supporting Continuous Operations<br />Section 8: Relevant CCM Controls<br />DSI-01 Management Classification<br />DSI-02 Data Inventory Flows<br />DSI-03 eCommerce Transactions<br />DSI-04 Handling / Labeling / Security Policy<br />DSI-05 Non Production Data<br />DSI-06 Ownership / Stewardship<br />DSI-07 Secure Disposal Questions |
| 7 |
Data Center Operations |
Section 1: The Logical Infastructure<br />Logical Infastructure Design Notes<br />Secure Configuration of Hardware Requirements<br />Secure Network Configuration<br />Hardening OS and Apps<br />Availability of Guest OS<br />Managing the Logical Infrastructure<br />IT Service Management (ITSM)<br />Information Security Management<br />Configuration Management Process<br />Configuration Change and Availability Management<br />Shadow IT<br />Change Management Objectives<br />Change Management Policies and Procedures<br />Problem Management<br />Release and Deployment Management Objectives<br />Release and Deployment Management<br />Service Level Management<br />Other Management areas<br />Section 2: Manage Communications with all Parties 5 Ws and the H<br />Vendors<br />Customers<br />Partners<br />Section 3: Relevant CCM Controls<br />CCC-01 New Development / Acquisition<br />CCC-02 Outsourced Development<br />CCC-03 Quality Testing<br />CCC-04 Unauthorized Software Installations<br />CCC-05 Production Changes<br />HRS-01 Asset Returns<br />HRS-02 Background Screening<br />HRS-03 Employment Agreements<br />HRS-04 Employment Terminations<br />HRS-05 Mobile Device Management<br />HRS-06 Non Disclosure Agreements<br />HRS-07 Roles / Responsibilities<br />HRS-08 Technology Acceptable Use<br />HRS-09 Training Awareness<br />HRS-10 User Responsibility<br />HRS-11 Workspace<br />STA-01 Data Quality and Integrity<br />STA-02 Incident Reporting<br />STA-03 Network / Infrastructure Services<br />STA-04 Provider Internal Assessments<br />STA-05 Supply Chain Agreements<br />STA-06 Supply Chain Governance Reviews<br />STA-07 Supply Chain Metrics<br />STA-08 Third Party Assessment<br />STA-09 Third Party Audits<br />Questions |
| 8 |
Interoperability and Portability |
Section 1: Interoperability<br />Interoperability<br />Reason a change may happen<br />Why is this important<br />Example<br />Recommendations<br />Section 2: Portability<br />Portability<br />Interoperability and Portability Helps to Mitigate<br />Golden Rule<br />Basic Recommendations<br />IaaS Recommendations<br />PaaS Recommendations<br />SaaS Recommendations<br />Private Cloud Recommendations<br />Public Cloud Recommendations<br />Hybrid Cloud Recommendations<br />Section 3: Relevant CCM Controls<br />IPY-01 API’s<br />IPY-02 Data Request<br />IPY-03 Policy and Legal<br />IPY-04 Standardized Network Protocols<br />IPY-05 Virtualization<br />Questions |
| 9 |
Traditional Security |
Section 1: The Physical Environment<br />Physical Environment<br />Physically. What does one of these beasts look like?<br />Major Factors in building a great datacenter<br />Google’s Top 10<br />Datacenter Design<br />Network and Communications in the Cloud<br />Compute<br />Storage<br />Physical and Environmental Controls<br />Protecting Datacenter Facilities<br />System and Communication Protections<br />Section 2: Planning Process for the Data Center Design<br />Support the Planning<br />Physical Design Considerations<br />DC Design Standards<br />Tier Standard Review<br />Tiered Model Summary<br />Environmental Design<br />Design Considerations<br />MultiVendor Pathway Connectivity (MVPC)<br />Section 3: Implement and Build Physical Infrastructure<br />Enterprise Operations<br />Security Requirements for Hardware<br />Oversubscription<br />iSCSI Implementation Considerations<br />Section 4: Typical Security for the Datacenter Components<br />Access Controls<br />Access Control (KVM)<br />Access Controls Securing Network Configurations<br />OS Hardening<br />Everything about the OS<br />Standalone Host Availability Considerations<br />Availability of Clustered Hosts<br />Clustered Storage Architectures<br />Performance Monitoring<br />Redundant System Architecture<br />Backup and Restore of Hosts?<br />Log Management Recommendations<br />Log Management<br />Management Planning Includes<br />Business Continuity & Disaster Recovery<br />Business Continuity Elements<br />Section 5: Relevant CCM Controls<br />DCS-01 Asset Management<br />DCS-02 Controlled Access Points<br />DCS-03 Equipment Identification<br />DCS-04 Off Site Authorization<br />DCS-05 Off Site Equipment<br />DCS-06 Policy<br />DCS-07 Secure Area Authorization<br />DCS-08 Unauthorized Persons Entry<br />DCS-09 User Access<br />Questions |
| 10 |
BCM and DR |
Section 1: Disaster Recovery and Business Continuity Management<br />The Business Continuity Management Concept<br />BCM Lifecycle<br />Business Continuity Disaster Recovery<br />BCDR Relevant Cloud Characteristics<br />Business Impact Analysis<br />BCDR Requirements<br />BCDR Risks Requiring Protection<br />BCDR Strategy Risks<br />BCDR Strategies<br />Creating the BCDR Plan<br />Planning Testing and Review<br />Section 2: Examples<br />Virtualization Pass Through<br />Backup and DR Software<br />Section 3: Relevant CCM Controls<br />BCR-01 Business Continuity Planning<br />BCR-02 Business Continuity Testing<br />BCR-03 Datacenter / Utilities Environmental Conditions<br />BCR-04 Operational Resilience Documentation<br />BCR-05 Environmental Risks<br />BCR-06 Equipment Location<br />BCR-07 Equipment Maintenance<br />BCR-08 Equipment Power Failures<br />BCR-09 Impact Analysis<br />BCR-10 Policy<br />BCR-11 Retention Policy<br />Questions |
| 11 |
Incident Response |
Section 1: Incident Management<br />Incident Management<br />Incident Management Plan<br />Incident Classification<br />Security Events<br />Logs<br />Alerts<br />What is an Incident?<br />Security Incident<br />Indication of Compromise<br />What is Incident Handling?<br />Difference between IH and IR<br />Common Tools<br />IPS vs WAF<br />SOC<br />Six Step Approach to Incident Handling<br />Section 2: Forensics<br />Cloud Forensics Challenges<br />Methodology for Forensics<br />Access to Data by Service Model<br />Forensic Readiness Considerations<br />Items to consider when collecting evidence<br />Section 3: Relevant CCM Controls<br />SEF-01 Contract / Authority Maintenance<br />SEF-02 Incident Management<br />SEF-03 Incident Reporting<br />SEF-04 Legal Preparation<br />SEF-05 Incident Response Metrics<br />Questions |
| 12 |
Application Security |
Section 1: Components affecting Security<br />Web Application Security<br />Application Basics<br />Application Programming Interface (API)<br />WS Features Web Services<br />Common Pitfalls<br />Encryption Dependencies<br />Section 2: Software Development Life Cycle (SDLC)<br />Software Development Lifecycle (SDLC)<br />Secure Software Development Lifecycle S-SDLC<br />Software Development Lifecycle<br />Project Initiation<br />Requirements Phase<br />Secure Design<br />Development<br />Unit Testing<br />Testing<br />Production Implementation<br />Summary<br />Section 3: Vulnerabilities<br />OWASP Top 10<br />A1 – Injection<br />A2 – Broken Authentication<br />A3 – Sensitive Data Exposure Threats and Risks<br />A4 – XML External Entities (XXE)<br />A5 – Broken Access Control<br />A6 – Security Misconfiguration<br />A7 – Cross-Site Scripting<br />A8 – Insecure Deserialization<br />A9 – Using Components with Known Vulnerabilities<br />A10 – Insufficient Logging and Monitoring<br />Cloud Specific Risks<br />STRIDE Threat Model<br />Recommendations<br />Section 4: Identity and Access Management (IAM)<br />Identity and Access Management<br />Federated Identity Management<br />Security Assertion Markup Language 2.0 (SAML 2.0)<br />SAML Assertion<br />SAML Assertion Child Elements<br />SAML Protocols<br />SAML Bindings<br />Open ID Connect (OIDC)<br />OIDC Flows<br />OIDC Flow Comparison<br />JSON Web Tokens Best Practices<br />Which Federated Identity System to use?<br />Multi-Factor Authentication<br />Identities and Attributes<br />Examples<br />Identity Management<br />Section 5: Software Assurance and Validation<br />Assurance<br />Handling of Data<br />ISO/IEC 27034-1<br />Organization Normative Framework (ONF)<br />Frameworks Verification and Validation<br />Application Security Testing<br />Questions |
| 13 |
Encryption and Key Management |
Section 1: Review from other chapters<br />You are the teacher now!<br />Cryptography<br />Encryption / Data Protection<br />Encryption & Key Management<br />Emerging Technologies<br />Section 2: Key Management in today’s cloud services<br />Key Management Interoperability Protocol (KMIP)<br />KMIP<br />Vendors offering KMIP<br />Vendors that support KMIP<br />Cloud Access Security Broker (CASB)<br />Hardware Security Module (HSM)<br />Section 3: Recommendations General Recommendations<br />Recommendations Encryption with Databases<br />Section 4: Relevant CCM Controls<br />EKM-01 Entitlement<br />EKM-02 Key Generation<br />EKM-03 Sensitive Data Protection<br />EKM-04 Storage and Access<br />Questions |
| 14 |
Identity Entitlement & Access Management |
Section 1: Introduction to Identity and Access Management<br />Terms Used<br />Identity and Access Management<br />Key points to consider<br />Identity Architecture Differences<br />Generic Example<br />Identity Federation<br />General Usage of Federation<br />Section 2: Identities and Attributes<br />Provisioning<br />Examples of Identities and Attributes<br />Potential Decision Making Process<br />Identity and the Attribute<br />Entitlement Process<br />Automated Approaches<br />Interpretation Locations<br />Authorization and Access Management<br />Section 3: Options for Architectures<br />Hub and Spoke Model<br />Mesh or Free Form Model<br />Free Form Model<br />Hybrid Model<br />Bridge or Federation Hub<br />Provisioning Accounts<br />Identity and Attribute Provisioning<br />Section 4: The Identity<br />Identity and Data Protection<br />Consumerization Challenge<br />Section 6: Relevant CCM Controls<br />IAM-01 Audit Tools Access<br />IAM-02 Credential Lifecycle / Provision Management<br />IAM-03 Diagnostic /Configuration Port Access<br />IAM-04 Policies and Procedures<br />IAM-05 Segregation of Duties<br />IAM-06 Source Code Access Restriction<br />IAM-07 Third Party Access<br />IAM-08 Trusted Sources<br />IAM-09 User Access Authorization<br />IAM-10 User Access Reviews<br />IAM-11 User Access Revocation<br />IAM-12 User ID Credentials<br />IAM-13 Utility Programs Access<br />Questions |
| 15 |
Auditing and Compliance |
Section 1: Compliance and Audit Cloud Issues<br />GRC Value Ecosystem<br />Assurance by CSP<br />Assurance by CSP– Assurance Frameworks<br />Assurance Challenges of Virtualization and Cloud<br />Policies<br />Risk Audit Mechanisms<br />Section 2: Assurance Frameworks<br />Assurance by CSP Assurance Frameworks<br />Certification Against Criteria<br />Assurance Frameworks ISO 2700X<br />ISO/IEC 27001 Domains<br />Assurance Frameworks – AICPA SOC 1<br />SOC II and SOC III<br />Assurance Frameworks – NIST SP 800-53<br />PCI-DSS Merchant Level<br />PCI-DSS 12 Requirements<br />Assurance Frameworks – COBIT<br />Assurance Frameworks – AICPA/CICA Trust Services<br />Assurance Frameworks – Cloud Security Matrix<br />Assurance Frameworks – FedRamp<br />NIST SP 800-144<br />NIST SP 800-144 – Preliminary Activities<br />NIST SP 800-144 – Initiating & Coincident Activities<br />NIST SP 800-144 – Concluding Activities<br />Assurance Frameworks – HITRUST<br />Assurance Frameworks – BITS<br />Assurance Frameworks – Jericho SAS<br />System/Subsystem Product Certification<br />Common Criteria Protection Profiles (PP)<br />Section 3: The Audit<br />Cloud Audit Goals<br />Impact of Requirements Programs by the Use of Cloud<br />Types of Audit Reports<br />Restrictions of Audit Scope<br />Gap Analysis<br />Standards Requirements (ISO/IEC 27018 GAPP)<br />Internal ISMS<br />Internal Information Security Control System ISO 27002:2013<br />Cloud Computing Audit Characteristics<br />Internal and External Audit Controls<br />Planning & Scoping the Audit<br />Section 4: Relevant CCM Controls<br />AAC-01 – Audit Planning<br />AAC-02 – Independent Audits<br />AAC-03 – Info |