7 hours 35 minutes
Hey, guys. Welcome to the episode of the S S C T exam Prep Siri's. I'm your host here. Simple him.
This is going to be the fourth lesson in the seventh domain
so far in the seventh. Demean. We've taken a look at the CIA triad and how malware applies and threatens confidentiality, integrity and availability. We've taken a look at the different vectors of infection and malicious Web activity.
We've taken a look at how to identify an infection in your organization or on your computer. And we've taken a look at how to analyze malware and successfully mitigated.
Now, finally, in this lesson, we're going to talk about the cloud we're going to address cloud security, the layout of the clown, how the cloud is kept private howto handle data privacy in the clown and had a handle data storage and transmission within the cloud. Let's get started.
Cloud computing environments are really complex systems, a combination off hardware and software that is also Internet based. They use technology such as virtualization and data loss prevention to provide operating environments and to protect the data in the cloud.
Now, cloud computing is
Internet based, so it's kind of like bringing all of this infrastructure through the Internet and then doing computing and calculating and using software that is Internet based. Now. Clowns are very, very different
in terms off all the different kinds there are, but they usually share.
This is most similar characteristics.
Hey, I like to I like to map each characteristic with a picture on the right simply because it helps make it easier to remember.
First is on demand self service kind of like a watering found. Where you have you get resource is when you need them. So if you need more, resource is you say you need more resource is and you get more. Resource is. There's also broad network access,
which is being able to access your clout anywhere around the world.
There is resource pulling with most organizations and especially clown systems. There's only ah, high amount of activity for a small period of time, and everything else is usually a low amount of activity. So cloud resource is and help bring resource is together during the busy parts
of the day and then spread out. The resource is to other things.
When the areas are not so busy
was rapid elasticity. Being able to set up more infrastructure and get more resource is in the cloud immediately as soon as you need them. And there is measured self service
where cloud the cloud offers a unique ability to offer measurements for things in such a power, consumption or resource. Use it, which is kind of difficult to get in a regular network environment.
There are several deployment models. When it comes to clouds, there is the public cloud. This is open for used by the general public. Anyone can use this. It needs to concludes. Like Amazon, Microsoft and Google, there is the private cloud, which is used
only for a singular organization. This is where the organization, like
put different software and have different resource, is that the employees of the organization can use. And there is the hybrid cloud, which combines two or more cloud infrastructure is This is usually a hybrid between public and private,
and there is the Community cloud, which is used by a group of organizations that have shared concerns or if they belong to the same industry they might share. Cloud resource is and still be using the same. Basically, the same stuff.
There are several different service models associated with the cloud. There is software as a service. SAS. This is directed more towards end users. This is hosted application management and software on the man. This allows people to log on to a cloud and be able to
access different software that they need in order to perform their duties.
There is platform as a surface past. This is main believe. For developers, this has the capability for user's to develop applications on the cloud. So this is where they can write cud and test cud and compile it and really create different systems of projects on the cloud.
Using the fundamental cloud resource is that are given
and there is infrastructure as a surface i. A s. This is mainly used for I t professionals.
Fundamental resource is are available for the user to run different applications. It's although there's a couple of benefits with all of these main leads the cost of ownership, the ease of accessibility and the veil of ability to scale up and down infrastructure. Depending on the usage,
virtualization virtualization is the foundation for agile scaleable cloud. On the first practical step, four building cloud infrastructure. Now, virtual ization is the abstraction off virtual machines,
so it's kind of like a network that's run virtually. We could take a look at V lands a couple of lessons ago,
and this is the same thing as you lands Virtual Ran's, except that it bub applies more to the overall entire network. Instead of just a local area network,
virtualization is managed by a host server running a hyper visor. So, huh, improviser is a piece of software, metal or firm. Where that runs virtual machines.
There are two types of hyper visors. The first is known as the native or bare metal hyper visor. These are hyper visors that are run directly on the hosts hardware to control the hardware and manage guest operating systems.
This runs on the bare metal hardware of a server,
and the other type of hyper visor is a hosted hyper visor. These hyper visors run on convention conventional operating systems, just as other programs do so. This includes things like the M workstation virtual box, things like that. Now there's several different types of virtual ization.
It's good to have
a general knowledge of these types is well the first is server virtualization. This is where you can run multiple operating systems on a single server. So if you want to have a window server, But if you want to be able to run another window server or a linen server
a Mac OS server, you can now, and the resource is inside the server. They're all shared throughout the different servers. So if one server needs more, processing power for something than one of the other ones than the resource is can be shifted to that very, very simply.
There is network virtualization, Mr the reproduction of a physical Network in software. So this is the thing we talked about. Such a CZ Virtual Lands
network Virtualization presents a lot of logical networking devices, and service is port switches, routers and everything. Applications could run on the network virtualization. Similar Lee. If they run on the physical network,
there is desktop virtualization. This allows you to set up a new
desktop and and run applications on it for any user in an organization at a moment's notice,
there is application virtualization,
where you can run applications on the cloud as a managed service so you can save costs and increase service.
And there's also storage. Virtual is Asian.
This is the resource is within a a server or holding storage area with abstract discs and flash drives, and combines them into high performance storage pools and delivers these things as software.
So as they are software, they can also still hold data and information.
Now, when it comes to legal and privacy concerns, there's there's a gray area, right? I mean, the cloud is an Internet beast,
system. So if the system is run on somebody else's server, so there's kind of a gray area when it comes to what the clap providers responsible for and what the organization would, Network is responsible for their two main concepts. When it comes to legal and privacy concerns,
there is Applicability law,
which determines the legal regime. Africa ble to a certain matter, and there is jurisdiction which determines the ability of a national court to decide a case
Now when it comes to splitting up responsibility. Usually this diagram is the general rule of thumb force. Putting up that responsibility, the enterprise is responsible for data application platform security,
while the cloud provider is responsible for plaque for infrastructure at physical security within the cloud operations of infrastructure,
and the platform on the software surfaces that they offer different clown service is all for different types of storage with infrastructure as a service, users are responsible for managing applications, data run time and operating system,
while the providers still managed a virtual ization servers, hard drives and networking. Now Infrastructures Service uses two different types of stores. They used volume storage, which is a virtual hard drive me attached to a virtual instance, and used the whose data within the file system
volume storage is act kind of like a physical Dr.
And then there's also Object Storage, which is a file share the 80 eyes or a Web interface
with Platt for warmth as a service. This is where the
cloud providers offer All of the resource is, but the developers actually manage the applications
that when platforms the service there to type of storage, there are structured storage, which is information with a high degree off organization. So what they mean by that? This is information that can be fit in a relation database, and it's seamless and can be searched by simple, straightforward
algorithms or queries.
Unstructured storage is information that does not reside in a database, so it's it's information that doesn't fit nicely into a database. This includes things for this email word processing documents, videos, photos, things like that.
Software, as a service offers two types of storage. Well, it's a offer. Information, storage and management. This utilizes different database, which is in turn, stored on object or volume stored. And then there's also content and file storage, which utilizes again
object or volume storage
content. Ball storage is also available via a Web based user interface. David Loss prevention. As always, day loss prevention is a difficult concept is also a very important concept. You don't want to provide weeks whether you're in a physical network or the clown network. Now, thankfully, date of loss prevention is very similar.
Regardless, if you wore in
right your network or in a cloud based network,
obviously class or just some of the weakness, such as administrator access. Technically, an administrator of the cloud or that clap fighter can access your data if they needed to or wanted to, and that's something you can't really control.
There's also configuration changes since everything is virtualized. Clouds can go from private to public to anything relatively quickly, especially if there is a configuration change. And this is one of the
most common problems when it comes to data loss prevention. There's always databases cloud databases that are private originally that become public simply because a configuration error.
There are also a lack of controls when it comes to cloud storage. When you use the cloud, you're using it, usually with a bunch of other people. And so your data is placed on the same.
His goal area, same physical, our driver server as other tenants. So with the lack of controls, it's possible that someone else's data could be seized. For whatever reason, you're through a court order or it can be removed, and somehow what happens to their data, it can impact what happens. But your data,
obviously data loss prevention attempts to protect the data through
discovery and classifications. You can't protect eight if you don't know where it is, and you can't, and you need to protect sensitive data even more than you need to protect non sensitive data. You can also enforce the data loss prevention by monitoring data and enforcing pot different policies
similar to those on a regular network, though of people who can access and modify the data.
In today's lecture, we discussed cloud characteristics, virtual ization, data storage and data loss prevention.
This service model offers users the capability to develop our own software application Given resource
a salt forest service.
Be platform as a service,
the infrastructure as a service or D enterprise as a service.
If you said be platform as a service, then you are correct. Remember, with platform as a service, the resource is and the tools are already there if the developers who then come in and create their applications on the clown and then manage them from the cloud.
Thanks for watching guys. I hope you learned a lot in this video, and I'll see you next time.
ISC2 Systems Security Certified Practitioner (SSCP) Practice Assessment
The SSCP exam preparation package helps students prepare for the ISC2 SSCP certification exam. ...
(ISC)2 Certified Information Systems Security Professional 2015
(ISC)2 Certified Information Systems Security Professional 2015 is a practice exam preparing for the CISSP ...