123ArticleOnline Logo
Welcome to 123ArticleOnline.com!

ALL >> Computers >> View Article

Cloud Security Requires A Multi-layered Approach

By Author: LaurenEllis
Total Articles: 35

Cloud service providers can make many promises regarding their data center’s physical security, but it is vital that you are able to understand the logical, remote and application dimensions to cloud security in that provider’s cloud stack. Physical security is important as well, but the security of data can be compromised by many different types of threats.

Infrastructure as a Service (IaaS) is one of the most important cloud service categories today along with Software as a Service (SaaS). Both services require different approaches to Cloud Security and these approaches will dictate what the base cost of these services may be versus extra costs for additional services.

IaaS Providers

Cloud service providers describe the “cloud” in many different ways but before this confusion took place, IaaS simply meant “virtual colocation”, which is a technical way to describe the concept that activities, which take place in your data center, can be done virtually in the provider’s web console. Adding IP’s, building virtual machines and fully controlling three layers of high availability firewalls is necessary for a fully functional cloud service.

Traffic through all security devices is controlled by the customer, which means you, as the customer, retain full control. Furthermore, a customer is able to fully lock down the data center in your cloud. Firewall logs can be exported just like physical firewalls from your web console into an Excel document. You can also use an API to push the logs to a Security Information and Management (SIEM) product.

Intrusion Preventions Systems (IPS) and Intrusion Detection Systems (IDS) are another very important consideration, and these can be provided by an outside security firm against your virtual data center context within your cloud. These intrusion measures can be provided, especially if you are able to inform your security firm early on.

SaaS Providers

In contrast to IaaS, the customer has less control with SaaS based services because the cloud provider codes, hosts and secures applications that may be utilized over the web. This means that it is incumbent on the customer to research the security measures taken by the SaaS provider.

Usernames, passwords and Personally Identifiable Information (PII) data such as social security numbers must be secured through web applications designed by an SaaS company just as an IaaS provider will do. The biggest risks faced by an SaaS involve incorrectly configured databases, operating systems and middleware that a provider may deploy.

If you as a customer are seeking proof that an SaaS provider are as secure as possible, be sure to request a full list of compliance, regulatory and audit results to place your mind at ease. Some of these regulations include PCI, SOC 2, HIPPAA, SSAE16 as well as all of the ISO standards.

A cloud service agreement should include risk assessment services as well, which should focus on the customer more than the cloud provider. The provider should already have a full security breakdown available for your compliance and security department to review. Meetings with your cloud provider’s design team will enable you to gain a deeper understanding of how they actually secure their cloud, which can help to lower your risks.

Logging in to the cloud can be handled in different ways, and authentication is of paramount concern for the security of your cloud. The simplest arrangement will involve a single-factor authentication that is based on a password or credentials that you give to the cloud administrator, but more advanced authentication will involve a phone call with a verbal cue or passcode to ensure security.

The big test of whether your cloud provider is up to the task is if they can encrypt your data while still allowing the customer to own the encryption keys. If they are able to accomplish this, you can mirror the in your physical data center.

Data loss prevention that takes place within your own organization should be duplicated through DLP services offered in an SaaS based service. Any security violations should be communicated to you immediately.

Author :
Lauren Ellis is a research analyst covering the technology industry’s top trends & topics, focusing on Cloud Security, Cloud Computing, Data Loss Prevention etc.,

Total Views: 129Word Count: 678See All articles From Author

Computers Articles

1. Researchers Use Ridesharing Cars To Sniff Out A Secret Spying Tool
Author: Clara Clarkson

2. How To Troubleshoot Norton Error 8504, 104?
Author: James Watson

3. 24*7 Norton Customer Support Services Launched In Europe
Author: Maria Williams

4. Building An Access Databases
Author: Ben Beitler

5. How To Troubleshoot The Webroot Secure Anywhere Error 10?
Author: Daniel Wilson

6. Avg Ranked Under Top 10 Antivirus In 2018
Author: James Watson

7. Norton Tech Support: All-in-one Norton Support Service Provider
Author: Hey buddies! Sandy gibbon with more than five year

8. Is Your Tv Spying On You?
Author: Limeproxies

9. Hire Computer Repair Service Waukesha To Resolve The Issues Immediately
Author: adronseton

10. Looking To Buy A Surface Pro 4? Don’t Forget To Grab A Surface Pro 4 Promo Code
Author: Christine Bleakley

11. Some Great Exit Intent Strategies To Ensure You Never Lose A Visitor Again!
Author: jessia

12. Contact Hard Drive Data Recovery Milwaukee To Restore Data - Itcdatarecovery
Author: adneyjett

13. How To Avail And Cancel Mcafee Subscription Free Trial?
Author: Maria Williams

14. Never Underrate Your Laptop Charger
Author: Lapmart India

15. Türkiye'de çevrimiçi Elektronik Mağazalar: Yeni Gadget'lar Için Tek Elden Mağazanız
Author: Owenthomson

Login To Account
Login Email:
Password:
Forgot Password?
New User?
Sign Up Newsletter
Email Address: