Cloud-based Systems Vulnerabilities and Mitigations
3 slides · 1 min read · Domain 3
Cloud-based Systems Vulnerabilities and Mitigations
Some of the common vulnerabilities found in the cloud are listed opposite
- Inherently exposed to external communication/access: By their nature, cloud systems tend to be more exposed to external communications.
- Misconfiguration a major risk: Cloud providers typically have well-managed infrastructure, but unfamiliarity with the interface and management functions often results in users misconfiguring the cloud service or hosted components in away that exposes data.
- May exist for long periods (risk of being outdated): Services ported to cloud environment may exist for long periods of time. While the underlying components provisioned by the cloud service provider (CSP) may be periodically updated, it is often the user's responsibility to update some components, but assumptions may exist that it is not necessary or that the CSP is providing that function when
they are not.
- Gap between CSP and data owner security controls: There is a high risk for misunderstanding on the cloud customer's part where the responsibilities end of the CSP for security and the customer responsibilities begin.
Text on this slide
These are the mitigations for the cloud vulnerabilities.
- Reputable cloud service provider that supplies security information/ testing results.
- Well-trained system administrators.
- Robust configuration control/ change control.
- File and communication encryption.
- Well-managed identity and access controls.
