0% found this document useful (0 votes)
5 views18 pages

Chapter One

The document provides an overview of the CCSP (Cloud Certified Security Professional) certification, including its domains, weightage, and comparison with other certifications like CISSP and CEH. It outlines key concepts in cloud security, virtualization, emerging technologies, and the roles and responsibilities within cloud computing. Additionally, it emphasizes the importance of security, compliance, and operational considerations in cloud environments.

Uploaded by

nashalmeida27
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views18 pages

Chapter One

The document provides an overview of the CCSP (Cloud Certified Security Professional) certification, including its domains, weightage, and comparison with other certifications like CISSP and CEH. It outlines key concepts in cloud security, virtualization, emerging technologies, and the roles and responsibilities within cloud computing. Additionally, it emphasizes the importance of security, compliance, and operational considerations in cloud environments.

Uploaded by

nashalmeida27
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

CCSP Cloud Certified Security

Professional
Joseph Gollapudi CISSP, CCSP, CISA
● What is CCSP?
● [Link]
● Comparison of CISSP vs CCSP
● [Link]
IS CCSP for
● Resources:
me? ● Study Materials
Alternatives
CISSP
● ISC2 Books
CEH ● Youtube Video’s / AI
CISA / CISM ● Exam Prep Materials
Security+ /CompTIA
● ISC2 Exam Prep
● Udemy / Immersivelabs
● Other
Link
● [Link]
line

Domains Weightage
1. Cloud Concepts, Architecture and
What is in it? Design
17%

2. Cloud Data Security 20%


3. Cloud Platform & Infrastructure Security 17%
4. Cloud Application Security 17%
5. Cloud Security Operations 16%
6. Legal, Risk and Compliance 13%
Total 100%
Chapter 1 Architectural Concepts
Chapter 2 Data Classification
Chapter 3 Cloud Data Security
Chapter 4 Security in the Cloud
Chapter 5 Shared Cloud Platform Risks and Responsibilities
Chapters Chapter 6 Cloud Application Security
Chapter 7 Operations Elements
Chapter 8 Operations Management
Chapter 9 Legal and Compliance Issues
Chapter 10 Cloud Vendor Management
Cloud Characteristics
● Broad Network Access
● SSH / Browser
● OnDemand Self-Service
● Agility / Scale Compute and Storage
Chapter 1 ● Resource Pooling
● Meet Customer Demands / Wastage reported
Cloud Concepts, ● Rapid Elasticity
● Vertical / Horizontal Scaling
Architecture and
● Metered Service
Design ● Accurate measurements / All services metered

● Note: Elasticity Vs Scalability


● Elasticity – Ability to grow or shrink
● Scalable – Grow as demand increases
Understanding Business
● Business Requirements
● Understand the need vs want / Security review /
● Functional vs Non-Functional Requirements
● Understanding Existing State
● Do BIA ( Understand Critical Paths and Single Point of Failure)
Chapter 1 ● Inventory of Assets ( Tangible – Employee, HW/SW and Intangible – Patterns,
TM)
● Cost-Benefit Analysis
Cloud Concepts, ● Meet Customer Demands / Wastage reported

Architecture and ● Reduction in Capital Expenditure


● Pay for use / Expand based on need /
Design ● Cloud Bursting – On Prem + Cloud as needed
● Cloud Governance – Avoid Shadow IT / Importance of Governance & Security
● Transferring Regulatory Cost
● Accurate measurements / All services metered
● Reduction in Backup
● BC/DR Strategy
● Archival / Backup Strategy
Cloud Service Model Vs Cloud Deployment Model

Service Models
Deployment Models
IaaS
• Vendor Provides:
Private Cloud
Network/Compute/Storage/Orchestr
• Dedicated / Single Customer
ation (e.g: Azure/AWS/GCP/Oracle)
• Build or Pay someone to do
• IaaS Capabilities
Chapter 1 Public Cloud
• Virtualized Servers
• CSP – Invests in Massive Infra
• Block Storage – Disk Volumes /
Images • Dedicated Vs Multi-Tenancy
Cloud Concepts, • Object Storage – Maintain Files Hybrid Cloud
• Networking • Public + Private Cloud
Architecture and • Orchestration • Private for Sensitive Data/Apps
Design • OnDemand Self-service Community Cloud
PaaS • Orgs with similar goal
• Ready for your code to run • Gaming – FedRamp
• FaaS (AWS Lambda, Azure Multi-Cloud
Functions and Google Cloud • Combine resources from one or
Functions) two or three CSP’s
SaaS • Single Point of Failure (SPoF)
• CSP Delivers
• Customer : Data and GRC
Multi-tenancy

● Different Customers share the same Compute/Storage/Network (CSP)


Chapter 1 environments
● Principle of Isolation
● Privacy : Never see the data belonging to other customers
Cloud Concepts, ● Performance: Actions of one customer should not affect the others
Architecture and ● Oversubscription: Multi-tenancy allows CSP to oversubscribe their
resources
Design ● Multitenancy possible because of Resource Pooling
● Responsibility of CSP: Make sure Physical Capacity never exceeds
Cloud Computing Roles and Responsibilities

● CSP – Cloud Service Provider


● Offers cloud computing services
● Responsible for building and Maintenance
Chapter 1
● CSC – Cloud Service Consumer/Customer
● Consumer of cloud computing services
Cloud Concepts, ● CS Partner
● Third party companies that provide with CSP
Architecture and ● Products – cloud applications
Design ● Services - Monitoring Services
● Regulator
● Based on location and industry you operate
● Always consult a regulator when in doubt
● CASB – Cloud Access Security Broker
● CSP’s who offer IAM and Managed Identity
Cloud Computing Reference Architecture

● What does it mean? Who is responsible for what activities in the


cloud ecosystem
Chapter 1 ● CSC
● Use / Perform / Monitor / Administer security and Tenants
● Request services / Audit reports
Cloud Concepts, ● CSP
Architecture and ● Prepare Systems ( Linux/Windows) & services for consumption
Design ● Manage Compliance / Assets and Inventories (Physical security)
● Peering with other cloud services and Provide Audit data
● CS Partner
● Assess market place, Acquire and assess customer needs
● Design and Test service components
● Perform Audit
Virtualization and Hypervisor Types
● Virtualization: usually means running multiple operating systems on a single
physical machine.
● This is achieved by using a virtualization software layer, called a
hypervisor
● Allows the creation and management of virtual machines (VMs)
Chapter 1 ● Examples: Microsoft Hype-V, VMware, Oracle Virtual Box
● Host VM has real h/w and Guest VM thinks it has but does not
Cloud Concepts, ● Types : Type 1 (Bare Matel) is common and secure compared to Type 2
Architecture and
Design
Virtualization Security
● VM Isolation: Difficult compared to OnPrem(own CPU and other
isolations but not in cloud)
Chapter 1 ● VM Escape : When compromised process and memory are exposed
● VM Sprawl : It is easy to spin VM’s. When you have unused and
abandoned servers it becomes VM Sprawl ( Wastage reports )
Cloud Concepts, ● Advantage :
Architecture and ● Ephemeral computing: - spin up easy and dispose easy
● Not easy in the physical server environment
Design
● Disadvantage:
● Logs cannot directly be accessed by VMs and provide only VM related
logs
● Most amount of security needed for this virtualization process
Cloud Shared Considerations
● Security and Privacy Considerations
● Goal of Cybersecurity is CIA + Privacy
● Confidentiality – Unauthorized Access / Disclosure
● Integrity - Unauthorized Modifications
Chapter 1 ●

Availability - Authorized use when needed
Privacy – Confidentiality of Individual Personal Information
● Leads to
● Governance
Cloud Concepts, ● Comply with legal, security and business constraints
Architecture and ● Helps maintain vendor & cloud operations
● Crucial for Oversight
Design ● Auditability
● Right to Audit or third party audit – SOC, ISO/certifications,
FedRamp
● Regulatory oversight
● HIPP. PCIDSS, SOX etc..
● Compliance achieved by
● Third-party providers
● Handling of data consistent with regulations
● Operational Considerations
● Availability and Performance
● Availability – Security and Operational consideration
● Increase availability by Increasing Resilience
● Resiliency: - Withstand the disruptive events ( Redundancy/ AZ(zone redundant) )
● Maintenance and Version Control
● Cloud scheduled maintenance & impact to business
Chapter 1 ● Version control to track changes to config
● System
● Application
Cloud Concepts ● Outsourcing Issues
● Reversibility: - Restore original ops / Reverse the ongoing impl. rollback
Architecture and ● Vendor Lock-in
Design ● Portability – a design principle
● Avoid vendor specific features
● Interoperability
● SaaS/PaaS interoperability is very crucial
● Concern of integration of solutions with CSP
● Expense reporting does not work with Financials
● Storage does not work with web content mgt
Emerging Technologies
● ML and AI
● ML
● Analyze data and uncover trends, Categorize data and bring efficiency
● AI
Chapter 1 ● ML is a subset of AI
● Collection of techniques to mimic human thought process ( Gen AI, AGI)
● Descriptive Analytics
● Seeks to describe the data
● Predictive Analytics
Cloud Concepts ● Use existing data to predict future events
● Prescriptive Analytics
Architecture and ● Seek to optimize behavior by simulating scenaries

Design ● Blockchain
● Immutable ledgers - different systems from around the world and cannot be tampered
● Nobody can tamper or destroy
● Application of Block Chain – Crypto ledgers eg. Bitcoin
● Other Applications
● Birth/Death, Passport etc
● Supply chain tracking – reputable original source
● Property ownership records
Emerging Technologies .. Continued..2
● IOT / OT ( CPS – Cyber physical systems)
● Definition: Connecting non-traditional devices to internet for data collection,
analysis and control
● Home: Smart devices eg. Camera, garage door, fridge etc.
Chapter 1 ● Smart Devices
● Computer Controlled
● Network Controlled
Cloud Concepts ● IOT devices poses the following challenges
● Difficult to update the software (no keyboard or monitor)
Architecture and ● Always connected to network (easy to compromise)
Design ● Connects back to cloud for command and control (attacks)
● Containers
● Definition: Lightweight packaging of application to make it portable between
h/w platforms
● Application function independent of H/W
● Containers function regardless of the OS and H/W
● Security issues similar to virtualization. Isolation of data and resources
Emerging Technologies .. Continued..3
● Quantum Computing
● Qubits : Multidimensional quantum bit
● Uses principles of quantum mechanics (duality)
● Quantum can render current cryptography ineffective
● Edge and Fog Computing
Chapter 1 ●

Not sensible to transfer IOT data to Cloud
Edge Computing:
● Processing power to IOT Network

Cloud Concepts ●
● Transfer subset of data to Cloud
Fog Computing
Architecture and ● Place gateway devices to collect IOT data
● Transfer subset of data to the cloud
Design ● Confidential Computing
● For secure environments like military and defense
● Security throughout the computer process
● Provides protection of code and data in memory
● Uses TEE (Trusted execution environment) ( no outside processes can snoop
during computer cycles)
DevOps and DevSecOps

●DevOps
● Improves interaction between Dev and Tech Ops
● Build collaborative relationships
● Embrace automation
● Outcome of the agile methodology

Chapter 1 ●

In Cloud DevOps achieved by IaC (Infrastructure as Cloud)
IaC Modify config and components by scripts
● Eg: Baseline Image for Linux Server ( Golden Image)
● Need a new server
Cloud Concepts ● Start a server using a baseline config

Architecture and ●

Configure for a specific function
IaC Advantages:
Design ● Enables Scalability – creates many devices (Virtual) rapidly
● Reduces errors – immutable copy ( modify code and create new servers)
● Makes testing easy – spin up servers as needed
● DevOps + Cybersecurity = DevSecOps

You might also like