CCSP Cloud Certified Security
Professional
Joseph Gollapudi CISSP, CCSP, CISA
● What is CCSP?
● [Link]
● Comparison of CISSP vs CCSP
● [Link]
IS CCSP for
● Resources:
me? ● Study Materials
Alternatives
CISSP
● ISC2 Books
CEH ● Youtube Video’s / AI
CISA / CISM ● Exam Prep Materials
Security+ /CompTIA
● ISC2 Exam Prep
● Udemy / Immersivelabs
● Other
Link
● [Link]
line
Domains Weightage
1. Cloud Concepts, Architecture and
What is in it? Design
17%
2. Cloud Data Security 20%
3. Cloud Platform & Infrastructure Security 17%
4. Cloud Application Security 17%
5. Cloud Security Operations 16%
6. Legal, Risk and Compliance 13%
Total 100%
Chapter 1 Architectural Concepts
Chapter 2 Data Classification
Chapter 3 Cloud Data Security
Chapter 4 Security in the Cloud
Chapter 5 Shared Cloud Platform Risks and Responsibilities
Chapters Chapter 6 Cloud Application Security
Chapter 7 Operations Elements
Chapter 8 Operations Management
Chapter 9 Legal and Compliance Issues
Chapter 10 Cloud Vendor Management
Cloud Characteristics
● Broad Network Access
● SSH / Browser
● OnDemand Self-Service
● Agility / Scale Compute and Storage
Chapter 1 ● Resource Pooling
● Meet Customer Demands / Wastage reported
Cloud Concepts, ● Rapid Elasticity
● Vertical / Horizontal Scaling
Architecture and
● Metered Service
Design ● Accurate measurements / All services metered
● Note: Elasticity Vs Scalability
● Elasticity – Ability to grow or shrink
● Scalable – Grow as demand increases
Understanding Business
● Business Requirements
● Understand the need vs want / Security review /
● Functional vs Non-Functional Requirements
● Understanding Existing State
● Do BIA ( Understand Critical Paths and Single Point of Failure)
Chapter 1 ● Inventory of Assets ( Tangible – Employee, HW/SW and Intangible – Patterns,
TM)
● Cost-Benefit Analysis
Cloud Concepts, ● Meet Customer Demands / Wastage reported
Architecture and ● Reduction in Capital Expenditure
● Pay for use / Expand based on need /
Design ● Cloud Bursting – On Prem + Cloud as needed
● Cloud Governance – Avoid Shadow IT / Importance of Governance & Security
● Transferring Regulatory Cost
● Accurate measurements / All services metered
● Reduction in Backup
● BC/DR Strategy
● Archival / Backup Strategy
Cloud Service Model Vs Cloud Deployment Model
Service Models
Deployment Models
IaaS
• Vendor Provides:
Private Cloud
Network/Compute/Storage/Orchestr
• Dedicated / Single Customer
ation (e.g: Azure/AWS/GCP/Oracle)
• Build or Pay someone to do
• IaaS Capabilities
Chapter 1 Public Cloud
• Virtualized Servers
• CSP – Invests in Massive Infra
• Block Storage – Disk Volumes /
Images • Dedicated Vs Multi-Tenancy
Cloud Concepts, • Object Storage – Maintain Files Hybrid Cloud
• Networking • Public + Private Cloud
Architecture and • Orchestration • Private for Sensitive Data/Apps
Design • OnDemand Self-service Community Cloud
PaaS • Orgs with similar goal
• Ready for your code to run • Gaming – FedRamp
• FaaS (AWS Lambda, Azure Multi-Cloud
Functions and Google Cloud • Combine resources from one or
Functions) two or three CSP’s
SaaS • Single Point of Failure (SPoF)
• CSP Delivers
• Customer : Data and GRC
Multi-tenancy
● Different Customers share the same Compute/Storage/Network (CSP)
Chapter 1 environments
● Principle of Isolation
● Privacy : Never see the data belonging to other customers
Cloud Concepts, ● Performance: Actions of one customer should not affect the others
Architecture and ● Oversubscription: Multi-tenancy allows CSP to oversubscribe their
resources
Design ● Multitenancy possible because of Resource Pooling
● Responsibility of CSP: Make sure Physical Capacity never exceeds
Cloud Computing Roles and Responsibilities
● CSP – Cloud Service Provider
● Offers cloud computing services
● Responsible for building and Maintenance
Chapter 1
● CSC – Cloud Service Consumer/Customer
● Consumer of cloud computing services
Cloud Concepts, ● CS Partner
● Third party companies that provide with CSP
Architecture and ● Products – cloud applications
Design ● Services - Monitoring Services
● Regulator
● Based on location and industry you operate
● Always consult a regulator when in doubt
● CASB – Cloud Access Security Broker
● CSP’s who offer IAM and Managed Identity
Cloud Computing Reference Architecture
● What does it mean? Who is responsible for what activities in the
cloud ecosystem
Chapter 1 ● CSC
● Use / Perform / Monitor / Administer security and Tenants
● Request services / Audit reports
Cloud Concepts, ● CSP
Architecture and ● Prepare Systems ( Linux/Windows) & services for consumption
Design ● Manage Compliance / Assets and Inventories (Physical security)
● Peering with other cloud services and Provide Audit data
● CS Partner
● Assess market place, Acquire and assess customer needs
● Design and Test service components
● Perform Audit
Virtualization and Hypervisor Types
● Virtualization: usually means running multiple operating systems on a single
physical machine.
● This is achieved by using a virtualization software layer, called a
hypervisor
● Allows the creation and management of virtual machines (VMs)
Chapter 1 ● Examples: Microsoft Hype-V, VMware, Oracle Virtual Box
● Host VM has real h/w and Guest VM thinks it has but does not
Cloud Concepts, ● Types : Type 1 (Bare Matel) is common and secure compared to Type 2
Architecture and
Design
Virtualization Security
● VM Isolation: Difficult compared to OnPrem(own CPU and other
isolations but not in cloud)
Chapter 1 ● VM Escape : When compromised process and memory are exposed
● VM Sprawl : It is easy to spin VM’s. When you have unused and
abandoned servers it becomes VM Sprawl ( Wastage reports )
Cloud Concepts, ● Advantage :
Architecture and ● Ephemeral computing: - spin up easy and dispose easy
● Not easy in the physical server environment
Design
● Disadvantage:
● Logs cannot directly be accessed by VMs and provide only VM related
logs
● Most amount of security needed for this virtualization process
Cloud Shared Considerations
● Security and Privacy Considerations
● Goal of Cybersecurity is CIA + Privacy
● Confidentiality – Unauthorized Access / Disclosure
● Integrity - Unauthorized Modifications
Chapter 1 ●
●
Availability - Authorized use when needed
Privacy – Confidentiality of Individual Personal Information
● Leads to
● Governance
Cloud Concepts, ● Comply with legal, security and business constraints
Architecture and ● Helps maintain vendor & cloud operations
● Crucial for Oversight
Design ● Auditability
● Right to Audit or third party audit – SOC, ISO/certifications,
FedRamp
● Regulatory oversight
● HIPP. PCIDSS, SOX etc..
● Compliance achieved by
● Third-party providers
● Handling of data consistent with regulations
● Operational Considerations
● Availability and Performance
● Availability – Security and Operational consideration
● Increase availability by Increasing Resilience
● Resiliency: - Withstand the disruptive events ( Redundancy/ AZ(zone redundant) )
● Maintenance and Version Control
● Cloud scheduled maintenance & impact to business
Chapter 1 ● Version control to track changes to config
● System
● Application
Cloud Concepts ● Outsourcing Issues
● Reversibility: - Restore original ops / Reverse the ongoing impl. rollback
Architecture and ● Vendor Lock-in
Design ● Portability – a design principle
● Avoid vendor specific features
● Interoperability
● SaaS/PaaS interoperability is very crucial
● Concern of integration of solutions with CSP
● Expense reporting does not work with Financials
● Storage does not work with web content mgt
Emerging Technologies
● ML and AI
● ML
● Analyze data and uncover trends, Categorize data and bring efficiency
● AI
Chapter 1 ● ML is a subset of AI
● Collection of techniques to mimic human thought process ( Gen AI, AGI)
● Descriptive Analytics
● Seeks to describe the data
● Predictive Analytics
Cloud Concepts ● Use existing data to predict future events
● Prescriptive Analytics
Architecture and ● Seek to optimize behavior by simulating scenaries
Design ● Blockchain
● Immutable ledgers - different systems from around the world and cannot be tampered
● Nobody can tamper or destroy
● Application of Block Chain – Crypto ledgers eg. Bitcoin
● Other Applications
● Birth/Death, Passport etc
● Supply chain tracking – reputable original source
● Property ownership records
Emerging Technologies .. Continued..2
● IOT / OT ( CPS – Cyber physical systems)
● Definition: Connecting non-traditional devices to internet for data collection,
analysis and control
● Home: Smart devices eg. Camera, garage door, fridge etc.
Chapter 1 ● Smart Devices
● Computer Controlled
● Network Controlled
Cloud Concepts ● IOT devices poses the following challenges
● Difficult to update the software (no keyboard or monitor)
Architecture and ● Always connected to network (easy to compromise)
Design ● Connects back to cloud for command and control (attacks)
● Containers
● Definition: Lightweight packaging of application to make it portable between
h/w platforms
● Application function independent of H/W
● Containers function regardless of the OS and H/W
● Security issues similar to virtualization. Isolation of data and resources
Emerging Technologies .. Continued..3
● Quantum Computing
● Qubits : Multidimensional quantum bit
● Uses principles of quantum mechanics (duality)
● Quantum can render current cryptography ineffective
● Edge and Fog Computing
Chapter 1 ●
●
Not sensible to transfer IOT data to Cloud
Edge Computing:
● Processing power to IOT Network
Cloud Concepts ●
● Transfer subset of data to Cloud
Fog Computing
Architecture and ● Place gateway devices to collect IOT data
● Transfer subset of data to the cloud
Design ● Confidential Computing
● For secure environments like military and defense
● Security throughout the computer process
● Provides protection of code and data in memory
● Uses TEE (Trusted execution environment) ( no outside processes can snoop
during computer cycles)
DevOps and DevSecOps
●DevOps
● Improves interaction between Dev and Tech Ops
● Build collaborative relationships
● Embrace automation
● Outcome of the agile methodology
Chapter 1 ●
●
In Cloud DevOps achieved by IaC (Infrastructure as Cloud)
IaC Modify config and components by scripts
● Eg: Baseline Image for Linux Server ( Golden Image)
● Need a new server
Cloud Concepts ● Start a server using a baseline config
Architecture and ●
●
Configure for a specific function
IaC Advantages:
Design ● Enables Scalability – creates many devices (Virtual) rapidly
● Reduces errors – immutable copy ( modify code and create new servers)
● Makes testing easy – spin up servers as needed
● DevOps + Cybersecurity = DevSecOps