Module 05
Module 05
Today, organizations are moving towards digital transformation with the introduction of cloud
computing. They are changing their infrastructure and incorporating cloud-based tools and
technologies. This transition to cloud-based environments can have several adverse
consequences. If cloud-based technologies are not used securely, the organizations can be
subjected to external threats that can be a danger to their business security. Thus, to gain the
maximum benefit, enterprises, when using interconnected cloud technologies, require the best
cloud security procedures and technology. A cloud computing environment offers different as-
a-service models that enable organizations to offload many time-consuming IT-related tasks.
Examples are infrastructure-as-a-service (IaaS), platform-as-a-service (PaaS), and software-as-a-
service (SaaS) computing models. However, while using these services, organizations may
encounter many challenges related to data security. Although third-party cloud computing
providers follow security best practices and ensure the integrity of their servers, data asset
management is still the responsibility of the organization availing these services. With the
evolution of cloud computing environment, security threats have also become more advanced.
These threats target cloud computing providers because of a lack of transparency in the data
movement and access across the cloud. Thus, organizations need to be compliant and have the
right approvals when managing client data stored on the cloud. A successful deployment of the
cloud infrastructure is dependent on the countermeasures to secure against modern-day
cyberattacks. You should have adequate cloud security solutions in all cloud environments,
whether they are private, public, or hybrid to ensure business continuity and security.
Identifying the right cloud security solution requires various considerations.
Let’s discuss them. First is lack of visibility in a public cloud environment. It is difficult to keep
track of who is accessing your data and which cloud service they are using outside your
organization. Second is multitenancy in a public cloud environment. Multiple client
infrastructures might be hosted by the same cloud computing provider. Your services might get
compromised by malicious attackers when targeting other businesses. Another challenge is
access management and shadow IT. You may find it difficult to restrict unfiltered access to your
services from any device and geolocation in a cloud environment. Finally, misconfigurations of
assets are also accountable for breached records in a cloud environment. They include
inappropriate privacy settings or retaining default administrative passwords.
Next, let’s discuss some evolving threats and risks in cloud computing. Insider threats are
caused by current or former employees, business partners, contractors, or anyone who has had
access to systems or networks in the past. They can at any time abuse their access permissions.
This category of threats is invisible to external security systems and thus are more dangerous.
Another prevalent attack on the cloud computing system is distribute-denial-of-service (DDoS).
A DDoS attack targets the server on the enterprise by overloading it with traffic from multiple
synchronized systems. The attack works through Simple Network Management Protocol
(SNMP) used for modems, printers, switches, routers, and servers. The cloud faces another
critical risk and that is data breach. A breach can be due to a leak in the cloud security measures
used by your organization. Malicious users may gain access to sensitive data and misuse the
information. A breach can cost the organization a financial and reputation loss.
Now let’s understand the different security models used in cloud computing. A shared
responsibility model is a cloud security framework where the organization hands off certain IT
security responsibilities to the cloud computing provider. Each party, the cloud provider and the
user are accountable for different aspects of the security, and they work together for the full
security coverage. There are different types of shared security models for IaaS, PaaS, and SaaS.
In IaaS, the provider looks after the physical security of the infrastructure at their data centers.
IaaS users are responsible for the security of the software including the OS required to run their
applications and their data. In PaaS, the provider secures the platform including the OS, user
subscriptions and login credentials, but the user is responsible for the security of any code or
data -- or other content -- produced on the platform. However, in SaaS, the provider is
responsible for almost every aspect of security, including underlying infrastructure, service
application, and the data the application produces. Users still have some security
responsibilities such as protection of login credentials.
Organizations are migrating their workload to a hybrid cloud environment increasing the threat
attack surface. This expansion can result in new data security and compliance challenges. Thus,
you require a robust data-centric cybersecurity program to protect your data. In addition, you
require centralized visibility and monitoring against unauthorized access, exposure, or data
theft across your enterprise data environment.
Let’s discuss some data security capabilities that you can implement to protect your data. To
secure data, you can improve maturity across people, process, and technology. Identify your
most critical data assets, who has access to them, and how they are protected. You can prevent
data loss by detecting, preventing, and enforcing policy violations to avoid accidental data loss.
Implement data security governance by establishing process, metrics, and continuous steady-
state data discovery and classification. In addition, it is critical to monitor database security by
enforcing data protection and compliance policies across hybrid cloud environments. Your next
focus in a cloud environment should be the management of access controls and authentication.
You need to develop Cloud identity and access management (IAM) strategies that provide and
work on zero trust architecture, risk protection, and constantly authenticate any user to any
resource.
An organization should consider the following points while building the IBM cloud: Modernize
at your own pace, matching your business requirements. Retain your existing investments and
on-premises applications, while slowly inducting the right cloud IAM architecture to
complement or replace your framework. Establish a zero-trust implementation that will
provide a centralized access control, preserve client confidentiality, reduce insider threats, and
secure your remote resources. Zero trust model and plan use an environment that securely
connects the right users to the right data at the right time under the right conditions, while also
protecting your organization from cyber threats. Enable scalability for your cloud IAM for
millions of users or transactions without a major modification of the infrastructure.
Another element of cloud security is cloud network security which refers to the security
measures, technology, policies, controls, and processes used to protect data on public, private,
and hybrid cloud networks. There are many security implications when you extend your
network to a cloud environment. To meet modern network security requirements,
organizations need to deploy and manage network security built directly on the cloud.
The benefits of cloud network security are: Centralized security monitoring and management
Easy management and updating of granular policies Real-time detection and powerful
prevention against intrusions, DDoS, and other web-based attacks Automated configuration
and management, helping to eliminate misconfiguration errors, and maintain control over
traffic Encryption services to protect data at rest and in transit Centralized protection and
management of identity and access.
Let’s summarize the best practices you can follow for cloud security. There are some critical
steps under three phases that you can follow. First is identifying your cloud usage state and
risks. Second is protecting your cloud system, and third is responding to attacks. The first phase
comprises: Identifying how your data is accessed Detecting unknown cloud usage Checking your
configurations for cloud services Monitoring for signs of malicious usage of cloud data In the
second phase, you can protect your cloud system by: Assigning protection policies Encrypting
sensitive data Formulating policies for data sharing Restricting data sharing to unknown devices
Implementing a bot protection and mitigation solution Using a proper anti-malware solution
The third phase offers best practices for responding to attacks and attempts to attack: Add
additional authentication and verification steps for high-risk access scenarios Add new policies
for new cloud services The National Institute of Standards and Technology (NIST) has made a
list of best practices and principles that establish a secure and sustainable cloud computing
framework. These principles are NIST's five pillars of a cybersecurity framework: Identify,
Protect, Detect, Respond, and Recover. Another emerging technology in cloud security that
supports cybersecurity framework is cloud security posture management (CSPM). CSPM
solutions are designed to address a common error in many cloud environments, that is,
misconfigurations. CPSM also addresses issues by helping in the deployment of the core
components of cloud security. They include identity and access management (IAM), regulatory
compliance management, traffic monitoring, threat response, risk mitigation, and digital asset
management. The colossal increase in cloud adoption across the cyberworld will motivate
cybercriminals to target organizations in the cloud environment. Although organizations are
taking adequate security measures, they are still vulnerable to cyber-attacks. The current major
trend in cloud security includes multi-cloud strategies such as cybersecurity mesh, zero-trust
security models, hybrid and multi-cloud environment, cloud-native tools and applications,
deployment of DevSecOps, securing remote workforces, and AI and machine learning for threat
detection. The focus is on privacy and data protection regulations.
POLICIES
A policy in cloud security refers to a set of rules and guidelines that determine how users
should access and protect resources within a cloud environment. These policies provide a
framework for maintaining security, ensuring compliance with industry regulations, and
mitigating potential risks
The format of a policy typically includes the following:
A title that provides a descriptive name or identifier for the policy
The scope of the policy, which defines the specific resources, systems, or individuals to
which the policy applies
The objective of the policy, or its goals and purpose
A policy statement that lists the rules, procedures, and restrictions of the policy
The roles and responsibilities of the individuals and groups that are enforcing and
adhering to the policy
Compliance and enforcement details or the measures are taken to monitor and ensure
policy compliance
A review and revision section which outlines how often to review and update the policy
to remain relevant and effective
Service provider and customer-managed policies
Cloud service providers (CSPs) typically have security policies that govern the overall security of
their infrastructure, data centers, and services. These policies ensure a baseline level of security
and protection for customer data. Service provider policies cover various aspects such as
physical security, network security, data encryption, access controls, and incident response.
In addition to service provider policies, customers can implement their own policies, also
known as customer-managed policies. These policies allow customers to tailor security
measures according to their requirements, industry regulations, and risk tolerance. Customer-
managed policies can include additional security controls, access restrictions, data protection
measures, and compliance frameworks.
By combining service provider and customer-managed policies, organizations can establish a
comprehensive security framework that aligns with their unique needs while benefiting from
the underlying security measures provided by the cloud service provider.
Principle of Least Privilege
The principle of least privilege is a key concept in access control that minimizes the risk of
unauthorized access or accidental misuse of resources. It dictates that organizations should
grant users only the minimum necessary permissions required to perform their tasks. By
following the principle of least privilege, organizations limit the potential damage caused by
compromised user accounts.
User Access Level
In a cloud environment, user access levels vary depending on their roles and responsibilities.
Some users may only need access to the console, or the graphical user interface (GUI) provided
by the cloud service provider for resource management and configuration. These users interact
with the cloud through the console to perform tasks such as provisioning resources,
monitoring, and administration.
On the other hand, users involved in software development may require access to the
development environment. This environment includes tools, APIs, and services necessary for
building, testing, and deploying applications in the cloud. These users interact with the cloud
infrastructure using APIs and command-line interfaces (CLIs) rather than relying solely on the
console.
Depending on the organization’s requirements, certain users may have access to both the
console and development environment, enabling them to perform a broader range of tasks and
responsibilities.
Identity and Access Management (IAM)
Identity and Access Management (IAM) enables organizations to manage and authenticate
users’ identities and access to resources in a cloud environment. It involves the processes and
policies that ensure that only authorized individuals have access privileges to sensitive systems,
applications, and data. IAM simplifies user management by centralizing user provisioning,
authentication, and authorization processes, making granting or revoking access rights easier as
needed. This process helps organizations enhance security, protect sensitive information,
enforce compliance with regulations, and streamline administrative tasks related to user
access.
Standard Password Policy
A standard password policy for users logging into the cloud should adhere to best practices to
ensure strong password security. Typically, a password policy includes requirements for
password complexity, such as a minimum length and a combination of upper and lowercase
letters, numbers, and special characters. The policy may also define password expiration
intervals, after which users must change their passwords. Additionally, enforcing a password
history, which is a required number of unique passwords used before reusing an old password,
adds an extra layer of protection against password reuse. Other password policies may include
account lockout, multi-factor authentication, and user awareness and training. The specific
requirements of a password policy will depend on the organization’s needs, requirements, and
risk assessments.
Identity provider standards (SAML, OpenID)
Identity provider standards are protocols and frameworks that define how identity providers
(IdPs) and service providers (SPs) securely exchange authentication and identity information.
These standards ensure consistent and standardized approaches to authentication and access
management. Two widely used identity provider standards are:
Security Assertion Markup Language (SAML) - SAML is an XML-based standard for
exchanging authorization and authentication data between IdPs and SPs. It enables
secure single sign-on (SSO) and identity federation. SAML allows users to authenticate
once with their IdP and access multiple SPs without needing separate authentication.
SAML assertions contain information about the user’s identity and attributes, which SPs
rely on to grant access to their resources.
OpenID Connect - OpenID Connect is a modern standard built on the OAuth 2.0
protocol. It provides a framework for authentication and identity federation. OpenID
Connect allows users to authenticate using their chosen OpenID provider and obtain an
ID token that contains information about their identity. Service providers can use the ID
token to authenticate users and provide access to their resources.
These identity provider standards offer secure and interoperable solutions for managing
authentication and access control in various contexts, including cloud environments, web
applications, and enterprise systems. They enable organizations to establish trust relationships
between identity providers and service providers, simplify user authentication experiences, and
enhance security by centralizing identity management.
According to the Cloud Security Report by Cybersecurity Insiders, the top cloud security concern
of cybersecurity professionals is data loss and leakage. Unauthorized access through misuse of
employee credentials and improper access controls is the single biggest perceived vulnerability
to cloud security, followed by insecure interfaces and APIs. In this session, we will look at how
Identity and Access Management, also known as access control, works as the first line of
defense, allowing you to authenticate and authorize users and provide user-specific access to
cloud resources, services, and applications.
A comprehensive security strategy needs to encompass the security needs of a wide audience
—including organizational users, internet and social-based users, third-party business partner
organizations and vendors. There are three main types of users: Administrative Users,
Developer Users, and Application Users.
Administrative users include cloud platform administrators, operators, and managers: roles that
typically create, update, and delete application and service instances, and also need insight into
their team members’ activities. An attacker on an administrative account can steal data from
production database service instances, deploy malicious applications inside the customer's
domain, or even deface or destroy existing applications.
Developer users include cloud application developers, platform developers, and application
publishers. Developer users are authorized to read sensitive information and to create, update,
and delete applications.
The third type of user is the Application user. These are the users of the cloud-hosted
applications.
Let’s look at the key components of identity and access management, and how they work.
Authentication, or the identity service, enables applications deployed to the cloud to
authenticate users at an application level, based on a range of identity providers such as the
cloud directory, social identity providers such as Google, LinkedIn, Facebook, and Twitter,
enterprise-hosted identity provider, and cloud-hosted identity provider. Sometimes API keys, or
unique identifiers are passed into an API to identify the calling application or user. Multifactor
authentication is used to combat identity theft by adding an additional layer of authentication
for application users, such as single-use passwords or pins, certificates, tokens, risk-based
authentication, (such as changes in the user’s location, past activity, and preferences). Cloud
Directory services are used to securely manage user profiles and their associated credentials
and password policy inside a cloud environment. A directory service within a cloud means that
applications hosted on the cloud do not need to use their own user repository. Reporting helps
provide a user-centric view of access to resources or a resource-centric view of access by users.
Reports typically give information about which users have access to which resources, which
users have changes in access rights, which access is being exploited by each user, and under
which conditions. Audit and compliance is a critical service within identity and access
management framework, both for cloud provider, and cloud consumer. Auditors use these
processes to validate implemented controls against an organization's security policy, industry
compliance, and risk policies--and to report deviations. User and service access management
capability enables cloud application and service owners to provision and de-provision customer,
partner, and vendor user profiles with minimal human interaction. This streamlines access
control based on the role, organization, and access policies defined by the owner. User
accounts of administrators and developers give access to sensitive information. In order to
mitigate the risks of these accounts being hacked into, you require maximum control over the
whole life cycle of these users. Some of the controls that can help secure these sensitive
accounts include: provisioning users by specifying roles on resources for each user; password
policies that control the usage of special characters, minimum password lengths and other
similar settings; multifactor authentication like time-based one-time passwords; and immediate
de-provisioning of access when users leave or change roles. Cloud providers offer Identity
Access and Management services, typically including the ability to create access groups, add
users to access groups, and manage access for existing users. An access group is a group of
users and service IDs created so that the same access can be assigned to all entities within the
group with one or more access policies. Access policies define how users, service IDs, and
access groups in the account are given permission to access account resources. Policies include:
a subject, which can be users, service IDs, or access groups; a target, which is the resource or
provisioned service offering, to which you want to provide access; and role, which defines the
actions allowed on the target of the policy, that is, the resource to which the access is being
granted. Access groups provide a more streamlined access assignment process as compared to
assigning individual access to each user and help reduce the number of policies in an account.
In this session, we learned how Identity and Access Management work as the first line of
defense to secure the cloud.
# Cloud Encryption
Given the concerns around data security and privacy, especially in public cloud environments,
encryption plays a key role and is often referred to as the last line of defense in a layered
security model. This protection not only encrypts data, but also provides robust data access
control, key management, and certificate management. In this session, we will take a closer
look at cloud encryption.
Encryption is defined as scrambling data in a way that makes it illegible. There are two parts to
an encryption system, the encryption algorithm and the decryption key. The encryption
algorithm defines the rules by which data will be transformed so that it becomes illegible. And
the decryption key defines how the encrypted data will be transformed back to legible data.
Encryption ensures that only authorized users have access to sensitive data and when accessed
or intercepted without authorization, data is unreadable and meaningless. Cloud providers
offer various cloud encryption services, this could be limited encryption of data that is identified
as sensitive, or end-to-end encryption of all data uploaded to the cloud. Data is encrypted upon
receipt, and encryption keys are passed to the customers to decrypt data when needed. Keys
need to be managed securely. If you lose your keys, you will not be able to read your data. Data
needs protection in three states: at rest, in transit, and when it is in use. Encryption at rest
protects data while it is physically stored in a database or the storage layer. Depending on the
application and business requirements, there could be multiple options for encrypting data at
rest, such as encryption for block and file storage, built-in encryption, in object storage, and
database encryption services. Encryption in transit protects data while it is transmitted from
one location to another. Encryption in transit includes encrypting the data before transmission,
authenticating endpoints, and decrypting and verifying data on arrival. Secure Sockets Layer or
SSL and Transport Layer Security, TLS are commonly used protocols for encryption in transit.
They are not only used when accessing websites securely, but also for data moving between
servers and services within the cloud. Encryption in use protects data when it is in use in
memory for computations. It allows computations to be performed on encrypted text without
needing to decrypt the data. Cloud storage encryption could be server-side or client-side.
Server-side encryption occurs after Cloud storage receives your data, but before the data is
written to disk and stored. For server-side encryption you can either create and manage your
own encryption keys, known as customer supplied encryption keys, or you can generate and
manage your encryption keys using key management services offered by the cloud storage
provider, known as customer managed encryption keys. Client-side encryption occurs before
data is sent to Cloud storage. This way, users can utilize encryption keys and algorithms that are
not visible to the cloud provider, making it virtually impossible for cloud providers to decrypt
hosted data. Given that a majority of enterprises today operate in multi-cloud environments,
there is a need to implement a singular data protection strategy across an enterprise on-
premise, hybrid, and multi-cloud deployments. Some cloud providers offer multi-cloud data
encryption services with a range of features, such as data access management, integrated key
management, and sophisticated encryption that combine to deliver the scalability and flexibility
to help protect the most sensitive workloads across the enterprise, regardless of where the
data resides. Using a multi-cloud data encryption console, you can define and manage access
policies, create, rotate, and manage encryption keys, and aggregate access logs. Encryption
does not eliminate data security risk, it separates the security risk from the data itself by
moving security to the encryption keys. These keys need to be managed and protected against
threats in order to keep the data secure. Key management services offered by some cloud
providers help perform lifecycle management for encryption keys that are used in cloud
services or customer-built applications. They enable customers to encrypt sensitive data at rest
and to easily create and manage the entire lifecycle of cryptographic keys that are used to
encrypt data. Since the keys remain in possession of the customer, the data is protected from
cloud service providers as well as from other users. Some of the best practices for encryption
key management include: Storing encryption keys separately from the encrypted data. Taking
key backups off site and auditing them regularly. Refreshing the keys periodically. Implementing
multi-factor authentication for both the master and recovery keys.
Cloud computing has transformed the business landscape, offering scalability, flexibility, and
cost-efficiency. However, it also introduces unique challenges in ensuring the security,
performance, and availability of cloud-based services. Monitoring plays a critical role in
proactively detecting and addressing potential issues. In this blog post, we will explore how
monitoring can be achieved in the cloud using techniques such as alarms, logs, metrics, events,
and service-based monitoring, including Infrastructure as Code (IaC).
IaC has emerged as a powerful approach to automate the provisioning and configuration of
cloud resources. With IaC, organizations define their infrastructure requirements through code,
allowing consistent and repeatable deployments. Monitoring IaC deployments is crucial in
ensuring a strong infrastructure that can detect any configuration drift. By incorporating IaC
monitoring alongside other monitoring approaches, organizations can achieve greater control
and visibility over their cloud infrastructure.
Additionally, we will delve into the importance of tracking API calls for audit purposes. API calls
are a gateway for interacting with various cloud services, making the calls crucial for security
and compliance. Organizations can maintain an audit trail by tracking and storing API calls,
ensuring transparency, accountability, and regulatory compliance. Furthermore, we will discuss
attacks, vulnerabilities, risks, and mitigation measures associated with cloud monitoring to
provide a comprehensive understanding of the potential risks and the steps needed to mitigate
them effectively.
Through this exploration, we aim to equip readers with the knowledge and insights to establish
robust cloud monitoring practices, effectively track API calls, and mitigate potential risks. By
embracing comprehensive monitoring strategies, including service-based and IaC monitoring,
organizations can optimize their cloud infrastructure, enhance security, and deliver exceptional
services in the dynamic and ever-evolving cloud environment.
1. The Fundamentals of Cloud Monitoring:
Monitoring in the cloud environment encompasses several vital components. Alarms are set to
be proactive for specific events or thresholds, enabling organizations to respond promptly to
critical situations. Logs are essential in collecting and analyzing data to gain insight into system
behavior. Log management services provide efficient storage and retrieval capabilities, while
log aggregation and analysis tools help detect anomalies and troubleshoot issues.
Metrics allow organizations to collect and visualize performance data through cloud-provided
metrics. Establishing baseline metrics makes it easier to identify anomalies and make informed
decisions. Monitoring dashboards offer real-time visibility into system health, enabling quick
responses to potential issues.
Events capture and process real-time events within the cloud infrastructure. Event-driven
architectures leverage them to trigger actions based on specific criteria. Organizations can
efficiently mitigate potential threats by integrating event monitoring with incident response
workflows.
2. Service-Based Monitoring for Enhanced Cloud Management:
Service-based monitoring focuses on specific cloud services to optimize performance and
ensure efficient resource utilization. Load balancing monitoring involves tracking workload
distribution and identifying potential bottlenecks. Alarms monitor load balancer health and
performance issues, enabling organizations to respond promptly.
Content delivery monitoring involves monitoring content delivery networks (CDNs) for efficient
content distribution. Performance, latency, and cache hit rates are proactively tracked to
ensure an optimal user experience. In the event of content delivery issues, troubleshooting
measures can rectify the situation promptly.
Auto-scaling monitoring is essential for dynamically adjusting resource capacity in response to
changing demands. By monitoring auto-scaling groups, organizations can track scaling events
and evaluate the effectiveness of scaling policies. Coordination between monitoring and scaling
activities ensures seamless scalability.
Infrastructure as Code (IaC) monitoring is critical for organizations utilizing automation and
provisioning resources through code. Monitoring IaC deployments enables verification of
infrastructure changes and detects any drift from the desired state. Configuration issues need
to be identified and rectified promptly to maintain the integrity of the infrastructure.
3. Tracking API Calls for Audit Purposes:
API monitoring is essential for security and compliance in cloud environments. Organizations
must recognize the significance of API calls and the risks associated with unauthorized or
malicious API activity. By implementing API monitoring, organizations can configure audit trails
and access controls to track API activities. Analyzing logs and detecting anomalies help identify
suspicious API behavior, ensuring transparency and accountability in cloud service usage.
The following are examples of cloud services that track API calls.
Amazon Web Services (AWS) CloudTrail: AWS CloudTrail is a service that enables
organizations to monitor, log, and retain API activity across their AWS accounts. It
records API calls made to AWS services and provides detailed information such as
the caller's identity, the time of the API call, and the parameters used. By enabling
CloudTrail, organizations can maintain an audit trail of API activities, ensuring
transparency and accountability. The CloudTrail logs are analyzed to identify
unauthorized or suspicious API behavior.
Google Cloud Audit Logging: Google Cloud Platform (GCP) provides Audit Logging,
which captures API calls and system events across various GCP services. It allows
organizations to track activities related to resource creation, deletion, modification,
and access control changes. Audit Logging provides detailed logs that are monitored
and analyzed to detect anomalous API behavior. By leveraging Audit Logging,
organizations can maintain an audit trail for API activities and enforce compliance
with security policies.
Microsoft Azure Activity Logs: Azure Activity Logs record API calls and other
administrative actions performed. These logs capture the operation type, resource
actions, and the caller's identity. By enabling Azure Activity Logs, organizations can
track API activities, detect unauthorized or malicious behavior, and maintain an
audit trail for compliance.
Salesforce Event Monitoring: Salesforce offers Event Monitoring, a service that logs
API calls and user activities within the Salesforce platform. It provides detailed
information about API operations, user logins, data exports, and other system
events. Event Monitoring enables organizations to track API activities, monitor user
behavior, and identify potential security risks or policy violations.
These examples highlight how specific cloud services can track API calls and maintain audit
trails. Organizations can effectively monitor and analyze API activities by utilizing services like
AWS CloudTrail, Google Cloud Audit Logging, Azure Activity Logs, and Salesforce Event
Monitoring, ensuring transparency, accountability, and compliance with security policies and
regulations.
Conclusion:
Monitoring is vital to cloud management, ensuring cloud-based services' security, performance,
and availability. Organizations can proactively address potential issues and optimize their cloud
infrastructure by utilizing techniques such as alarms, logs, metrics, events, service-based
monitoring, and tracking API calls for audit purposes. Understanding attacks, vulnerabilities,
risks, and mitigation measures help organizations fortify their cloud environment. Robust
monitoring practices and thorough audit trail tracking are essential for maintaining a secure and
efficient cloud ecosystem. By embracing comprehensive cloud monitoring strategies,
organizations can optimize their cloud infrastructure and deliver exceptional services while
mitigating potential risks.
In this session, we will look at some case studies that demonstrate the use of cloud computing
in real business scenarios and the ensuing impact on these businesses and the customers they
serve.
The weather company's mission is to map the atmosphere of the Earth and based on that,
generate the most accurate and hyperlocal forecast of which can be solved out to all our
consumers and devices, which number in millions across the globe. Weather is unpredictable
and we need to be able to spin up and spin down as fast as weather happens. Our normal day-
to-day load is 30 million unique users. When we peek into severe weather that can go north of
100 million across our products. We generate forecasts on-demand. Our forecasts on-demand
system is responsible for generating forecast at a resolution of one squared kilometer grid. We
deliver forecasts on-demand to the tune of 250 billion per day. On the backside of that is our
API platform. That system operates at the scale of about 150,000 requests per second. If our
products don't work and don't work fast, people's lives are in danger. Imagine a hurricane is
approaching East Coast of the United States. As it is approaching the coast, usage of my
weather data, goes up tremendously. It can go up from anywhere from two times to five times.
It took us six months to migrate into to IBM Kubernetes from our previous provider. What
we've noticed is some real efficiencies with DevOps. It's reduced our workflow in pipeline by
about 80%. With the latest hurricane, we were able to scale with IBM Cloud very easily, very
seamlessly. IBM's community service, allows us to scale as fast as the weather happens. As we
migrated our VEP platform to IBM Cloud Kubernetes Services, one of the biggest advantages is
that this is a managed service- which allows our team not to have to babysit our system,
enables them to do other work. With the migration to IBM Cloud Kubernetes, we've gained the
ability to have automation security baked in. This was a feature and a component that was very
manual for us in the past. IBM's security team proactively now notifies us of any security
vulnerabilities. The tools and the investment that the company has made gives us capabilities
that we would have never had before. It gets us very excited and it gives our developers and
engineers opportunities to build new things that they wouldn't have otherwise been able to do.
The global reach that IBM and IBM Cloud together with our technology, with our capabilities for
forecasting, give us the ability to extend our products and services to keep people safe all over
the world.
Good afternoon, ladies and gentlemen. Welcome aboard, captain speaking. Pretty much
anticipating on-time arrival. In a scenario where there's a flight cancellation or some other off-
schedule operation, we've had a system where we find new seats and flights availability for
those customers. But I think oftentimes customers didn't necessarily know that that was the
best option for them. What we wanted to do was create a system where they could actually see
alternate options. The goal was to facilitate a better experience for our customers on how to
get to their destination in an automated fashion on the channel of their choice. In our business,
hurricanes, storms, other natural events impact our customers on a fairly regular basis. What
happened and this is a true story. The hurricanes hit and everybody said "this is ridiculous," our
customers were being impacted by the hurricanes immediately. Why are we mitigating risk of a
traditional rollout when we have the power of the cloud? This is exactly the scenario that our
customers need this capability. I think people now realize that these activities and integration
are much easier when we can use cloud technology and especially microservices, we can break
problems into much smaller problems. Those get much easier to wrap your head around and
develop. This is the technology that we need to be adopting now in order to keep pace with our
customer expectations.
What I love about my job at Cementos Pacasmayo is that it challenges me every single day.
Technology moves so agile that I have to keep up with it. What I love it that the company is also
on that same road driving towards its digital transformations. Our customers are now
demanding quicker time to market and also a more broad portfolio of products we need to
keep up and deliver the best service and the best products that they can get in the least
amount of time. We implemented SAP S/4HANA on IBM Cloud, since it brings us a cost-
effective Infrastructure, and also it's quite scalable. Cementos Pacasmayo is now turning from a
product-driven company to a service driven company. The accounting area now has real
insights on real-time of our financial statements that they didn't use to have. Also on our supply
and chain area, especially on the procurement, they now have the dashboard that helps them
take decisions right on time.
My name is Mukesh Sharma and I'm the Senior Manager of IT at Welch Food. Welch's started
as organization 150 years ago and pretty fast it became the national hallmark. We're owned by
the farmers; it's a co-up, and we value the sweat equity our farmers put into it. That's what
drives us every day that our farmers are working out on the farms, and we're working here to
make sure the organization gives the best benefit of each dollar spent back to them. Welch's IT
is the heart of the business. All the manufacturing systems, any manufacturing data which
comes in through different processing, ERP systems and you name it. We started this journey
with the private cloud. Then at the same time, we have started the process of asking ourselves
on any new application request. Can it be run in the public cloud? The approach we have taken
is slowly and steadily start to move these non mission-critical systems, which can be done
better by somebody else. Let them run outside, let them spend time on it while we spend time
on our core values.
Liquid Power is a company that sells products that when you inject them into crude oil or
gasoline pipelines, it changes the flow characteristics to such a point that you can either one,
increase the flow of those fluids, or secondly, use less energy to actually push the fluids down
the pipeline. We needed to become a standalone company under Berkshire Hathaway. Without
any experience in running our own infrastructure for SAP, we had to come up with the solution
that was best for our business to operate as a standalone company. There were many decisions
we had to make. Do we go cloud? Do we stay on-premise? How do we create our own
infrastructure and back-office and what's the best decision for us, not only today and now, but
in the future going forward. I talked to some CIOs and IT professionals. If you had a blank sheet
of paper, what would you do? Cloud or go on-premise? Without a doubt, all of them say cloud.
This whole process and the migration to the cloud is giving what we believe is a competitive
advantage. What I really love about having IBM with SAP on the cloud is it's scalable. We can do
it much faster and change in a much faster time period than we could otherwise.
Cloud computing is a key part of an enterprise’s digital transformation strategy. As more and
more companies are moving critical business processes and applications to a mix of cloud
infrastructures, qualified cloud computing professionals are in high demand. With a compound
annual growth rate of 14.1%, Grand View Research estimates that the cloud computing market
will reach a revenue of 1,554.94 billion in 2030. Employer demand is outpacing the number of
qualified candidates available. Gartner TalentNeuron’s database of more than one billion
unique job listings, scores the hiring scale for jobs requiring cloud computing skills at 78, which
means employers are finding it "difficult" to get the right applicants for open positions in cloud
technologies. There are many specialization areas within this domain. Here’s a look at some of
the common roles available currently:
1. Cloud Developers, or Cloud Software Engineers, work through all phases of the software
development lifecycle: writing, testing, and maintaining the code. They work with the front-
and back-end of applications, as well as platforms and systems that their applications run on.
Cloud Developers need to have a mix of technical skills, business knowledge, and experience
with at least one of the major cloud providers. Technical skill for a Cloud Developer would
typically include: Knowledge of data structures, distributed systems, operating systems, and
algorithms. Experience with databases. Proficiency in commonly used web application
development languages, such as Python, JavaScript, Java, HTML, and CSS.
2. Cloud Integration Specialists are responsible for integrating new cloud services, applications
and infrastructure, into the organization’s portfolio of internal systems and existing cloud
services. These specialists assess the implications and trade-offs between different solutions as
they relate to the integration between external and internal systems, optimize integration and
user-experience, and ensure that performance standards adhere to service level agreements
set with the enterprise.
3. Cloud Data Engineers are responsible for designing, developing, and deploying scalable data
pipelines and data services. They look at integrating new data management technologies and
software engineering tools into existing infrastructure. Their responsibilities include:
Understanding existing systems to recommend automated integration of disparate data sets.
Collaborating with data scientists and researchers to develop predictive models and proofs of
concept. Promoting best practices that enable teams to accelerate their consumption and
understanding of data. Improving overall efficiency by introducing new engineering processes
and tools.
4. Cloud Security Engineers provide expertise around the systems and processes needed to
protect the confidentiality, integrity, and availability of an organization’s systems and
application data. They Determine security requirements. Plan, implement, and test security
systems. Perform threat simulations to detect possible risks. Recommend innovative
technologies that will enhance the security of cloud-based environments. Cloud Security
Engineers need to have deep knowledge of cloud platforms and services, software design
patterns, and DevOps tools and methodologies.
5. Cloud DevOps Engineers collaborate with development and operations teams to create
reliable and rapid release pipelines for software and updates. This may typically involve creating
custom automation tools, building and maintaining configuration and deployment frameworks,
tracking design bugs and automating the debugging process for developers, maintaining and
deploying web-based applications, monitoring security issues, measuring performance against
expected business outcomes. Containerization expertise is increasingly a must-have for DevOps
Engineers.
6. Cloud Solutions Architects work to translate business requirements into application
architecture and design. Some of the technical skills required for a Cloud Architect role include:
deep knowledge of cloud platforms and services, deep understanding of software design
patterns, knowledge of DevOps tools and methodologies, good understanding of networking, a
high-level understanding of key security concepts. Solution Architects work closely with Cloud
Developers, Networking Specialists, Security Engineers, Integration Specialists, and DevOps
Engineers to architect and design solutions.
There are several resources available for learning cloud technologies, in a variety of delivery
methods, including instructor-led courses, self-paced online courses, online videos, books, and
also technology-focused community forums. Many cloud providers have dedicated learning
portals with extensive resources available on the complete range of cloud technologies and
services they provide. They offer learning paths, which make resources available as per specific
career roles, hands-on learning labs, with interactive learning resources that can be filtered by
role, level, or product, free trials on their suite of products and services.
In this session, we will listen to several cloud application professionals discuss the job market
and the nature of opportunities available in cloud computing for people aspiring to get into this
field. They will also discuss what they foresee as the future of opportunities in this field.
>>With more companies adopting some sort of cloud and becoming more cloud aware, there is
no lack of opportunities for aspiring software developers. Now, you could get into this field as a
cloud architect where you're thinking about how to architect applications, which by the way,
look a lot different than if you were developing applications, monolith applications on a single
server, versus developing applications for the distributed cloud. So that, that is a very
prominent role. Another role could be that of a data engineer, where you're looking at building
pipelines, for data to flow from their source databases, and other storage into perhaps data
science models that are deployed at scale on Cloud. Another very important role is that of a
cloud security engineer. In that role, it will be your responsibility to see that all of the all of the
different layers of your cloud are secure for your developers and your end users.
>>There are so many opportunities for people thinking about getting into Cloud computing,
you'd be surprised how many companies are still not in the cloud. And it's very clear that
they're all going to go to the cloud eventually, because it's just so much better for so many
reasons that we've talked about. And there is not enough talent right now, to fill all of that
demand. And that demand will just keep coming. And, really, there are so many things to know
about the cloud, one person can know them all. So if you just learn one or two things about the
cloud really well, you're already going to be really valuable to some company. Let's say you just
know, storage service, and one compute service really well or even just decently that is really
valuable to many companies. And if you're just getting started, I would recommend get a
certification. I had zero experience in the cloud, and I got a certification. And by getting that
cloud certification, I was instantly more visible to recruiters and I got a job. And so if you don't
have the experience on your resume, start off by getting a certification.
>>Depending on your area of interest, you can get into different fields under cloud computing.
If you like programming, you can be a cloud application developer. You should have knowledge
of front end and back end technologies like Python, Java, Angular, React etc. It would also
require you to have database skills in relational databases like SQL, MySQL, as well as NoSQL
databases like Hadoop, Mongo DB, etc. There is a rapidly increase demand for Machine learning
and Artificial intelligence. You need to have a good understanding of machine learning concepts
and should have the ability to handle and process big data. You can choose the career path of
being a data scientist, machine learning engineer. There is also a need for cloud professionals
with specialization in cloud security skills. These professionals should understand cloud security
and also leverage the cloud security tools offered by organizations. Another opportunity for
cloud computing is in the area of DevOps. DevOps Engineers will need an understanding of
DevOps tools like Docker, Kubernetes, Github etc. They should also focus on understanding the
CI/CD pipeline and automating the process of development and deployment.
>>Suffice it to say, there are a myriad of career paths in the cloud technology space, including
professional career path options for people with and without, you know, a BS degree or a non
technical college degree. Companies cannot find enough trained people in cloud technology. So
opportunities and demand are definitely out there. In addition, companies are focusing on
training their current employees both, you know, reskilling and upskilling to meet this demand
internally. So Coursera is committed to helping people without college degrees or people that
are making career changes to access the job, these job opportunities that exist in cloud
technology.
# Summary and Highlights
In this module, you have learned:
Cloud security refers to the policies, technological procedures, services, and solutions
designed to secure enterprise applications and data on the cloud against insider threats,
data breaches, compliance issues, and organized security threats.
Cloud security is a shared responsibility between the cloud provider and the user
organization.
Security architecture and methods for achieving continuous security need to be
embedded through the life cycle of an application to ensure that the application runs on
a safe platform, the code is free from vulnerabilities, and the operational risks are
understood.
Identity and Access Management, also known as access control, helps authenticate and
authorize users and provides user-specific access to cloud resources, services, and
applications.
As part of their Identity and Access Management services, most cloud providers offer
users the ability to define access groups and create access policies that define
permissions for users on account resources.
Cloud encryption, often called the last line of defense, encrypts data and provides
robust data access control, key management, and certificate management.
Data needs encryption in three states:
o Encryption at rest: Protecting data while it is stored
o Encryption in transit: Protecting data while it is transmitted from one location to
another
o Encryption in us: Protecting data when it is in use in memory
All connected systems and cloud-based services should be monitored to maintain
visibility of all data exchanges between public, private, and hybrid cloud environments.
This ensures that the cloud provides a trusted platform to integrate with your enterprise
data centers securely.
Businesses all over the world are realizing tangible benefits from the use of cloud
technologies and services, including:
o The Weather Company migrating to the cloud to reliably deliver critical weather
data at high speed, especially during major weather events such as hurricanes
and tornadoes
o American Airlines uses the cloud platform and technologies to deliver digital self-
service tools and customer value more rapidly across its enterprise
o Cementos Pacasmayo achieving operational excellence and insight to help drive
strategic transformation and reach new markets using cloud services
o Welch chose cloud storage to drive business value from hybrid cloud
o LiquidPower uses cloud-based SAP applications to fuel business growth
The market size of the cloud services industry is at nearly three times the growth of
overall IT services, increasing the need for qualified cloud computing professionals.
Some common job roles that are available in this domain include Cloud Software
Engineers, Cloud Integration Specialists, Cloud Data Engineers, Cloud Security Engineers,
Cloud DevOps Engineers, and Cloud Solution Architects.