CLOUs BuRSTING
cloud da opicatima.
Some
prt
n local on dou
is that he
ybricl adel
excero apuy at
or tus
cloud caw or voune
’ fean Advaviagcombineo advan
Cloud veourr con
is honddby locadt
operatin,most wrtlond
>duuring horma caed
additinal ocload ae to
oiea nas dartiarg
’
cloud-,
(doO
Scalup
Advaustageooloud Burshing, hovdorQ
ter fermhent
Avoid ned
) )nveotmn
tu clod are
)ksoure
ignegead avulaaity dunung
enares pea Hmo
T n k
Dataua Rr
LA N
to cloud
butt to perorm
Sgetns
Most si nave sipe daig
cloud olaud
ni ue
syotenm beItee
clonu tota rore ight
portin but
achny
jn clone
prorg Databa l
tocal
Frawoactn 7 faymant
ciDud 7 gtuy
to
serr Databse
CLoUD APLS intevact wth daud
allow apps fo
jtefaa that iukematiom betaesn abplictie
Cue
Servieo olauaation
Twy ekelaug, tecoud
dupperte hy
Oporatima
+Riqueot Monoving chud
managemlnt aand
’basd apictton
enalse
s AP Servid
ha
cloud
vendor REST a few ore
RST
’Sach poud as
as bo th.
are
mosf
expoxd jnclude wechann
API also fo servico
A a Cloud
> Authort2atio
to
Caucthttcattn A
otaa pl fom A
addeno
utiatives or
AP 4
BiwpeCloud Ams
Iintereperalilsy
PNITION
STORAGe De a welb
CLOUD accemd loy
Huat 0s
nAPl ed inBatagerteo
class
Hamed Sercp alos wr to
cloud gera their Storag
deuand
mog moole
formaf that
Yaw dis hogehakpedat
Praideg fomat ahd mna
Drtifon
sterg
nanigad (Baas)(aa
tasaa
eers
Stoagt ca to
epsCenic) Servo
SNA Sforag as
(TaaS) jorage ter
bogle olouo
s) donstep
lusinin
BMSmot
hrvanik
sonko
enail
hosted
brouOser
Welbmail~
(agtwore
sorke
orrice
wavity wmd aceno
’ most eall
hebnau aos oer
beulrtUR
brouwsr and igltsus
welbuad poviloxs
Yahovmai
attatmut for
exeutadu fO
ad blbcka tanalo
TTIS -br data
’wes
Mal2Welo
attount
brows
[Link],done
nam and
weball tnterta
mor g.
Orchestration is the coordination and management of multiple computer systems,
applications and/or services, stringing together multiple tasks
in order to execute a larger workflow or process.
How to deal with storage location and tenancy compiled src7cse@[Link] 25-Sept-2025 Pg 1 of 7
How to deal with storage location and tenancy for securing data in Cloud
Computing?
(This document is prepared partially from LLM models)
[Link]
How to deal with storage… This document is prepared partially from LLM models Pg 1 of 7
How to deal with storage location and tenancy compiled src7cse@[Link] 25-Sept-2025 Pg 2 of 7
[Link]
Here's a concise overview of dealing with storage location and tenancy for securing
data in cloud computing, along with an example case:
Storage location and multi-tenancy are crucial aspects of data security in cloud
computing. Cloud providers often store data across multiple geographic locations for
redundancy and performance. However, this can raise compliance and privacy
concerns. To address this:
1. Data residency: Ensure data is stored in locations that comply with relevant
regulations.
2. Data sovereignty: Be aware of laws governing data access in different
jurisdictions.
3. Encryption: Use strong encryption for data at rest and in transit.
4. Access controls: Implement robust identity and access management.
5. Tenant isolation: Ensure proper logical separation between different tenants'
data.
Example case: A multinational financial services company needs to store customer data
in the cloud while complying with various regional regulations. They work with a cloud
provider that offers:
● Region-specific data centers
● Strong encryption
● Virtual private cloud options
● Compliance certifications (e.g., ISO 27001, SOC 2)
How to deal with storage… This document is prepared partially from LLM models Pg 2 of 7
How to deal with storage location and tenancy compiled src7cse@[Link] 25-Sept-2025 Pg 3 of 7
The company implements a hybrid cloud solution, keeping sensitive data on-premises
and using the cloud for less sensitive workloads. They use data classification and
tagging to ensure data is stored in appropriate locations and apply encryption and
access controls consistently across their infrastructure.
[Link]
When migrating data to the cloud, ensuring its security is paramount. Two crucial factors
to consider are storage location and tenancy.
Storage location refers to the geographical region where your data is stored. This can
influence factors like data latency, regulatory compliance, and potential risks. For
instance, if your business operates primarily in Europe, storing data in a European data
center ensures compliance with GDPR regulations. However, storing data in a region
with a different legal framework might expose it to potential risks.
Tenancy refers to the level of isolation between your data and other tenants on the
same cloud platform. In a multi-tenant environment, multiple organizations share the
same infrastructure. 1 While this can be cost-effective, it raises concerns about data
isolation. 2 Cloud providers typically employ various techniques like logical isolation,
encryption, and access controls to mitigate these risks. 3 In contrast, a single-tenant
environment provides dedicated resources for your data, offering a higher level of
security but at a potentially higher cost.
How to deal with storage… This document is prepared partially from LLM models Pg 3 of 7
How to deal with storage location and tenancy compiled src7cse@[Link] 25-Sept-2025 Pg 4 of 7
Example: A healthcare organization might choose to store patient data in a data center located within the country to
comply with local healthcare regulations. To mitigate risks associated with multi-tenancy, they could opt for a private
cloud or a dedicated server within a public cloud.
Security in cloud computing is a major concern. Data in cloud should be stored
in encrypted form. To restrict client from accessing the shared data directly,
proxy and brokerage services should be employed.
Security Planning
Before deploying a particular resource to cloud, one should need to analyze
several aspects of the resource such as:
Select resource that needs to move to the cloud and analyze its sensitivity
to risk.
Consider cloud service models such as IaaS, PaaS, and SaaS. These
models require customer to be responsible for security at different levels
of service.
Consider the cloud type to be used such as public, private, community
or hybrid.
Understand the cloud service provider's system about data storage and its
transfer into and out of the cloud.
The risk in cloud deployment mainly depends upon the service models and cloud
types.
How to deal with storage… This document is prepared partially from LLM models Pg 4 of 7
How to deal with storage location and tenancy compiled src7cse@[Link] 25-Sept-2025 Pg 5 of 7
Understanding Security of Cloud
Security Boundaries
A particular service model defines the boundary between the responsibilities of
service provider and customer. Cloud Security Alliance (CSA) stack model
defines the boundaries between each service model and shows how different
functional units relate to each other. The following diagram shows the CSA
stack model:
[Link]
Key Points to CSA Model
IaaS is the most basic level of service with PaaS and SaaS next two above
levels of services.
Moving upwards, each of the service inherits capabilities and security
concerns of the model beneath.
IaaS provides the infrastructure, PaaS provides platform development
environment, and SaaS provides operating environment.
How to deal with storage… This document is prepared partially from LLM models Pg 5 of 7
How to deal with storage location and tenancy compiled src7cse@[Link] 25-Sept-2025 Pg 6 of 7
IaaS has the least level of integrated functionalities and integrated
security while SaaS has the most.
This model describes the security boundaries at which cloud service
provider's responsibilities end and the customer's responsibilities begin.
Any security mechanism below the security boundary must be built into
the system and should be maintained by the customer.
Although each service model has security mechanism, the security needs also
depend upon where these services are located, in private, public, hybrid or
community cloud.
Understanding Data Security
Since all the data is transferred using Internet, data security is of major concern
in the cloud. Here are key mechanisms for protecting data.
Access Control
Auditing
Authentication
Authorization
All of the service models should incorporate security mechanism operating in all
above-mentioned areas.
Isolated Access to Data
Since data stored in cloud can be accessed from anywhere, we must have a
mechanism to isolate data and protect it from client’s direct access.
Brokered Cloud Storage Access is an approach for isolating storage in the
cloud. In this approach, two services are created:
A broker with full access to storage but no access to client.
A proxy with no access to storage but access to both client and broker.
How to deal with storage… This document is prepared partially from LLM models Pg 6 of 7
How to deal with storage location and tenancy compiled src7cse@[Link] 25-Sept-2025 Pg 7 of 7
Working Of Brokered Cloud Storage Access System
When the client issues request to access data:
The client data request goes to the external service interface of proxy.
The proxy forwards the request to the broker.
The broker requests the data from cloud storage system.
The cloud storage system returns the data to the broker.
The broker returns the data to proxy.
Finally the proxy sends the data to the client.
All of the above steps are shown in the following diagram:
[Link]
Encryption
Encryption helps to protect data from being compromised. It protects data that
is being transferred as well as data stored in the cloud. Although encryption
helps to protect data from any unauthorized access, it does not prevent data
loss.
How to deal with storage… This document is prepared partially from LLM models Pg 7 of 7
’each ’
’Pros Single
ore ’
’ Tenant in
more Cwtmor Tenany Compuctclodaeuding
house
recre
ol has Scalalbe)
étgttive
c¡Hulst tipe (more ona
4
tomi as their wl
eontrol r,
It
ouon userydedicalid
scctton (s but HyP
not olacieats shored ex
can plnoino) reo ou
sharodae reoour
dons ea
Cons Mre expenaiue
aily scalab .
t satsstoao
Hutteny
acivHeA ore
data aud
but-rr
ganl
kut nue
Opporthent people
poriral spgu
Pros
provi
but
to epdata
Jow er scsrong
solatiet
austonigaten
enev
DAT.
storeo in loccoon
Rosiclany Data is
hat co (aws
Soweignits e auare
sata
crs eat
RoGust ac idan
plemt
Managmnt to chech
Atcer control Sapovatton
Terant|sdatton roper al
logic fenants dota.
cieua ore cuaually reapmable tor co
bsod provider soices
ien cn maing
ENTEAPRISt SERYICE BUs (esius
integoctien.
avchiteclure -to enable
Bus baard
multip Commnicatton b
hnann faciltala to
to nediall/ wot suypd
hups
> oppication fuat uene
work fogetheg
cammnCale/
pYoduncer yoduer
Preder Datadbane
Appiatin
tntrerpng Serme
Buo
Conumy
BRP ConuneY
-’each
Can
to
ve
tsp
to
dle mcm ht Yols
Nediatng as fornats
A
act
translaleo ge reac
agd enures
mens
anoactn Á
destnatn
enunes ranaHng Integrito
Mantaining TanSXn
obhngeo
rolls laal
tranoaction faulAas property
similor t
Parting Diredg rasoga
Ibatd on cients requeat
record
the
oud fraclet
SoA
actounHny
packae
Procucha
payro)
Hodub
Senia Buo
(nerpriu
BSB
seris auttenticain
Roris
made. contain
acout
into enplog
redutton els
into about
databax: hoo Containo into
relald to
prod
acountig Peckog'.
eneuring
gulatior Ye
qovernane s)
va
tol á
ensures
other Trawolation 2)
Servias
lala Trans cund
seriee Data 1)
n blw merng
Feature Core
compont senrioy to
Repositery jsty Pa
Managa
aglman: federation Qervle
o Aas
tolS
SLcuYHYe )
open
eeJava oodi SHend
and
nto pheNe webCxample
0 SB
produco
NeBeoo into
otup or OS )
knah inteated be cwBsB
enterporix
/Bagsh-tore the buina
pole Rposie ulps mthtainne tht
Servt
componant Jcodl.
terea actual wARdo
Cupostorka and ineing dstalo
dolus SoA ServiCs
( Be) orchstatH
buaino rocuo
modul
(orger ynaCanacoorinate enauing a
pusinen appVcan malintain
multple
oore togthey and
port CUo
apn
r a n t
Seure
’m
SeAVIce CATALOS
Hae
-there ore
cotaloss dataloane
is e direcio
Asorne coto appicaon' ocate
Undorshend avouala Sos
eatalog Ihclude
boeA Sernce
Wt
detads to waes
Provides
e eniCe e accmed
) Houotecan the Sorria dpundlnaeo
boo
ghows
pependercae eacn
othar
wh pa h
connectd
are
bo upd tl
and hocd (om
Servie Agremn Outlnes
be cono ore
Sykma ou Catalogs
As SoA
qnd manag n inproq sytempotem
FuNCTIONALITY MAPPINh
Som orplications
rted fo tue
claud travslatn
otHens uler from
luu applicaton ll bog
fmd out uhether cloud t0
5 to danlogmant at kotlc comfnont
from chud uy dpplicatm nto Sup poria
i brealkdo tht Cou be
idenity chitiçal f%
o data
appcaton that u
’ examps 8tore R
Some its
titaio vud to wmai
melator
AcD propAnSmpe
windows Agume
fo waintin tanaachiord
jst
Storag vecord loclhq
art o
ad ane
dadreevl
and ag
.woe
yate
anoactick
order
for a
functonaity
on the fop
attrbuo ore thre tncioning
>ugh el eraautial tor
factiona oe ae not
’ Soma othors
hereas
managemato
dLouw gn Data mthod
l oplores data areo
cviticalatiauto
A
-fo ooth
bota
Avalo ailitMoragart
Dota Momognent
Stat1
|Data,
Accers
(Acurmathod
Applicatton Atriaule
mgt be
te cnaded
applitatim nat
Istue
AbshacHon
Appliatim Arewtectctue
Contgaratn
ntoro oralbuty
Avaulaab calrg
Fudt fhonagènurt
SySTeH AsTRACTON>
troditana; ecallg d.
yaen into irtua elaud lanad gyten
>trawaomt miunyad nod for, on premy
inyru a martanAr eunamu chiorali
Erawmple: udial
Peviosly
>Pattt Scas reTocacreaJs
computr.
tered on He
were PN
hospitl da and accesad via
wers
for emote
>wignnra cost renote we
>nitt uent accen
aCcer to
)Tranatiowd to cloud
from tto
migatd Shor
mogeo were 'oasd
stered AN to cloud
) thospital
Step2 olon! oud.
task wieh
0PNY hoved to
wEr
baed macine
irtual macin
ction benia,
Syoteu tbstra tlaud
Beneft
Playib-Simplifird
- Scalalal'y wmaunagmart