Amity School of Engineering & Technology
Cloud Security
Course Code: CSE439
Dr. Nitish Kumar
Department of Computer Science & Engineering
ASET, Amity University, Noida
Amity School of Engineering & Technology
Legal and compliance issues in cloud security
Legal and compliance issues in cloud security are critical concerns for organizations that use
cloud services to store, process, and manage their data. Failing to address these issues can lead to
legal consequences, regulatory violations, and reputational damage. Here are some key legal and
compliance issues in cloud security:
[Link] Privacy and Protection:
Data Privacy Regulations: Many regions and countries have enacted data privacy regulations,
such as the European Union's General Data Protection Regulation (GDPR) and the California
Consumer Privacy Act (CCPA). These laws impose strict requirements on how organizations
collect, store, and process personal data. Cloud service providers must comply with these
regulations, and organizations using cloud services must ensure that their data handling practices
align with these laws.
[Link] Ownership:
Determining who owns the data stored in the cloud can be a complex issue. Cloud service
agreements often outline data ownership and usage rights. Organizations must clearly define data
ownership and usage terms in their contracts with cloud providers.
Amity School of Engineering & Technology
Legal and compliance issues in cloud security
[Link] Audits:
Many industries, such as healthcare (HIPAA), finance (PCI DSS), and government, have specific
compliance requirements for data handling and security. Cloud users are responsible for ensuring that
their cloud infrastructure and practices comply with these industry-specific regulations. Audits may be
required to demonstrate compliance.
[Link] Issues:
Data stored in the cloud may be subject to the laws and regulations of the country or region where the
cloud provider's data centers are located. Organizations must consider the potential legal implications
of storing data in different jurisdictions and assess the associated risks.
5. Compliance Audits:
Many industries, such as healthcare (HIPAA), finance (PCI DSS), and government, have specific
compliance requirements for data handling and security. Cloud users are responsible for ensuring that
their cloud infrastructure and practices comply with these industry-specific regulations. Audits may be
required to demonstrate compliance.
Amity School of Engineering & Technology
Legal and compliance issues in cloud security
[Link] and Breach Notification:
Organizations are responsible for securing their data in the cloud. In the event of a data
breach or security incident, legal and regulatory requirements often mandate prompt
notification to affected parties, which can include customers, employees, and regulatory
authorities.
[Link] Level Agreements (SLAs):
•Cloud service agreements typically include SLAs that outline the level of service,
availability, and security that the cloud provider commits to. Understanding these SLAs
is crucial, as they may affect legal remedies and liabilities in case of service disruptions
or breaches.
Amity School of Engineering & Technology
Local laws, and Examination of modern Security Standards PCIDSS
• Local laws and regulations play a crucial role in shaping the security and compliance landscape for
organizations. One prominent set of security standards that organizations often need to adhere to is the
Payment Card Industry Data Security Standard (PCI DSS)
•Here's how local laws and regulations interact with the examination of modern security standards like
PCI DSS:
[Link] and Regulatory Environment:
Local laws and regulations vary from one jurisdiction to another. Organizations must be aware of and
comply with the specific data protection and cybersecurity laws applicable in their region or country.
These laws often set the baseline for data security and privacy requirements.
2 Alignment with PCI DSS:
PCI DSS is a global standard, but it is not a substitute for local laws and regulations. Organizations must
ensure that their security practices, including those related to cardholder data, are aligned with both PCI
DSS requirements and local legal requirements. In some cases, local laws may impose stricter standards
or additional obligations
Amity School of Engineering & Technology
Local laws, and Examination of modern Security Standards PCIDSS
[Link] Protection and Privacy Laws:
Many countries have comprehensive data protection and privacy laws that govern how organizations
collect, store, and process personal data. These laws may have specific provisions regarding the
protection of payment card data. Compliance with PCI DSS can help organizations meet some of these
requirements, but additional measures may be necessary to ensure full compliance.
4. Cross-Border Data Transfers:
If an organization processes payment card data across borders, they must consider data transfer
restrictions and requirements imposed by local laws. Some regions have strict rules on the cross-border
transfer of personal data, which can impact how cardholder data is stored and processed in the cloud or
at data centers located in different countries.
5. Legal Obligations in the Event of a Data Breach:
Local laws may mandate specific actions in the event of a data breach involving payment card data. This
can include notification requirements to affected individuals, regulatory authorities, and payment card
networks. Organizations must be prepared to meet these legal obligations while also complying with
PCI DSS breach reporting requirements.
Amity School of Engineering & Technology
Compliance for the cloud provider vs. Compliance for the customer.
Compliance in the context of cloud computing involves meeting various regulatory and security
requirements to ensure that data and services are handled in a secure and compliant manner.
Compliance responsibilities can be divided into two main categories: compliance for the cloud
provider and compliance for the customer.
[Link] for the Cloud Provider:
Cloud service providers (CSPs) are responsible for ensuring that their cloud infrastructure and
services meet certain industry standards and regulations. These responsibilities typically include:
a. Physical Security: CSPs are responsible for securing their data centers, including physical access
controls, surveillance, and protection against natural disasters. Compliance with standards like ISO
27001 demonstrates adherence to strong physical security practices.
b. Network and Data Security: Providers must implement robust network security measures to
protect customer data from unauthorized access, breaches, and data loss. Compliance with standards
like SOC 2 attests to the effectiveness of these controls.
Amity School of Engineering & Technology
Compliance for the Cloud Provider's..
c. Data Privacy and Encryption: CSPs should implement encryption mechanisms for
data at rest and in transit. They often must comply with data privacy regulations, such
as GDPR or HIPAA, to protect customer data adequately.
d. Compliance Certifications: Many CSPs seek third-party certifications and
attestations to demonstrate their compliance with industry-specific standards, such as
PCI DSS for payment card data or FedRAMP for government cloud services.
e. Incident Response: Cloud providers should have incident response plans in place to
address security incidents and breaches promptly. Compliance may require them to
notify customers and regulatory authorities in case of a data breach.
f. Availability and Uptime: CSPs must ensure high availability and uptime for their
services, often through service-level agreements (SLAs) that specify acceptable levels
of service interruptions.
Amity School of Engineering & Technology
Compliance for the Customer:
Customers using cloud services also have compliance responsibilities, which often depend on the nature of their
business, the type of data they handle, and the specific regulations they must adhere to. These responsibilities may
include:
a. Data Classification: Customers need to classify their data based on sensitivity and regulatory requirements.
Different data types may have varying access controls and encryption requirements.
b. Access Controls: Customers must configure and manage access controls within the cloud environment to ensure
that only authorized personnel can access data and resources.
c. Data Retention and Deletion: Compliance may require customers to establish data retention and deletion
policies to ensure that data is not kept longer than necessary and is disposed of properly.
d. Audit Trails: Customers should monitor and maintain audit logs of activities within their cloud environment to
demonstrate compliance and investigate security incidents.
e. Security Configurations: Customers are responsible for configuring security settings, firewalls, and security
groups to protect their cloud resources adequately.
f. User Training: Training employees and users on security best practices and compliance requirements is essential
to prevent security lapses and data breaches.
Amity School of Engineering & Technology
AWS Organizations-
•AWS Organizations is a service provided by Amazon Web Services (AWS)
that allows you to centrally manage and govern multiple AWS accounts within
your organization. It helps you to create and organize accounts, apply policies
across accounts, and simplify billing and cost management. AWS Organizations
is useful for enterprises and businesses that have multiple AWS accounts and
need to manage them more efficiently.
•AWS offers different support plan levels to assist customers with technical
support and access to AWS resources. As of my last knowledge update in
September 2021, AWS offers several support plans, including Basic, Developer,
Business, and Enterprise Support. Each support plan comes with different
service levels and features:
Amity School of Engineering & Technology
AWS different service levels and features:
[Link] Support:
Service Level: 24/7 customer service access, including email support.
Included: General guidance and documentation access.
[Link] Support:
Service Level: All Basic Support features, plus 12-hour response time during business hours.
Included: Technical support for AWS infrastructure and services, general guidance, best practices, and
architecture recommendations.
[Link] Support:
Service Level: All Developer Support features, plus a 1-hour response time during business hours.
Included: Technical support for all AWS services, infrastructure, and applications, as well as access to
AWS Trusted Advisor for cost optimization
Amity School of Engineering & Technology
AWS different service levels and features: Cont..
[Link] Support:
Service Level: All Business Support features, plus a 15-minute response time, 24/7.
Included: Extensive technical support, dedicated Technical Account Manager (TAM),
infrastructure event management, and access to AWS Infrastructure Event Management, AWS
Personal Health Dashboard, and AWS Trusted Advisor.
•Please note that AWS may update its support offerings, features, and pricing over time, so it's
essential to check the AWS website for the most up-to-date information on support plans and
their associated service levels.
• Additionally, organizations using AWS Organizations can choose to have consolidated billing
for their AWS accounts, which allows them to centralize billing and cost management across
multiple accounts. This is particularly useful for tracking and managing AWS expenses for
various departments or projects within an organization.
Amity School of Engineering & Technology
AWS Cloud Support Plans
• AWS offers four different support plans.
• Basic
• Developer
• Business
• Enterprise