Preview

Cloud Computing

Powerful Essays
Open Document
Open Document
17928 Words
Grammar
Grammar
Plagiarism
Plagiarism
Writing
Writing
Score
Score
Cloud Computing
Evaluating Cloud Risk for the Enterprise: A Shared Assessments Guide

October 2010
Published By

©2010 The Shared Assessments Program. All Rights Reserved.

Table of Contents
About the Shared Assessments Program ............................................................................................4 Acknowledgments ..............................................................................................................................6 Foreword .............................................................................................................................................7 Introduction.........................................................................................................................................8 Cloud Computing: An Overview ......................................................................................................11 A Risk Management Approach: Common and Delta Controls ........................................................15 Cloud Computing Case Study...........................................................................................................40 Glossary ............................................................................................................................................43 Appendix: Additional Cloud Computing Initiatives.........................................................................48

Evaluating Cloud Risk for the Enterprise: A Shared Assessments Guide ©2010 The Shared Assessments Program. All Rights Reserved.

2

©Shared Assessments 2010 Complete and accurate documents created under the Shared Assessments Program may be downloaded from the official Shared Assessments Program website at www.sharedassessments.org. While retaining copyrights, the Shared Assessments Program makes specific documents available to the public for the purpose of conducting self-assessments and third-party security assessments. Licenses for other uses are available from

You May Also Find These Documents Helpful

  • Good Essays

    Amazon: Amazon Elastic Compute Cloud (Amazon EC2) is a web service that provides resizable compute capacity in the cloud. It is designed to make web-scale computing easier for developers. Amazon EC2 is simple web service interface allows you to obtain and configure capacity with minimal friction. It provides you with complete control of your computing resources and lets you run on Amazon’s proven computing environment. Amazon EC2 reduces the time required to obtain and boot new server instances to minutes, allowing you to quickly scale capacity, both up and down, as your computing requirements change. Amazon EC2 changes the economics of computing by allowing you to pay only for capacity that you actually use. Amazon EC2 provides developers the tools to build failure tough applications and isolate themselves from common failure scenarios that are common amongst other cloud providers. Amazon EC2 presents a true virtual computing environment, allowing you to use web service interfaces to launch instances with a variety of operating systems, load them with your custom application environment, manage your network’s access permissions, and run your image with the number of systems as you desire. The Amazon EC2 will provide some of the following features:…

    • 1408 Words
    • 6 Pages
    Good Essays
  • Better Essays

    The assessment was conducted in accordance with the recommendations outlined in NIST SP 800-115 (Technical Guide to Information Security testing and Assessment). The results of this assessment will be used by [Organization] to drive future decisions as to the direction of their information security program. All test and actions were conducted under controlled conditions. (Security O. , 2012)…

    • 1355 Words
    • 5 Pages
    Better Essays
  • Powerful Essays

    Cloud Computing has the means to possibly revolutionize the healthcare IT structure as it is known today. Healthcare is constantly looking for ways to reduce costs but keep patient care in the forefront. At the same time introducing Cloud computing will have to be compliant with HIPPA guidelines set by the government. With Cloud Computing in healthcare, costs such as software cost will be reduced significantly. Many options are available for Cloud Computing along with options with limited budgets. This proposal will show how Cloud Computing can reduce costs in healthcare IT structures and still have the excellent patient care that all healthcare providers want.…

    • 4913 Words
    • 20 Pages
    Powerful Essays
  • Powerful Essays

    Security Dialogue 43(6) 495–512 © The Author(s) 2012 Reprints and permission: sagepub. co.uk/journalsPermissions.nav DOI: 10.1177/0967010612463488 sdi.sagepub.com…

    • 10783 Words
    • 44 Pages
    Powerful Essays
  • Powerful Essays

    Cloud Security Report

    • 9993 Words
    • 40 Pages

    Cloud Computing is the result of a rapid evolution of computing technologies and a response to the new world business requirements. The adoption of the technology is widely accepted and its future is promising. However the cloud computing phenomena does not come without a risk. There are many issues of concerns that might slow the adoption of the cloud computing; most notably are the security concerns which come as a result of the complexity of cloud technologies and the wide parties involved with them. Issues such as cloud computing compliance and governance, cloud computing deployment and architectural models, virtualization, cloud computing applications, cloud operations, standards, guidelines, frameworks and contracting for cloud service provisioning are all necessary for any business to understand before adopting the technology. This report will explain the top security risks of using cloud service providers for essential business applications and how they can be identified using the cloud risk assessment process. It will also explore various topics related to cloud computing, including concepts and terminologies of cloud security, risk assessment, frameworks and standards. It will conclude with a scenario of a case study to explain the process of analyzing a cloud service provider services security; and to show some of the most common cloud computing risks that exist in the world.…

    • 9993 Words
    • 40 Pages
    Powerful Essays
  • Powerful Essays

    Cloud Computing

    • 1763 Words
    • 7 Pages

    IT departments and infrastructure providers are under increasing pressure to provide computing infrastructure at the lowest possible cost. In order to do this, the concepts of resource pooling, virtualization, dynamic provisioning, utility and commodity computing must be leveraged to create a public or private cloud that meets these needs. Cloud computing is a general term for anything that involves delivering hosted services over the Internet. This provides the smaller companies or individuals who couldn’t able to buy costly software or any other resources. This becomes easy because of cloud computing. Cloud promises real costs savings and agility to customers. It’s a ‘Pay for Usage’ plan. We pay the money based on our usage only. Through cloud computing, a company can rapidly deploy applications where the underlying technology components. Access to applications and data anywhere, any Time, from any device is the potential outcome of cloud computing. This is suitable technology for limited budgets and a highly dynamic market with minimal resources.…

    • 1763 Words
    • 7 Pages
    Powerful Essays
  • Good Essays

    The use of this tool will help provide an assessment for the stakeholders on the effectiveness of the internal security and controls related to the cloud computing environment. Deficiencies within the internal controls can be identified. An assessment can be prepared for the stakeholders that will help them determine if the quality and reliability of the service they are being provided is compliant with the results of the internals control audits.…

    • 1171 Words
    • 5 Pages
    Good Essays
  • Better Essays

    Bibliography: Craig-Wood, K. (2010). Retrieved from http://www.katescomment.com/iaas-paas-saasdefinition/ VMware and Intel. (2010). New Power for Data Center Virtualization. Retrieved from http://ra.techtarget.com/leads/magnifierResponded.do?email=lmoyo@bhiretirement.org& resourceId=1285800393_587&leadFollowupPathId=3969819&site=bpmd&asrc=EM_R MU_20101214 Jo Maitland, Executive Editor of SearchCloudComputing.com. (2010). Infrastructure as a Service: How to maintain control. Retrieved from SearchCloudComputing.com: http://searchcloudcomputing.techtarget.com/generic/0,295582,sid201_gci1378172,00.ht ml Sudip Chahal, J. H.-S. (2010). An Enterprise Private Cloud Architecture and Implementation Roadmap. Retrieved from www.intel.com/IT Wilkins, G. (2010). A marketing foray into Cloud Computing - Part 1 - What 's it all about? Retrieved from http://rocketfuelmarketing.co.uk…

    • 920 Words
    • 4 Pages
    Better Essays
  • Powerful Essays

    Cloud Computing

    • 1296 Words
    • 6 Pages

    The author will explain in this case study how Ericsson benefitted from using Amazon Web Services (AWS) in terms of cost reduction, automated software updates, remote access, and on-demand availability. The study will also evaluate the scalability, dependability, manageability, and adaptability of Amazon Elastic Compute Cloud (Amazon EC2), Amazon Simple Storage Services (Amazon S3), and RightScale. The author will also discuss the security concerns of cloud-based services and make suggestions to cope with these concerns. Lastly, the author will assess possible scalability, reliability, and cost issues associated with cloud computing, and make suggestions to overcome each of these issues.…

    • 1296 Words
    • 6 Pages
    Powerful Essays
  • Satisfactory Essays

    The brain and concussions

    • 502 Words
    • 3 Pages

    B Y: PA I G E M O R R I S O N & N I C O L E G O R M L E Y…

    • 502 Words
    • 3 Pages
    Satisfactory Essays
  • Satisfactory Essays

    What is the relationship between soft and hard universalism? Which of the two doctrines you agree with the most and which of the two you feel applies to our current social environment the most? Please be specific and provide one example.…

    • 649 Words
    • 2 Pages
    Satisfactory Essays
  • Better Essays

    Cloud Computing

    • 1742 Words
    • 7 Pages

    Ericsson was able to instantly take advantage of Amazon’s resources. Amazon’s AWS is able to build and manage a global infrastructure to the scale Ericsson needed to support their business. This infrastructure already being in place provides a cost savings benefit. They had the ability to deploy new applications and automated software updates instantly because they were able to scale up and down as demand changed or the business required it. They could access their cloud from anywhere thanks to the freedom of remote access. The web services provided Ericsson with a highly reliable, scalable, low-cost infrastructure platform with data center locations in the U.S., Europe, Singapore, and Japan. The company chose Amazon Web Services (AWS) because they felt AWS was the most integrated public cloud provider in the Rightscale Cloud Management Platform (Rightscale). “The Ericsson team states that having hosting centers in various regions was important for them. AWS also showed a better quality of service with solid management and a proven track record.” (Amazon Web Services, 2012)…

    • 1742 Words
    • 7 Pages
    Better Essays
  • Better Essays

    Secure Cloud

    • 1589 Words
    • 7 Pages

    CSQ1: Although cloud computing have the potential to deliver powerful benefits, they pose new challenges to system security and reliability. Cloud computing is indeed cloudy, and due to lack of transparency it creates so many problems. One of the major security issue is cloud computing is highly distributed. Cloud applications and application mash-ups reside in virtual libraries in large remote data centers and server mainly supplies business services and data management for multiple corporate and organizations clients.…

    • 1589 Words
    • 7 Pages
    Better Essays
  • Powerful Essays

    Cloud Computing Case Study

    • 1150 Words
    • 5 Pages

    As cloud computing develops in ubiquity, a large number of organizations are essentially rebranding their non-cloud items and administrations as "cloud computing." Always burrow more profound when assessing cloud offerings and remember that in the event that you need to purchase and oversee hardware and programming, what you're taking a gander at isn't generally cloud computing yet a false cloud.…

    • 1150 Words
    • 5 Pages
    Powerful Essays

Related Topics