1
1

00:00:00,480  -->  00:00:02,100
<v Presenter>Cloud models.</v>
2

2

00:00:02,100  -->  00:00:05,190
These days cloud computing is such a buzzword
3

3

00:00:05,190  -->  00:00:07,950
and everybody wants to migrate into the cloud.
4

4

00:00:07,950  -->  00:00:09,990
If you're working as a cybersecurity analyst though,
5

5

00:00:09,990  -->  00:00:12,180
you have to understand the vulnerabilities associated
6

6

00:00:12,180  -->  00:00:13,620
with moving into the cloud
7

7

00:00:13,620  -->  00:00:15,510
and that's what we're going to be focused on here.
8

8

00:00:15,510  -->  00:00:17,340
Now, while there is great savings to be had
9

9

00:00:17,340  -->  00:00:18,660
by moving to the cloud,
10

10

00:00:18,660  -->  00:00:21,120
we have to make sure we understand those security risks.
11

11

00:00:21,120  -->  00:00:23,670
But before we can dive into all those security risks,
12

12

00:00:23,670  -->  00:00:24,540
we really have to talk
13

13

00:00:24,540  -->  00:00:27,000
about the various cloud computing models that are used
14

14

00:00:27,000  -->  00:00:28,770
within the organizations these days.
15

15

00:00:28,770  -->  00:00:30,390
And as we do that, I will talk
16

16

00:00:30,390  -->  00:00:32,910
about the different risks associated with each one.
17

17

00:00:32,910  -->  00:00:34,350
These different models include things
18

18

00:00:34,350  -->  00:00:37,860
like public clouds, private clouds, community clouds,
19

19

00:00:37,860  -->  00:00:40,410
hybrid clouds, and multi-cloud setups.
20

20

00:00:40,410  -->  00:00:42,480
Now, when I talk about a cloud deployment model
21

21

00:00:42,480  -->  00:00:43,950
what do I really mean?
22

22

00:00:43,950  -->  00:00:45,780
Well, when we talk about a cloud deployment model
23

23

00:00:45,780  -->  00:00:47,730
we're talking about classifying the ownership
24

24

00:00:47,730  -->  00:00:50,580
and the management of the cloud as one of these categories.
25

25

00:00:50,580  -->  00:00:54,180
It's either public, private, community, or hybrid.
26

26

00:00:54,180  -->  00:00:56,100
Now, when I talk about the ownership and management
27

27

00:00:56,100  -->  00:00:58,080
it's who's responsible for what?
28

28

00:00:58,080  -->  00:00:59,640
Because there is a trade off here.
29

29

00:00:59,640  -->  00:01:01,920
When you move to the cloud, you don't own everything.
30

30

00:01:01,920  -->  00:01:03,810
There's certain things you're going to be responsible for
31

31

00:01:03,810  -->  00:01:06,660
as the consumer and certain things your cloud provider
32

32

00:01:06,660  -->  00:01:08,460
is going to be responsible for.
33

33

00:01:08,460  -->  00:01:09,960
Now these cloud deployment models
34

34

00:01:09,960  -->  00:01:11,130
have various vulnerabilities
35

35

00:01:11,130  -->  00:01:12,600
and threats associated with them
36

36

00:01:12,600  -->  00:01:15,480
depending on which one you choose, as I mentioned before.
37

37

00:01:15,480  -->  00:01:17,610
So let's go ahead and look at each of these.
38

38

00:01:17,610  -->  00:01:19,530
First we have the public cloud.
39

39

00:01:19,530  -->  00:01:21,300
Now, when we deal with the public cloud, we're dealing
40

40

00:01:21,300  -->  00:01:23,700
with a service provider making resources available
41

41

00:01:23,700  -->  00:01:26,040
to the end users over the internet.
42

42

00:01:26,040  -->  00:01:27,947
Now, really, when we talk about a public cloud
43

43

00:01:27,947  -->  00:01:30,090
we are talking about things that are being deployed
44

44

00:01:30,090  -->  00:01:33,510
for shared use by multiple independent tenants.
45

45

00:01:33,510  -->  00:01:34,380
And we talk about a tenant.
46

46

00:01:34,380  -->  00:01:36,090
Just think about that as a customer.
47

47

00:01:36,090  -->  00:01:39,690
It's somebody who is going to have access to those resources.
48

48

00:01:39,690  -->  00:01:41,173
Now, let me give you a great example of this.
49

49

00:01:41,173  -->  00:01:42,006
AWS.
50

50

00:01:42,006  -->  00:01:45,240
AWS is a great example of a public cloud.
51

51

00:01:45,240  -->  00:01:48,660
Anybody can go and buy services from AWS.
52

52

00:01:48,660  -->  00:01:51,960
Now, when I buy services and I put up a virtual site on a VM,
53

53

00:01:51,960  -->  00:01:53,940
inside one of these cloud centers,
54

54

00:01:53,940  -->  00:01:56,070
I'm sitting on AWS's hardware.
55

55

00:01:56,070  -->  00:01:58,740
And that hardware may not just have my servers
56

56

00:01:58,740  -->  00:02:00,090
it may have your servers
57

57

00:02:00,090  -->  00:02:02,670
and your company servers and your college's servers
58

58

00:02:02,670  -->  00:02:05,040
and we're all sitting on one server.
59

59

00:02:05,040  -->  00:02:07,050
Now, there are logical separations there
60

60

00:02:07,050  -->  00:02:09,510
but we're all still sitting on the same server.
61

61

00:02:09,510  -->  00:02:11,820
That's the idea when we start talking about public cloud
62

62

00:02:11,820  -->  00:02:14,010
because we don't own the resources, they are public.
63

63

00:02:14,010  -->  00:02:17,010
Anybody who pays for it can have access to it.
64

64

00:02:17,010  -->  00:02:19,740
Now, AWS does a really good job with their public cloud
65

65

00:02:19,740  -->  00:02:22,260
by making it available in lots of places.
66

66

00:02:22,260  -->  00:02:24,150
Everywhere you see a blue dot, that's one
67

67

00:02:24,150  -->  00:02:25,410
of the AWS regions.
68

68

00:02:25,410  -->  00:02:28,110
Everywhere you see an orange dot, that's a future region
69

69

00:02:28,110  -->  00:02:29,490
that's coming soon.
70

70

00:02:29,490  -->  00:02:32,040
Now, these data servers are all in these different regions
71

71

00:02:32,040  -->  00:02:33,780
so that way they can have higher redundancy
72

72

00:02:33,780  -->  00:02:35,130
and availability.
73

73

00:02:35,130  -->  00:02:36,840
So if I have my servers in the east coast
74

74

00:02:36,840  -->  00:02:38,880
of the United States over in Virginia, that's one
75

75

00:02:38,880  -->  00:02:39,930
of those blue dots.
76

76

00:02:39,930  -->  00:02:42,180
But I might have the same set of servers over
77

77

00:02:42,180  -->  00:02:44,730
in the west coast, over in Washington state
78

78

00:02:44,730  -->  00:02:46,890
and I might have another one over in England.
79

79

00:02:46,890  -->  00:02:48,390
And by having it in those three regions,
80

80

00:02:48,390  -->  00:02:50,160
I can have them all talk to each other.
81

81

00:02:50,160  -->  00:02:52,170
I can have them have data transfer back and forth
82

82

00:02:52,170  -->  00:02:53,610
and being replicated between 'em.
83

83

00:02:53,610  -->  00:02:55,920
That way if one of those three sites goes down,
84

84

00:02:55,920  -->  00:02:58,530
the other two can carry the load from my customers.
85

85

00:02:58,530  -->  00:02:59,670
This is one of the great things
86

86

00:02:59,670  -->  00:03:01,620
about public clouds because you can have yourself
87

87

00:03:01,620  -->  00:03:04,320
in lots of different places really, really quickly
88

88

00:03:04,320  -->  00:03:07,650
and that gives you great redundancy and great availability.
89

89

00:03:07,650  -->  00:03:09,810
Now, when we talk about these clouds though
90

90

00:03:09,810  -->  00:03:11,970
we have to think about who owns what.
91

91

00:03:11,970  -->  00:03:14,970
When we talk about this, think about public clouds this way,
92

92

00:03:14,970  -->  00:03:16,590
you're going to have the infrastructure,
93

93

00:03:16,590  -->  00:03:19,350
the application code, and the data that's being hosted
94

94

00:03:19,350  -->  00:03:21,030
within these private instances.
95

95

00:03:21,030  -->  00:03:24,810
But you have no ability to control the physical server.
96

96

00:03:24,810  -->  00:03:26,490
I can't go to Amazon and say, Hey
97

97

00:03:26,490  -->  00:03:28,320
I want to walk in and touch my server.
98

98

00:03:28,320  -->  00:03:29,730
They're not going to let me do that.
99

99

00:03:29,730  -->  00:03:33,330
I don't have physical access, but I do have logical access.
100

100

00:03:33,330  -->  00:03:34,890
And so I might have this private instance
101

101

00:03:34,890  -->  00:03:37,590
of my server inside this virtual thing sitting
102

102

00:03:37,590  -->  00:03:40,740
on their bigger servers, their physical servers.
103

103

00:03:40,740  -->  00:03:43,200
Now this brings up the question on who's responsible
104

104

00:03:43,200  -->  00:03:45,660
for the security of a public cloud?
105

105

00:03:45,660  -->  00:03:48,060
Well, this is kind of a hard question to answer, right?
106

106

00:03:48,060  -->  00:03:50,670
Because we each have our own responsibilities.
107

107

00:03:50,670  -->  00:03:53,250
If I'm the cloud service provider like Amazon,
108

108

00:03:53,250  -->  00:03:54,480
I have the responsibility
109

109

00:03:54,480  -->  00:03:57,240
for integrity and availability of the platform.
110

110

00:03:57,240  -->  00:03:58,073
Now, what do I mean
111

111

00:03:58,073  -->  00:04:00,600
by this integrity and availability of the platform?
112

112

00:04:00,600  -->  00:04:02,580
Well, Amazon is responsible
113

113

00:04:02,580  -->  00:04:05,130
for making sure the physical server stays up.
114

114

00:04:05,130  -->  00:04:07,410
It has the right power, it has the right cooling,
115

115

00:04:07,410  -->  00:04:08,490
it has the right bandwidth
116

116

00:04:08,490  -->  00:04:11,160
and it has the right redundancy from a physical component.
117

117

00:04:11,160  -->  00:04:12,960
So if they're going to store something there,
118

118

00:04:12,960  -->  00:04:14,910
they should have it on a rate array, for instance.
119

119

00:04:14,910  -->  00:04:17,280
So if one of the drives fails, the other one picks up
120

120

00:04:17,280  -->  00:04:19,050
or if we put it on their storage area network,
121

121

00:04:19,050  -->  00:04:21,030
they have it mirrored and backed up to make sure
122

122

00:04:21,030  -->  00:04:22,920
that it's always up and ready to go.
123

123

00:04:22,920  -->  00:04:24,660
That's the availability piece.
124

124

00:04:24,660  -->  00:04:27,180
Now, the integrity piece is to make sure nobody messes
125

125

00:04:27,180  -->  00:04:29,820
with my data, nobody changes it, modifies it.
126

126

00:04:29,820  -->  00:04:31,617
When I write it there, it should stay there
127

127

00:04:31,617  -->  00:04:34,290
and it shouldn't be modified by their underlying server.
128

128

00:04:34,290  -->  00:04:36,120
Now, as the consumer though,
129

129

00:04:36,120  -->  00:04:38,210
I have the responsibility to manage the confidentiality
130

130

00:04:38,210  -->  00:04:40,080
of my systems as well
131

131

00:04:40,080  -->  00:04:42,480
as the authorization and the authentication.
132

132

00:04:42,480  -->  00:04:44,310
So if I'm using their service,
133

133

00:04:44,310  -->  00:04:47,040
I'm going to be able to have access to the data
134

134

00:04:47,040  -->  00:04:48,450
but I'm responsible to make sure
135

135

00:04:48,450  -->  00:04:50,100
that data is properly stored
136

136

00:04:50,100  -->  00:04:51,720
and the right people have access
137

137

00:04:51,720  -->  00:04:54,690
to it by doing authorization authentication.
138

138

00:04:54,690  -->  00:04:57,600
Now, the next area we want to talk about is private clouds.
139

139

00:04:57,600  -->  00:04:59,730
Now, private clouds is where a company creates
140

140

00:04:59,730  -->  00:05:02,370
its own cloud environment that only it can utilize
141

141

00:05:02,370  -->  00:05:04,860
as an internal enterprise resource.
142

142

00:05:04,860  -->  00:05:06,510
So what might this look like?
143

143

00:05:06,510  -->  00:05:10,770
Well, let's say that I decide to go and buy my own servers.
144

144

00:05:10,770  -->  00:05:13,590
I put them in three different locations around the world.
145

145

00:05:13,590  -->  00:05:15,960
I now have multiple servers sitting in different locations
146

146

00:05:15,960  -->  00:05:17,940
around the world, and I tie them all together.
147

147

00:05:17,940  -->  00:05:19,680
That would be a private cloud.
148

148

00:05:19,680  -->  00:05:21,180
Now, what's great about doing that?
149

149

00:05:21,180  -->  00:05:23,040
Well, I have full control.
150

150

00:05:23,040  -->  00:05:25,470
I control the hardware, I control the software.
151

151

00:05:25,470  -->  00:05:26,820
I control the entire stack.
152

152

00:05:26,820  -->  00:05:28,710
It's mine because it's private.
153

153

00:05:28,710  -->  00:05:31,560
Now, a private cloud can be hosted both internally
154

154

00:05:31,560  -->  00:05:32,550
or externally.
155

155

00:05:32,550  -->  00:05:34,110
This is really up to you.
156

156

00:05:34,110  -->  00:05:36,630
So I might take my physical server and put it
157

157

00:05:36,630  -->  00:05:39,420
in somebody else's data farm, but again, I own it
158

158

00:05:39,420  -->  00:05:42,570
and I have access to walk in and touch it anytime I want.
159

159

00:05:42,570  -->  00:05:43,830
That's part of that agreement.
160

160

00:05:43,830  -->  00:05:45,240
Or I can do it internally.
161

161

00:05:45,240  -->  00:05:47,550
Maybe I have three corporate offices around the world
162

162

00:05:47,550  -->  00:05:49,950
and I can put these servers in those three offices
163

163

00:05:49,950  -->  00:05:52,020
and that way it would be hosted internally.
164

164

00:05:52,020  -->  00:05:53,370
Either way is acceptable.
165

165

00:05:53,370  -->  00:05:54,450
Let me give you a great example
166

166

00:05:54,450  -->  00:05:56,490
of an externally hosted private cloud.
167

167

00:05:56,490  -->  00:05:57,720
There is something in the United States
168

168

00:05:57,720  -->  00:05:59,850
known as the AWS GovCloud.
169

169

00:05:59,850  -->  00:06:03,450
And as you can guess, AWS means Amazon Web Services.
170

170

00:06:03,450  -->  00:06:07,080
So what this is is the US government has given a contract
171

171

00:06:07,080  -->  00:06:11,250
to Amazon to stand up their cloud for the government.
172

172

00:06:11,250  -->  00:06:13,410
So these are servers that were bought
173

173

00:06:13,410  -->  00:06:16,290
and paid for under contract for the US government.
174

174

00:06:16,290  -->  00:06:18,840
Nobody else can use it, but the US government.
175

175

00:06:18,840  -->  00:06:20,160
So if you work
176

176

00:06:20,160  -->  00:06:21,900
for the Bureau of Indian Affairs, which is one
177

177

00:06:21,900  -->  00:06:23,880
of our departments underneath the US government,
178

178

00:06:23,880  -->  00:06:25,410
they can have access to the GovCloud.
179

179

00:06:25,410  -->  00:06:27,270
If you work for the Department of Defense,
180

180

00:06:27,270  -->  00:06:28,350
you work for the US government,
181

181

00:06:28,350  -->  00:06:30,060
you can have access to the GovCloud.
182

182

00:06:30,060  -->  00:06:32,100
If you work for Social Security Administration,
183

183

00:06:32,100  -->  00:06:33,900
you can have access to the GovCloud.
184

184

00:06:33,900  -->  00:06:36,240
But Dion Training, we don't work for the government.
185

185

00:06:36,240  -->  00:06:38,240
We cannot have access to the GovCloud.
186

186

00:06:38,240  -->  00:06:39,900
And so these are servers that were stood up
187

187

00:06:39,900  -->  00:06:42,150
specifically for the use by the government.
188

188

00:06:42,150  -->  00:06:43,950
So it is a private cloud in this case
189

189

00:06:43,950  -->  00:06:47,190
it's a contracted private cloud and it's hosted externally.
190

190

00:06:47,190  -->  00:06:51,210
Now, a private cloud should be chosen when you have security
191

191

00:06:51,210  -->  00:06:52,350
as your main concern.
192

192

00:06:52,350  -->  00:06:55,620
If you want more security and you're not worried about cost,
193

193

00:06:55,620  -->  00:06:57,240
you can move to a private cloud.
194

194

00:06:57,240  -->  00:06:58,710
That's what the GovCloud is.
195

195

00:06:58,710  -->  00:07:00,150
They wanted to have more security
196

196

00:07:00,150  -->  00:07:02,550
than just having regular old AWS.
197

197

00:07:02,550  -->  00:07:04,650
So they have their own servers that are hosted
198

198

00:07:04,650  -->  00:07:06,990
by AWS and only used by the government.
199

199

00:07:06,990  -->  00:07:09,540
That way there can't be co-mingling of data.
200

200

00:07:09,540  -->  00:07:12,390
This is what we consider a single tenant model.
201

201

00:07:12,390  -->  00:07:14,700
When you're talking about private clouds, think about this.
202

202

00:07:14,700  -->  00:07:16,440
It is a single tenant model,
203

203

00:07:16,440  -->  00:07:19,860
one company or one organization being able to use it.
204

204

00:07:19,860  -->  00:07:20,750
In the case of GovCloud,
205

205

00:07:20,750  -->  00:07:23,070
it is multiple smaller organizations,
206

206

00:07:23,070  -->  00:07:24,330
but all of those organizations
207

207

00:07:24,330  -->  00:07:25,620
are owned by the US government.
208

208

00:07:25,620  -->  00:07:28,710
So it is still one organization, the US government.
209

209

00:07:28,710  -->  00:07:29,700
Now, as I said,
210

210

00:07:29,700  -->  00:07:31,980
one of the drawbacks to using a private cloud
211

211

00:07:31,980  -->  00:07:34,500
is private clouds are much more expensive.
212

212

00:07:34,500  -->  00:07:35,333
Why?
213

213

00:07:35,333  -->  00:07:37,470
Because you have to pay for all the hardware
214

214

00:07:37,470  -->  00:07:39,750
and you're paying for the entire use of the server
215

215

00:07:39,750  -->  00:07:41,970
whether or not you're using the entire use of the server.
216

216

00:07:41,970  -->  00:07:43,980
Now, what do I mean by that?
217

217

00:07:43,980  -->  00:07:46,110
Well, let's say I bought a bunch of servers
218

218

00:07:46,110  -->  00:07:49,620
for this GovCloud, and I'm only using 50% of the capacity.
219

219

00:07:49,620  -->  00:07:50,453
Well, guess what?
220

220

00:07:50,453  -->  00:07:51,810
I paid for 100% capacity.
221

221

00:07:51,810  -->  00:07:53,040
'Cause I bought the hardware,
222

222

00:07:53,040  -->  00:07:54,900
I bought the software, I bought the licenses.
223

223

00:07:54,900  -->  00:07:55,950
And whether I'm using it or not,
224

224

00:07:55,950  -->  00:07:57,330
I'm paying for the whole thing.
225

225

00:07:57,330  -->  00:07:58,890
So it's more expensive.
226

226

00:07:58,890  -->  00:08:01,470
Now, if I was using a public cloud, I'd only pay
227

227

00:08:01,470  -->  00:08:03,720
for what I'm using because Amazon bought all the servers,
228

228

00:08:03,720  -->  00:08:06,060
they bought all the hardware, they bought all the software
229

229

00:08:06,060  -->  00:08:07,800
and they pay for all the infrastructure.
230

230

00:08:07,800  -->  00:08:10,080
And so I'm only paying on a per usage basis
231

231

00:08:10,080  -->  00:08:11,520
under a public cloud model.
232

232

00:08:11,520  -->  00:08:12,900
And so when you use a private cloud,
233

233

00:08:12,900  -->  00:08:14,520
think it's going to cost more.
234

234

00:08:14,520  -->  00:08:17,010
Again, security is more important than money here.
235

235

00:08:17,010  -->  00:08:19,110
That's when we go to a private cloud.
236

236

00:08:19,110  -->  00:08:20,880
So as a private cloud administrator,
237

237

00:08:20,880  -->  00:08:22,650
what is your responsibility?
238

238

00:08:22,650  -->  00:08:24,570
Well, if you're a private cloud administrator
239

239

00:08:24,570  -->  00:08:27,120
you have to consider the data protection, the compliance
240

240

00:08:27,120  -->  00:08:28,350
and the patch management.
241

241

00:08:28,350  -->  00:08:29,183
Why?
242

242

00:08:29,183  -->  00:08:31,860
Because you own the servers, you own the infrastructure.
243

243

00:08:31,860  -->  00:08:33,600
All you get is bare metal here,
244

244

00:08:33,600  -->  00:08:35,610
and you have to do everything yourself
245

245

00:08:35,610  -->  00:08:37,650
because you're running your own cloud.
246

246

00:08:37,650  -->  00:08:39,810
And so this is one of the reasons that it costs more
247

247

00:08:39,810  -->  00:08:41,910
as well, because you have to pay people to do all
248

248

00:08:41,910  -->  00:08:44,430
of this work, and it's going to have a lot more oversight
249

249

00:08:44,430  -->  00:08:46,050
in terms of the things you have to do
250

250

00:08:46,050  -->  00:08:48,090
from a security standpoint.
251

251

00:08:48,090  -->  00:08:50,100
Now, another type of cloud we have is what's known
252

252

00:08:50,100  -->  00:08:51,600
as the community cloud.
253

253

00:08:51,600  -->  00:08:53,460
Now, a community cloud uses resources
254

254

00:08:53,460  -->  00:08:54,990
and costs that are shared among
255

255

00:08:54,990  -->  00:08:56,550
several different organizations who have
256

256

00:08:56,550  -->  00:08:58,410
a common service need.
257

257

00:08:58,410  -->  00:09:00,930
Let's say that I ran a credit union or a bank
258

258

00:09:00,930  -->  00:09:02,700
and you ran a credit union or a bank.
259

259

00:09:02,700  -->  00:09:04,830
We both want to set up some kind of a cloud service
260

260

00:09:04,830  -->  00:09:06,780
to store our records to make sure they're secure
261

261

00:09:06,780  -->  00:09:08,700
and we can have them for all of our regulatory requirements
262

262

00:09:08,700  -->  00:09:10,470
say four or five or 10 years.
263

263

00:09:10,470  -->  00:09:11,850
Well, we need a cloud to do that.
264

264

00:09:11,850  -->  00:09:13,050
Do we want to put on AWS
265

265

00:09:13,050  -->  00:09:14,850
or Azure and put on the public cloud?
266

266

00:09:14,850  -->  00:09:15,840
Probably not.
267

267

00:09:15,840  -->  00:09:17,370
Do we want to set our own private cloud each
268

268

00:09:17,370  -->  00:09:19,680
because it'd be really expensive, probably not.
269

269

00:09:19,680  -->  00:09:22,140
So we might get other banks to work with us and we get four
270

270

00:09:22,140  -->  00:09:24,960
or five or six or 10 banks, and we all form a community.
271

271

00:09:24,960  -->  00:09:27,180
We can share the cost of setting this thing up.
272

272

00:09:27,180  -->  00:09:29,130
Now, a community cloud is deployed using what
273

273

00:09:29,130  -->  00:09:32,340
we call a shared use by cooperating tenants.
274

274

00:09:32,340  -->  00:09:33,900
What this means is there's five
275

275

00:09:33,900  -->  00:09:36,450
or 10 different organizations and we all come together.
276

276

00:09:36,450  -->  00:09:38,490
We share the cost, we share the responsibility,
277

277

00:09:38,490  -->  00:09:39,570
we share the security.
278

278

00:09:39,570  -->  00:09:42,120
So we're a community. We all work together.
279

279

00:09:42,120  -->  00:09:43,050
Now, there's some good things
280

280

00:09:43,050  -->  00:09:44,820
about this and bad things about it.
281

281

00:09:44,820  -->  00:09:46,170
When everybody in the community helps
282

282

00:09:46,170  -->  00:09:47,550
with designing the cloud,
283

283

00:09:47,550  -->  00:09:50,430
we can have really good security or really bad security.
284

284

00:09:50,430  -->  00:09:52,080
It depends on who's in it.
285

285

00:09:52,080  -->  00:09:54,300
Now, when we take the security together and we all work
286

286

00:09:54,300  -->  00:09:57,060
as a community, say that I had really high security needs
287

287

00:09:57,060  -->  00:09:58,710
and you had low security needs,
288

288

00:09:58,710  -->  00:10:00,840
do you want to pay for my high security needs?
289

289

00:10:00,840  -->  00:10:01,710
Probably not.
290

290

00:10:01,710  -->  00:10:03,510
And so we're going to have to have a discussion
291

291

00:10:03,510  -->  00:10:04,980
and we're going to have to negotiate what those
292

292

00:10:04,980  -->  00:10:06,330
security needs are going to be.
293

293

00:10:06,330  -->  00:10:08,160
And maybe I had a security need of 10,
294

294

00:10:08,160  -->  00:10:09,750
you had a security need of two
295

295

00:10:09,750  -->  00:10:11,790
and we meet in the middle at say six.
296

296

00:10:11,790  -->  00:10:15,240
Well, if we do that, we have now met the common denominator
297

297

00:10:15,240  -->  00:10:17,520
which means I brought my level of security down
298

298

00:10:17,520  -->  00:10:19,590
which is bad for me, and you brought yours up
299

299

00:10:19,590  -->  00:10:22,350
and now paid more for security you really didn't care about.
300

300

00:10:22,350  -->  00:10:23,430
And so these are some of the things
301

301

00:10:23,430  -->  00:10:25,380
in the design considerations that you have to think
302

302

00:10:25,380  -->  00:10:26,280
about when you're working
303

303

00:10:26,280  -->  00:10:28,230
with the community cloud deployment.
304

304

00:10:28,230  -->  00:10:31,050
Now, community clouds are secure when the organizations
305

305

00:10:31,050  -->  00:10:34,500
involved have strong, interoperability agreements.
306

306

00:10:34,500  -->  00:10:36,960
Remember, we're all connecting to the same cloud
307

307

00:10:36,960  -->  00:10:38,310
because it's a community.
308

308

00:10:38,310  -->  00:10:40,260
And so again, going back to my bank example.
309

309

00:10:40,260  -->  00:10:42,750
If my bank is known as being the most secure out there
310

310

00:10:42,750  -->  00:10:44,010
and we're a level 10
311

311

00:10:44,010  -->  00:10:46,560
and you're a level two and you connect your network
312

312

00:10:46,560  -->  00:10:49,410
to our new community cloud with your level two security
313

313

00:10:49,410  -->  00:10:51,780
and I connect my level 10 to this cloud
314

314

00:10:51,780  -->  00:10:54,390
and now I'm connected, what to you through that cloud?
315

315

00:10:54,390  -->  00:10:56,190
And so your level two people can break in
316

316

00:10:56,190  -->  00:10:58,230
through your network and get into our cloud that way
317

317

00:10:58,230  -->  00:11:00,660
and then go from that cloud into my network.
318

318

00:11:00,660  -->  00:11:03,210
And so these IOP operations are important to think about.
319

319

00:11:03,210  -->  00:11:04,890
And when you have interoperability agreements
320

320

00:11:04,890  -->  00:11:06,870
you need to make sure you have the right security
321

321

00:11:06,870  -->  00:11:09,480
in place so everybody's meeting a baseline level
322

322

00:11:09,480  -->  00:11:12,060
of security that you all can live with.
323

323

00:11:12,060  -->  00:11:14,130
Now, the next thing we're going to talk about is what's known
324

324

00:11:14,130  -->  00:11:15,420
as a hybrid cloud.
325

325

00:11:15,420  -->  00:11:18,150
Now, a hybrid cloud is going to combine different types
326

326

00:11:18,150  -->  00:11:20,970
of clouds like public, private and community clouds,
327

327

00:11:20,970  -->  00:11:22,830
as well as on-premise infrastructure
328

328

00:11:22,830  -->  00:11:25,110
to meet an organization's needs.
329

329

00:11:25,110  -->  00:11:27,690
Sometimes just one of these clouds isn't enough.
330

330

00:11:27,690  -->  00:11:30,360
I might not want to use all of my systems as a public cloud
331

331

00:11:30,360  -->  00:11:32,670
because I'm worried about security of certain systems.
332

332

00:11:32,670  -->  00:11:34,530
I might not want to use a private cloud for everything
333

333

00:11:34,530  -->  00:11:35,820
because it costs too much.
334

334

00:11:35,820  -->  00:11:38,370
So I can combine those two together.
335

335

00:11:38,370  -->  00:11:40,980
I can say maybe that all my credit card and financial data
336

336

00:11:40,980  -->  00:11:44,010
will be kept in a private cloud, but all of my customer
337

337

00:11:44,010  -->  00:11:46,650
facing stuff that is supposed to be open to the public,
338

338

00:11:46,650  -->  00:11:48,150
will be on the public cloud.
339

339

00:11:48,150  -->  00:11:49,620
And so I can mitigate my risk
340

340

00:11:49,620  -->  00:11:52,560
and mitigate my cost by doing this hybrid approach.
341

341

00:11:52,560  -->  00:11:54,300
Now, what are some of the things you have to consider
342

342

00:11:54,300  -->  00:11:55,890
when dealing with a hybrid cloud?
343

343

00:11:55,890  -->  00:11:58,290
Well, they have greater complexity.
344

344

00:11:58,290  -->  00:12:01,110
Hybrid clouds have to deal with the scripted infrastructure
345

345

00:12:01,110  -->  00:12:03,630
and orchestration tools to be able to spin the instances
346

346

00:12:03,630  -->  00:12:05,940
up and tear instances down and make sure
347

347

00:12:05,940  -->  00:12:08,190
that all the connection between them are working.
348

348

00:12:08,190  -->  00:12:10,320
So if I'm going to have to operate both a private
349

349

00:12:10,320  -->  00:12:12,480
and a public cloud and I have to connect them together,
350

350

00:12:12,480  -->  00:12:15,000
that's more complex than just doing one or the other.
351

351

00:12:15,000  -->  00:12:16,020
Another thing you need to think
352

352

00:12:16,020  -->  00:12:17,070
about when you're dealing with public
353

353

00:12:17,070  -->  00:12:20,400
and private clouds is do you have the right data redundancy?
354

354

00:12:20,400  -->  00:12:21,690
You want to make sure you don't have an absence
355

355

00:12:21,690  -->  00:12:23,070
of data redundancy.
356

356

00:12:23,070  -->  00:12:23,903
Now, what I mean
357

357

00:12:23,903  -->  00:12:25,980
by this is sometimes people will have a hybrid environment
358

358

00:12:25,980  -->  00:12:27,180
and they'll go, well, I'm already paying
359

359

00:12:27,180  -->  00:12:28,710
for public and I'm already paying for private
360

360

00:12:28,710  -->  00:12:30,390
so I must have redundancy.
361

361

00:12:30,390  -->  00:12:31,223
But the public
362

362

00:12:31,223  -->  00:12:33,300
and private are doing two different functions,
363

363

00:12:33,300  -->  00:12:35,130
so there really is no redundancy there.
364

364

00:12:35,130  -->  00:12:36,540
So you might have to have a private cloud
365

365

00:12:36,540  -->  00:12:39,480
with full redundancy and a public cloud with full redundancy
366

366

00:12:39,480  -->  00:12:41,280
in addition to the connection between the two.
367

367

00:12:41,280  -->  00:12:43,110
So keep that in mind as well.
368

368

00:12:43,110  -->  00:12:44,340
Another thing that makes it a little bit more
369

369

00:12:44,340  -->  00:12:45,660
difficult when you're dealing with hybrids
370

370

00:12:45,660  -->  00:12:47,670
is to demonstrate your compliance.
371

371

00:12:47,670  -->  00:12:49,560
If you're at a highly litigious area
372

372

00:12:49,560  -->  00:12:51,900
and you have regulations and compliance requirements,
373

373

00:12:51,900  -->  00:12:53,790
moving to a hybrid model can make it harder
374

374

00:12:53,790  -->  00:12:54,623
for you to meet those
375

375

00:12:54,623  -->  00:12:57,150
because now you're not just dealing with the public cloud,
376

376

00:12:57,150  -->  00:12:58,620
you're not just dealing with the private cloud,
377

377

00:12:58,620  -->  00:12:59,610
but you're dealing with both
378

378

00:12:59,610  -->  00:13:01,170
and the interconnection between the two.
379

379

00:13:01,170  -->  00:13:03,810
So again, having that greater complexity makes it harder
380

380

00:13:03,810  -->  00:13:05,640
for you to demonstrate compliance.
381

381

00:13:05,640  -->  00:13:07,350
And finally, security management.
382

382

00:13:07,350  -->  00:13:08,910
Now again, you're not just doing private,
383

383

00:13:08,910  -->  00:13:10,770
you're not just doing public, you're doing both.
384

384

00:13:10,770  -->  00:13:12,780
And so you have security management concerns.
385

385

00:13:12,780  -->  00:13:14,670
You need to make sure you have the right authentication
386

386

00:13:14,670  -->  00:13:17,130
and authorization and identity management to work
387

387

00:13:17,130  -->  00:13:19,500
in both the private and the public cloud.
388

388

00:13:19,500  -->  00:13:20,970
You also need to make sure there's replication
389

389

00:13:20,970  -->  00:13:23,220
between the two of your security infrastructure.
390

390

00:13:23,220  -->  00:13:24,750
You need to make sure you have communications
391

391

00:13:24,750  -->  00:13:25,583
between the two
392

392

00:13:25,583  -->  00:13:27,600
and those are secure and properly channeled.
393

393

00:13:27,600  -->  00:13:28,800
All of these are things you have to think
394

394

00:13:28,800  -->  00:13:30,870
about when you're dealing with a hybrid model.
395

395

00:13:30,870  -->  00:13:31,890
The last thing we want to talk
396

396

00:13:31,890  -->  00:13:34,230
about here is what's known as multi-cloud.
397

397

00:13:34,230  -->  00:13:36,480
Now, multi-cloud is just like a sounds.
398

398

00:13:36,480  -->  00:13:38,730
It's a cloud deployment where the cloud consumer
399

399

00:13:38,730  -->  00:13:41,490
is going to use multiple public cloud services.
400

400

00:13:41,490  -->  00:13:43,560
So if I have an organization
401

401

00:13:43,560  -->  00:13:45,660
and I'm using lots of different things, for instance
402

402

00:13:45,660  -->  00:13:48,780
I might be using Amazon Web Services to host my website.
403

403

00:13:48,780  -->  00:13:50,490
I'm using Slack for communication.
404

404

00:13:50,490  -->  00:13:52,380
I'm using Zoom for live meetings.
405

405

00:13:52,380  -->  00:13:54,930
I'm using Google's G-suite for me to able to do my docs
406

406

00:13:54,930  -->  00:13:56,790
and my sheets and my Google Drive,
407

407

00:13:56,790  -->  00:13:57,720
and maybe some of my employees
408

408

00:13:57,720  -->  00:14:00,930
are also using Microsoft 365 or Word and Excel
409

409

00:14:00,930  -->  00:14:02,340
and PowerPoint.
410

410

00:14:02,340  -->  00:14:04,170
All of these are cloud tools.
411

411

00:14:04,170  -->  00:14:06,060
They're all public cloud tools.
412

412

00:14:06,060  -->  00:14:07,830
Now, if I'm using all of these,
413

413

00:14:07,830  -->  00:14:10,470
this puts me into what's known as a multi-cloud environment
414

414

00:14:10,470  -->  00:14:12,450
because we're using lots of different tools
415

415

00:14:12,450  -->  00:14:14,190
in lots of different ways.
416

416

00:14:14,190  -->  00:14:15,810
Anytime you start adding more tools
417

417

00:14:15,810  -->  00:14:17,490
and you start adding more clouds,
418

418

00:14:17,490  -->  00:14:19,350
you are dealing with more complexity.
419

419

00:14:19,350  -->  00:14:21,780
And so using multiple cloud service providers
420

420

00:14:21,780  -->  00:14:23,640
does require additional due diligence
421

421

00:14:23,640  -->  00:14:25,140
and risk assessment effort
422

422

00:14:25,140  -->  00:14:27,870
because you have to think what is the risk involved.
423

423

00:14:27,870  -->  00:14:30,840
For instance, when the global pandemic with COVID happened,
424

424

00:14:30,840  -->  00:14:33,210
lots of people moved on to using Zoom.
425

425

00:14:33,210  -->  00:14:34,770
They didn't think about the fact that Zoom
426

426

00:14:34,770  -->  00:14:37,140
at the time did not have end-to-end encryption.
427

427

00:14:37,140  -->  00:14:39,270
So you could be having a conference and somebody
428

428

00:14:39,270  -->  00:14:41,250
could actually be listening to what you're saying
429

429

00:14:41,250  -->  00:14:43,350
or they could actually jump into your Zoom call
430

430

00:14:43,350  -->  00:14:45,210
because they weren't password protected.
431

431

00:14:45,210  -->  00:14:46,380
These are all things you have to think about
432

432

00:14:46,380  -->  00:14:48,180
from a risk assessment effort.
433

433

00:14:48,180  -->  00:14:50,130
Now, as you're going through and doing this
434

434

00:14:50,130  -->  00:14:51,690
because you have multiple tools,
435

435

00:14:51,690  -->  00:14:53,340
this is going to become more complicated
436

436

00:14:53,340  -->  00:14:54,810
and more time consuming.
437

437

00:14:54,810  -->  00:14:57,480
Now, that was a ton of information.
438

438

00:14:57,480  -->  00:14:59,730
So let me give you a quick exam tip.
439

439

00:14:59,730  -->  00:15:02,100
For the exam, what do you need to know?
440

440

00:15:02,100  -->  00:15:04,050
You need to know the five different types
441

441

00:15:04,050  -->  00:15:05,520
of clouds that we talked about,
442

442

00:15:05,520  -->  00:15:10,500
public, private, community, hybrid, and multi-cloud.
443

443

00:15:10,500  -->  00:15:12,780
You need to know what the benefits and the drawbacks are
444

444

00:15:12,780  -->  00:15:16,230
for each of them in terms of security and cost.
445

445

00:15:16,230  -->  00:15:19,110
And you should understand when you should use each one.
446

446

00:15:19,110  -->  00:15:20,910
Or if I give you an example of one,
447

447

00:15:20,910  -->  00:15:22,980
you should be able to say based on that example
448

448

00:15:22,980  -->  00:15:25,440
this sounds like a, blank, type of cloud.
449

449

00:15:25,440  -->  00:15:26,910
For instance, if I say
450

450

00:15:26,910  -->  00:15:29,820
that your company is using Amazon Web Services
451

451

00:15:29,820  -->  00:15:31,770
to be able to host your infrastructure
452

452

00:15:31,770  -->  00:15:33,810
is that public or private?
453

453

00:15:33,810  -->  00:15:36,990
That would be public because anyone can sign up for AWS.
454

454

00:15:36,990  -->  00:15:39,510
If you're using Microsoft Azure or Google Cloud
455

455

00:15:39,510  -->  00:15:41,370
that again is public.
456

456

00:15:41,370  -->  00:15:43,170
If you decide to set up your own cloud,
457

457

00:15:43,170  -->  00:15:44,520
that would be private.
458

458

00:15:44,520  -->  00:15:46,320
These are the kind of things you have to be able to answer
459

459

00:15:46,320  -->  00:15:48,690
and also when each one would be appropriate,
460

460

00:15:48,690  -->  00:15:51,270
more security lean towards private,
461

461

00:15:51,270  -->  00:15:54,360
more openness and lower cost, more towards public.
462

462

00:15:54,360  -->  00:15:55,193
These are the kind
463

463

00:15:55,193  -->  00:15:57,200
of things you need to understand for the exam.
