1
00:00:06,534 --> 00:00:08,040
- In 10.2, we're gonna start

2
00:00:08,040 --> 00:00:09,900
talking about cloud services,

3
00:00:09,900 --> 00:00:12,420
primarily from the end user perspective.

4
00:00:12,420 --> 00:00:15,420
And then in 10.3, we'll revisit cloud,

5
00:00:15,420 --> 00:00:17,340
but this time, from an infrastructure

6
00:00:17,340 --> 00:00:18,990
or data center perspective.

7
00:00:18,990 --> 00:00:20,190
So let's get going here.

8
00:00:21,840 --> 00:00:24,900
Let's define cloud computing
as our starting point.

9
00:00:24,900 --> 00:00:27,600
Cloud computing is a delivery
of computing services

10
00:00:27,600 --> 00:00:31,080
including servers, storage, databases,

11
00:00:31,080 --> 00:00:35,100
networking, software,
analytics, and intelligence

12
00:00:35,100 --> 00:00:37,140
over the internet, "The cloud,"

13
00:00:37,140 --> 00:00:39,060
that scale to business need.

14
00:00:39,060 --> 00:00:40,830
And we talked about
this in the last lesson.

15
00:00:40,830 --> 00:00:43,800
It's not just that it's
delivery over the internet,

16
00:00:43,800 --> 00:00:46,353
it's that it scales to business needs.

17
00:00:47,700 --> 00:00:49,980
Now we're gonna talk about
three service models.

18
00:00:49,980 --> 00:00:51,380
Software-as-a-Service, SaaS,

19
00:00:52,230 --> 00:00:54,300
Platform-as-a-Service, PaaS,

20
00:00:54,300 --> 00:00:57,120
and Infrastructure-as-a-Service, IaaS.

21
00:00:57,120 --> 00:00:58,320
Now, these are only three

22
00:00:58,320 --> 00:00:59,730
of a lot of different models

23
00:00:59,730 --> 00:01:00,780
that are currently available

24
00:01:00,780 --> 00:01:03,540
but these are the three that
you need to know for the exam.

25
00:01:03,540 --> 00:01:05,550
We're gonna talk about
four deployment models.

26
00:01:05,550 --> 00:01:07,830
A private cloud, a community cloud,

27
00:01:07,830 --> 00:01:10,860
a public cloud, and a hybrid cloud.

28
00:01:10,860 --> 00:01:12,390
And then we're gonna talk about this idea

29
00:01:12,390 --> 00:01:13,680
of shared responsibility,

30
00:01:13,680 --> 00:01:15,570
or a shared responsibility model

31
00:01:15,570 --> 00:01:17,193
in terms of security.

32
00:01:19,260 --> 00:01:22,320
So starting with SaaS,
Software-as-a-Service,

33
00:01:22,320 --> 00:01:23,730
we're gonna look at three components

34
00:01:23,730 --> 00:01:25,290
for Software-as-a-Service,

35
00:01:25,290 --> 00:01:26,280
Infrastructure-as-a-Service,

36
00:01:26,280 --> 00:01:27,600
and Platform-as-a-Service,

37
00:01:27,600 --> 00:01:31,080
specifically provisioning customer impact

38
00:01:31,080 --> 00:01:33,183
and our security considerations.

39
00:01:34,110 --> 00:01:35,400
So what are we provisioning?

40
00:01:35,400 --> 00:01:37,950
Well, as the end user or the customer,

41
00:01:37,950 --> 00:01:40,140
we are provisioning computing resources

42
00:01:40,140 --> 00:01:41,550
plus an operating system,

43
00:01:41,550 --> 00:01:42,690
plus an application.

44
00:01:42,690 --> 00:01:45,090
So for example, Salesforce.

45
00:01:45,090 --> 00:01:47,910
Now the customer uses the
provider's application

46
00:01:47,910 --> 00:01:50,730
running on the cloud infrastructure.

47
00:01:50,730 --> 00:01:52,440
The customer impact?

48
00:01:52,440 --> 00:01:53,400
Customer doesn't have to do anything

49
00:01:53,400 --> 00:01:54,810
other than run the application, right?

50
00:01:54,810 --> 00:01:56,090
The customer doesn't manage or control

51
00:01:56,090 --> 00:01:58,140
of the underlying cloud infrastructure

52
00:01:58,140 --> 00:01:59,340
including network server,

53
00:01:59,340 --> 00:02:01,080
operating system storage,

54
00:02:01,080 --> 00:02:02,580
or even in some cases,

55
00:02:02,580 --> 00:02:04,380
the individual application capabilities.

56
00:02:04,380 --> 00:02:06,810
Now, there may be some
tweaking you can do, right?

57
00:02:06,810 --> 00:02:08,040
A few little settings,

58
00:02:08,040 --> 00:02:08,910
but generally speaking,

59
00:02:08,910 --> 00:02:10,923
it all belongs to the cloud provider.

60
00:02:12,090 --> 00:02:13,710
So from a security consideration,

61
00:02:13,710 --> 00:02:14,790
what are we thinking about?

62
00:02:14,790 --> 00:02:16,140
Well, one, we wanna make sure

63
00:02:16,140 --> 00:02:18,030
that the application is responsive

64
00:02:18,030 --> 00:02:19,980
and certainly meets our needs,

65
00:02:19,980 --> 00:02:21,000
that it's scalable,

66
00:02:21,000 --> 00:02:23,250
that it can grow as we grow,

67
00:02:23,250 --> 00:02:25,110
we wanna really understand

68
00:02:25,110 --> 00:02:26,610
how that application

69
00:02:26,610 --> 00:02:28,290
and the entire supporting infrastructure

70
00:02:28,290 --> 00:02:30,690
behind it is maintained.

71
00:02:30,690 --> 00:02:33,300
We wanna know more about
vulnerability management, right?

72
00:02:33,300 --> 00:02:36,600
How well is the systems being managed

73
00:02:36,600 --> 00:02:37,710
for any new vulnerabilities

74
00:02:37,710 --> 00:02:39,600
whether it's the backend operating system

75
00:02:39,600 --> 00:02:41,490
or it's in a piece of hardware,

76
00:02:41,490 --> 00:02:43,320
or it's the data itself

77
00:02:43,320 --> 00:02:44,340
because we wanna make sure

78
00:02:44,340 --> 00:02:45,870
that there aren't any vulnerabilities

79
00:02:45,870 --> 00:02:47,250
that could be exploited, right?

80
00:02:47,250 --> 00:02:50,283
By an adversary who might
get access to our data.

81
00:02:51,630 --> 00:02:52,920
In that same token, right?

82
00:02:52,920 --> 00:02:55,680
We wanna think about
confidentiality and privacy, right?

83
00:02:55,680 --> 00:02:57,240
What are their controls that they have,

84
00:02:57,240 --> 00:02:59,040
and what are their policies?

85
00:02:59,040 --> 00:03:01,740
Who actually owns the data
that's stored in the cloud?

86
00:03:01,740 --> 00:03:03,750
Particularly, if it's a cloud vendor

87
00:03:03,750 --> 00:03:06,750
who manipulates your data in some way.

88
00:03:06,750 --> 00:03:07,890
So maybe it's a cloud vendor

89
00:03:07,890 --> 00:03:10,830
that helps you do some credit scoring.

90
00:03:10,830 --> 00:03:12,300
So you've inputted information

91
00:03:12,300 --> 00:03:14,190
but they come up with the credit score.

92
00:03:14,190 --> 00:03:17,220
Who actually owns that information?

93
00:03:17,220 --> 00:03:18,540
You know, do they own the credit score

94
00:03:18,540 --> 00:03:20,850
and you own the the data about the person?

95
00:03:20,850 --> 00:03:21,780
Or do you own both?

96
00:03:21,780 --> 00:03:22,620
Or do you own neither?

97
00:03:22,620 --> 00:03:23,970
So we really wanna know,

98
00:03:23,970 --> 00:03:25,620
kind of, who owns data.

99
00:03:25,620 --> 00:03:26,910
Then we have multi-tenancy,

100
00:03:26,910 --> 00:03:29,070
because in a
Software-as-a-Service environment,

101
00:03:29,070 --> 00:03:31,650
we're not the only person
using that software.

102
00:03:31,650 --> 00:03:33,030
So there'll be other tenants there.

103
00:03:33,030 --> 00:03:34,020
And we wanna make sure

104
00:03:34,020 --> 00:03:37,080
that there isn't any
cross-border pollination,

105
00:03:37,080 --> 00:03:37,913
if you will,

106
00:03:37,913 --> 00:03:39,690
that I can't get to somebody else's data,

107
00:03:39,690 --> 00:03:40,680
they can't get to mine,

108
00:03:40,680 --> 00:03:42,750
that everything is kept separate.

109
00:03:42,750 --> 00:03:44,280
We wanna know what kind of testing

110
00:03:44,280 --> 00:03:45,450
they're doing on their systems

111
00:03:45,450 --> 00:03:46,680
on a regular basis,

112
00:03:46,680 --> 00:03:48,180
and we'd really love to see an audit.

113
00:03:48,180 --> 00:03:50,283
Do they have an independent audit done?

114
00:03:52,230 --> 00:03:54,840
Next up is PaaS, Platform-as-a-Service.

115
00:03:54,840 --> 00:03:58,230
And we start shifting
now more responsibility

116
00:03:58,230 --> 00:04:00,513
to the end user, to the customer.

117
00:04:01,530 --> 00:04:04,050
So provisioning, or what's
gonna be provisioned,

118
00:04:04,050 --> 00:04:06,570
computing resource and
an operating system,

119
00:04:06,570 --> 00:04:08,340
and optionally, a database,

120
00:04:08,340 --> 00:04:11,340
like an Oracle database or a SQL database.

121
00:04:11,340 --> 00:04:12,720
Now, the customer is gonna deploy

122
00:04:12,720 --> 00:04:14,820
onto that cloud infrastructure,

123
00:04:14,820 --> 00:04:17,010
applications that they either created

124
00:04:17,010 --> 00:04:18,750
or they acquired.

125
00:04:18,750 --> 00:04:20,070
So customer impact,

126
00:04:20,070 --> 00:04:21,780
while the customer does not manage

127
00:04:21,780 --> 00:04:24,240
or control the underlying
cloud infrastructure

128
00:04:24,240 --> 00:04:25,620
the operating system,

129
00:04:25,620 --> 00:04:26,850
the programming languages,

130
00:04:26,850 --> 00:04:28,470
the tools or the platform.

131
00:04:28,470 --> 00:04:30,420
But the customer does have full control

132
00:04:30,420 --> 00:04:32,820
over the deployed application.

133
00:04:32,820 --> 00:04:34,260
Our security considerations,

134
00:04:34,260 --> 00:04:37,260
again, responsiveness, scalability,

135
00:04:37,260 --> 00:04:40,470
maintenance, vulnerability management,

136
00:04:40,470 --> 00:04:42,990
confidentiality and privacy,

137
00:04:42,990 --> 00:04:46,080
data ownership, multi-tenancy,

138
00:04:46,080 --> 00:04:47,550
testing and audit.

139
00:04:47,550 --> 00:04:49,290
Really, all the same things we looked at

140
00:04:49,290 --> 00:04:51,153
in Software-as-a-Service.

141
00:04:53,010 --> 00:04:56,250
Our third is
Infrastructure-as-a-Service or IaaS.

142
00:04:56,250 --> 00:04:57,480
Very often that's referred to

143
00:04:57,480 --> 00:04:59,820
as, "bare metal" computing.

144
00:04:59,820 --> 00:05:00,653
What's provisioned?

145
00:05:00,653 --> 00:05:02,550
Well, really whatever the customer needs.

146
00:05:02,550 --> 00:05:04,680
They can provision processing power,

147
00:05:04,680 --> 00:05:06,450
they can provision storage,

148
00:05:06,450 --> 00:05:08,250
they can provision connectivity,

149
00:05:08,250 --> 00:05:11,313
or any other fundamental
computing resource.

150
00:05:12,600 --> 00:05:13,720
So the customer impact,

151
00:05:13,720 --> 00:05:15,120
well, the customer has control

152
00:05:15,120 --> 00:05:16,590
over the operating system,

153
00:05:16,590 --> 00:05:18,990
storage deployed applications,

154
00:05:18,990 --> 00:05:20,940
and perhaps a limited control

155
00:05:20,940 --> 00:05:22,803
of select networking components.

156
00:05:24,210 --> 00:05:25,530
So security considerations,

157
00:05:25,530 --> 00:05:27,720
again, availability, scalability,

158
00:05:27,720 --> 00:05:28,950
can they grow with us?

159
00:05:28,950 --> 00:05:30,750
How is the system maintained?

160
00:05:30,750 --> 00:05:32,820
Their vulnerability management program,

161
00:05:32,820 --> 00:05:36,180
confidentiality, multi-tenancy,

162
00:05:36,180 --> 00:05:38,403
testing, and audit.

163
00:05:42,360 --> 00:05:45,810
And then we have this
other thing called XaaS

164
00:05:45,810 --> 00:05:49,020
which should be probably
AaaS, but it's not.

165
00:05:49,020 --> 00:05:52,140
It's XaaS, called Anything-as-a-Service.

166
00:05:52,140 --> 00:05:53,790
Where the X represents really,

167
00:05:53,790 --> 00:05:55,200
anything and everything.

168
00:05:55,200 --> 00:05:56,490
So Anything-as-a-Service

169
00:05:56,490 --> 00:05:58,170
represents a growing type of services

170
00:05:58,170 --> 00:05:59,730
that are available over the internet

171
00:05:59,730 --> 00:06:01,230
via cloud computing,

172
00:06:01,230 --> 00:06:04,923
opposed to being provided
locally or on premises.

173
00:06:06,390 --> 00:06:07,500
So here's some examples,

174
00:06:07,500 --> 00:06:09,450
but these won't come up in your exam.

175
00:06:09,450 --> 00:06:11,730
Desktop-as-a-Service, DaaS,

176
00:06:11,730 --> 00:06:15,060
Disaster Recovery-as-a-Service, DRaaS,

177
00:06:15,060 --> 00:06:17,640
Network-as-a-Service, NaaS,

178
00:06:17,640 --> 00:06:20,670
Communications-as-a-Service, CaaS,

179
00:06:20,670 --> 00:06:23,703
Database-as-a-Service, DaaS.

180
00:06:27,630 --> 00:06:30,060
So let's talk about who's responsible.

181
00:06:30,060 --> 00:06:33,660
Who's responsible for different
components of security?

182
00:06:33,660 --> 00:06:36,480
Is the service provider, which is the CSP,

183
00:06:36,480 --> 00:06:38,460
the cloud service provider responsible?

184
00:06:38,460 --> 00:06:39,360
Or is the user,

185
00:06:39,360 --> 00:06:41,430
by the user, we mean the end user,

186
00:06:41,430 --> 00:06:42,840
not the individual necessarily,

187
00:06:42,840 --> 00:06:44,220
but the customer, the company

188
00:06:44,220 --> 00:06:46,650
that's the provisioner of the service?

189
00:06:46,650 --> 00:06:49,050
So let's look at five components.

190
00:06:49,050 --> 00:06:51,120
Infrastructure security,
platform security,

191
00:06:51,120 --> 00:06:52,230
application security,

192
00:06:52,230 --> 00:06:55,170
including APIs, application
programming interfaces,

193
00:06:55,170 --> 00:06:57,303
data security, and user security.

194
00:06:58,320 --> 00:07:00,480
In the Software-as-a-Service environment,

195
00:07:00,480 --> 00:07:02,430
the cloud service provider is responsible

196
00:07:02,430 --> 00:07:05,190
for infrastructure
security, platform security,

197
00:07:05,190 --> 00:07:07,260
and application security,

198
00:07:07,260 --> 00:07:09,000
where the user's actually responsible

199
00:07:09,000 --> 00:07:10,260
for their own data,

200
00:07:10,260 --> 00:07:12,510
and for the security on the user side.

201
00:07:12,510 --> 00:07:14,610
So when we talk about
security on the user side,

202
00:07:14,610 --> 00:07:16,920
we're really talking about access control.

203
00:07:16,920 --> 00:07:19,470
Who has given rights to use

204
00:07:19,470 --> 00:07:21,450
that particular application,

205
00:07:21,450 --> 00:07:23,850
and how they're authenticating,

206
00:07:23,850 --> 00:07:25,050
you know, how well they're securing

207
00:07:25,050 --> 00:07:26,550
their own password, et cetera.

208
00:07:27,390 --> 00:07:28,770
Platform-as-a-Service, again,

209
00:07:28,770 --> 00:07:31,792
we see a shifting over to the user,

210
00:07:31,792 --> 00:07:33,240
the provisioner of the service,

211
00:07:33,240 --> 00:07:35,640
so the cloud service
provider is responsible

212
00:07:35,640 --> 00:07:38,640
for infrastructure security
and platform security.

213
00:07:38,640 --> 00:07:40,380
But the application security,

214
00:07:40,380 --> 00:07:41,460
including those APIs,

215
00:07:41,460 --> 00:07:43,500
the data security, the user security,

216
00:07:43,500 --> 00:07:48,270
really now reside with the
provisioner or the user.

217
00:07:48,270 --> 00:07:49,103
And then lastly,

218
00:07:49,103 --> 00:07:50,550
we get to Infrastructure-as-a-Service

219
00:07:50,550 --> 00:07:52,830
and we see a further moving, right?

220
00:07:52,830 --> 00:07:54,900
In an Infrastructure-as-a-Service.

221
00:07:54,900 --> 00:07:56,760
The cloud provider is responsible

222
00:07:56,760 --> 00:07:58,410
for infrastructure security.

223
00:07:58,410 --> 00:07:59,760
But then as we move down

224
00:07:59,760 --> 00:08:02,010
to platform application data and user,

225
00:08:02,010 --> 00:08:03,570
the responsibility shifts over

226
00:08:03,570 --> 00:08:05,160
to the provisioner of the service.

227
00:08:05,160 --> 00:08:06,420
Now, these aren't hard and fast,

228
00:08:06,420 --> 00:08:08,040
and these may vary a little bit

229
00:08:08,040 --> 00:08:11,400
depending upon a specific application.

230
00:08:11,400 --> 00:08:13,170
But what I'm really trying to stress here,

231
00:08:13,170 --> 00:08:17,850
is that cloud security is
really a shared responsibility,

232
00:08:17,850 --> 00:08:19,260
and it's a shared responsibility

233
00:08:19,260 --> 00:08:21,330
between the cloud service provider

234
00:08:21,330 --> 00:08:23,433
and the provisioner of the service.

235
00:08:24,660 --> 00:08:26,880
So let's talk next about
cloud deployment models.

236
00:08:26,880 --> 00:08:28,590
There are four cloud deployment models,

237
00:08:28,590 --> 00:08:30,450
public cloud, community cloud,

238
00:08:30,450 --> 00:08:32,610
private cloud, and hybrid cloud.

239
00:08:32,610 --> 00:08:35,220
The public cloud is
provisioned for the public use.

240
00:08:35,220 --> 00:08:36,240
So what are we considering?

241
00:08:36,240 --> 00:08:37,620
Well, first of all, where is it?

242
00:08:37,620 --> 00:08:39,147
Because we may have contractual

243
00:08:39,147 --> 00:08:41,280
or regulatory obligations that say

244
00:08:41,280 --> 00:08:43,650
our data can only be in certain locations,

245
00:08:43,650 --> 00:08:44,790
so we need to know where it is.

246
00:08:44,790 --> 00:08:46,140
And of course, multi-tenancy,

247
00:08:46,140 --> 00:08:48,120
because it's a public cloud,

248
00:08:48,120 --> 00:08:49,170
there's other tenants

249
00:08:49,170 --> 00:08:51,870
and we really wanna be concerned about,

250
00:08:51,870 --> 00:08:54,120
is there any kind of
cross-pollination, right?

251
00:08:54,120 --> 00:08:55,770
We wanna make sure in a public cloud,

252
00:08:55,770 --> 00:08:56,760
my stuff is my stuff,

253
00:08:56,760 --> 00:08:57,593
your stuff's your stuff,

254
00:08:57,593 --> 00:08:59,120
and never the twain shall meet.

255
00:09:00,240 --> 00:09:01,620
A community cloud is provisioned

256
00:09:01,620 --> 00:09:04,560
for the exclusive use
of a well-defined group.

257
00:09:04,560 --> 00:09:06,137
Our considerations are
still multi-tenancy,

258
00:09:06,137 --> 00:09:07,710
'cause there's others in our group.

259
00:09:07,710 --> 00:09:09,840
But generally, we'll know the location.

260
00:09:09,840 --> 00:09:10,770
In a private cloud,

261
00:09:10,770 --> 00:09:12,750
that's provisioned for the exclusive use

262
00:09:12,750 --> 00:09:14,610
of a single organization.

263
00:09:14,610 --> 00:09:16,290
So we're okay on location

264
00:09:16,290 --> 00:09:17,123
we'll know where it is,

265
00:09:17,123 --> 00:09:18,210
and there aren't any other tenants,

266
00:09:18,210 --> 00:09:20,220
so multi-tenancy isn't an issue,

267
00:09:20,220 --> 00:09:21,840
but we wanna make sure that it's scalable,

268
00:09:21,840 --> 00:09:24,300
that it can grow appropriate with us.

269
00:09:24,300 --> 00:09:25,920
Hybrid cloud is the mixed use

270
00:09:25,920 --> 00:09:28,050
of on-premise infrastructure,

271
00:09:28,050 --> 00:09:30,570
private cloud, and public cloud platforms

272
00:09:30,570 --> 00:09:32,820
with orchestration or coordination

273
00:09:32,820 --> 00:09:34,500
among the providers.

274
00:09:34,500 --> 00:09:36,300
And so in addition to what happens

275
00:09:36,300 --> 00:09:37,380
at each of the different clouds,

276
00:09:37,380 --> 00:09:38,910
what we're also need to have

277
00:09:38,910 --> 00:09:40,680
a security consideration about,

278
00:09:40,680 --> 00:09:43,173
is going to be the
security of the connection.

279
00:09:45,120 --> 00:09:46,680
A term I want you to be familiar with

280
00:09:46,680 --> 00:09:48,150
is cloud bursting.

281
00:09:48,150 --> 00:09:50,400
Cloud bursting refers to the on-demand

282
00:09:50,400 --> 00:09:52,950
and temporary use of the public cloud

283
00:09:52,950 --> 00:09:55,200
when demand exceeds resources available

284
00:09:55,200 --> 00:09:56,700
in either a private cloud,

285
00:09:56,700 --> 00:09:59,190
or in an on-prem infrastructure.

286
00:09:59,190 --> 00:10:02,100
Now, there are three
categories of cloud bursting.

287
00:10:02,100 --> 00:10:03,540
Distributed load balancing,

288
00:10:03,540 --> 00:10:06,000
which focuses on workload balancing

289
00:10:06,000 --> 00:10:07,590
and monitoring between the data center

290
00:10:07,590 --> 00:10:09,030
and the public cloud.

291
00:10:09,030 --> 00:10:10,020
Automated bursting,

292
00:10:10,020 --> 00:10:12,330
which is based on on-demand policies,

293
00:10:12,330 --> 00:10:13,950
and then manual bursting,

294
00:10:13,950 --> 00:10:15,810
which is the manual provisioning

295
00:10:15,810 --> 00:10:18,210
of cloud resources on a temporary basis

296
00:10:18,210 --> 00:10:19,983
for specific workloads.

297
00:10:21,810 --> 00:10:23,250
So how do you make a decision?

298
00:10:23,250 --> 00:10:25,170
And be on-premise versus cloud?

299
00:10:25,170 --> 00:10:27,000
Well, there's a lot of considerations.

300
00:10:27,000 --> 00:10:29,010
Legal, regulatory, and contractual,

301
00:10:29,010 --> 00:10:30,960
infrastructure availability,

302
00:10:30,960 --> 00:10:32,910
disaster recovery, and
business continuity,

303
00:10:32,910 --> 00:10:35,130
and security are just some of them.

304
00:10:35,130 --> 00:10:36,307
You know, I'm often asked,

305
00:10:36,307 --> 00:10:37,260
"What would you do?

306
00:10:37,260 --> 00:10:39,210
Is cloud more secure or less secure?

307
00:10:39,210 --> 00:10:40,800
Is on-prem more secure or less secure?"

308
00:10:40,800 --> 00:10:41,917
And my answer's always gonna be,

309
00:10:41,917 --> 00:10:43,230
"It depends," right?

310
00:10:43,230 --> 00:10:45,270
In some situations, the
cloud is more secure

311
00:10:45,270 --> 00:10:46,410
and on-premise less,

312
00:10:46,410 --> 00:10:49,410
in others, on-prem is more
secure, the cloud is less.

313
00:10:49,410 --> 00:10:52,680
The key is to know what your
requirements are, right?

314
00:10:52,680 --> 00:10:54,090
Know what you need,

315
00:10:54,090 --> 00:10:56,430
and then those same
requirements will apply

316
00:10:56,430 --> 00:10:58,980
whether it is an on-prem or in the cloud.

317
00:10:58,980 --> 00:11:00,450
And you wanna make sure, right?

318
00:11:00,450 --> 00:11:01,650
That in either location,

319
00:11:01,650 --> 00:11:03,930
wherever your systems
or data are gonna be,

320
00:11:03,930 --> 00:11:07,170
that those security
requirements can be met.

321
00:11:07,170 --> 00:11:09,570
So let's look through some
of these categories, right?

322
00:11:09,570 --> 00:11:11,880
In terms of legal,
regulatory, and contractual,

323
00:11:11,880 --> 00:11:13,530
we wanna evaluate legal, regulatory,

324
00:11:13,530 --> 00:11:14,610
and contractual restrictions

325
00:11:14,610 --> 00:11:16,740
or obligations that we might have.

326
00:11:16,740 --> 00:11:17,850
The infrastructure,

327
00:11:17,850 --> 00:11:19,950
we wanna evaluate the required investment

328
00:11:19,950 --> 00:11:22,410
to build, maintain, and
support the infrastructure.

329
00:11:22,410 --> 00:11:23,310
Again, we're deciding,

330
00:11:23,310 --> 00:11:25,710
should we go to the cloud or be on-prem?

331
00:11:25,710 --> 00:11:27,300
Availability, we wanna evaluate

332
00:11:27,300 --> 00:11:29,490
the capability of resources

333
00:11:29,490 --> 00:11:32,070
and the ability to provision
additional resources

334
00:11:32,070 --> 00:11:34,050
as we need them.

335
00:11:34,050 --> 00:11:36,030
Disaster recovery and business continuity,

336
00:11:36,030 --> 00:11:37,710
that's the DR and BC,

337
00:11:37,710 --> 00:11:39,510
we wanna evaluate the synergy

338
00:11:39,510 --> 00:11:41,970
with disaster recovery
and business continuity

339
00:11:41,970 --> 00:11:43,500
strategies and requirements.

340
00:11:43,500 --> 00:11:44,790
And lastly, security.

341
00:11:44,790 --> 00:11:48,540
We wanna be evaluating security
and privacy requirements.

342
00:11:48,540 --> 00:11:50,340
There are other things we're
gonna look at too, of course,

343
00:11:50,340 --> 00:11:51,930
we're gonna look at reputation,

344
00:11:51,930 --> 00:11:55,020
we're going to look at cost,

345
00:11:55,020 --> 00:11:56,160
you know, there's a whole host of things,

346
00:11:56,160 --> 00:11:58,590
but here are some of
the primary categories

347
00:11:58,590 --> 00:12:00,600
that we use when we kind
of make these decisions

348
00:12:00,600 --> 00:12:02,163
of on-prem versus cloud.

349
00:12:03,030 --> 00:12:03,863
Alright, my friends.

350
00:12:03,863 --> 00:12:05,130
That brings us to a
three-second challenge.

351
00:12:05,130 --> 00:12:06,780
Five challenge questions,
three seconds each.

352
00:12:06,780 --> 00:12:07,980
You know how to do this.

353
00:12:09,240 --> 00:12:10,860
This cloud deployment models provision

354
00:12:10,860 --> 00:12:14,010
for the exclusive use
of a well-defined group.

355
00:12:14,010 --> 00:12:15,750
One, two, three,

356
00:12:15,750 --> 00:12:18,000
keyword, "Exclusive" here.

357
00:12:18,000 --> 00:12:20,253
Exclusive use of a well-defined group.

358
00:12:21,210 --> 00:12:22,910
That's gonna be a community cloud.

359
00:12:24,630 --> 00:12:25,980
In this cloud service model,

360
00:12:25,980 --> 00:12:28,080
the computing resources, operating system,

361
00:12:28,080 --> 00:12:31,323
and an application are all
managed by the provider.

362
00:12:32,160 --> 00:12:34,380
One, two, three.

363
00:12:34,380 --> 00:12:37,980
That's gonna be
Software-as-a-Service or SaaS.

364
00:12:37,980 --> 00:12:40,110
Number three, this term represents

365
00:12:40,110 --> 00:12:43,263
a growing type of service
available in the cloud.

366
00:12:44,550 --> 00:12:47,610
So it really encompasses
all these new services

367
00:12:47,610 --> 00:12:49,650
that are available in the cloud.

368
00:12:49,650 --> 00:12:51,570
One, two, three.

369
00:12:51,570 --> 00:12:54,573
That's XaaS, which is
Anything-as-a-Service.

370
00:12:56,550 --> 00:12:59,520
Number four, the security
and compliance framework

371
00:12:59,520 --> 00:13:02,130
describes the duties of the CSP,

372
00:13:02,130 --> 00:13:03,810
the cloud service provider,

373
00:13:03,810 --> 00:13:05,163
and the provisioner.

374
00:13:06,630 --> 00:13:08,730
We looked at a matrix, what was it called?

375
00:13:08,730 --> 00:13:10,740
One, two, three.

376
00:13:10,740 --> 00:13:13,380
That was a shared responsibility matrix,

377
00:13:13,380 --> 00:13:15,423
or a shared responsibility framework.

378
00:13:16,290 --> 00:13:18,090
And lastly, number five,

379
00:13:18,090 --> 00:13:19,710
this term refers to the ability

380
00:13:19,710 --> 00:13:22,803
to provide additional resources on demand.

381
00:13:23,820 --> 00:13:25,323
One, two, three.

382
00:13:26,160 --> 00:13:27,903
And that's gonna be scalability.

383
00:13:29,430 --> 00:13:31,650
So that brings us to a Security-in-Action.

384
00:13:31,650 --> 00:13:33,540
And this one's about cloud computing.

385
00:13:33,540 --> 00:13:35,010
So we're gonna put that knowledge

386
00:13:35,010 --> 00:13:36,810
right into play for you.

387
00:13:36,810 --> 00:13:38,490
So a metropolitan school district

388
00:13:38,490 --> 00:13:40,830
has decided to transition their entire

389
00:13:40,830 --> 00:13:43,503
IT infrastructure to the public cloud.

390
00:13:43,503 --> 00:13:45,570
SaaS, Software-as-a-Service,

391
00:13:45,570 --> 00:13:47,730
will be used for email, payroll,

392
00:13:47,730 --> 00:13:49,590
and facilities management.

393
00:13:49,590 --> 00:13:51,720
And PaaS, Platform-as-a-Service

394
00:13:51,720 --> 00:13:53,550
for the student database.

395
00:13:53,550 --> 00:13:55,327
Now, the cloud providers have promised,

396
00:13:55,327 --> 00:13:57,780
"Great service and great security

397
00:13:57,780 --> 00:13:59,400
at a great price."

398
00:13:59,400 --> 00:14:02,010
However, they have refused to provide

399
00:14:02,010 --> 00:14:04,890
any audit or testing documentation.

400
00:14:04,890 --> 00:14:07,350
Now, the district
superintendent is really excited

401
00:14:07,350 --> 00:14:09,150
about the potential cost savings,

402
00:14:09,150 --> 00:14:11,460
which will be realized by eliminating

403
00:14:11,460 --> 00:14:14,640
district IT and audit personnel.

404
00:14:14,640 --> 00:14:17,670
Hmm, so what's your first
reaction to this plan?

405
00:14:17,670 --> 00:14:19,410
Just a quick recap.

406
00:14:19,410 --> 00:14:21,270
This is a school district.

407
00:14:21,270 --> 00:14:22,140
They're gonna transition

408
00:14:22,140 --> 00:14:26,370
their entire IT infrastructure
to the public cloud.

409
00:14:26,370 --> 00:14:28,110
They're gonna use SaaS

410
00:14:28,110 --> 00:14:30,690
for email, payroll, and facilities.

411
00:14:30,690 --> 00:14:33,030
They're gonna use PaaS,

412
00:14:33,030 --> 00:14:35,493
Platform-as-a-Service
for the student database.

413
00:14:36,360 --> 00:14:38,370
The cloud providers are great marketers,

414
00:14:38,370 --> 00:14:40,860
'cause they say, "Great
service, great security

415
00:14:40,860 --> 00:14:43,890
everything you've ever
wanted at a great price."

416
00:14:43,890 --> 00:14:45,420
But this is really important.

417
00:14:45,420 --> 00:14:46,890
They have refused to provide

418
00:14:46,890 --> 00:14:49,920
any audit or testing documentation.

419
00:14:49,920 --> 00:14:52,020
Our superintendent thinks this is awesome

420
00:14:52,020 --> 00:14:54,120
because there's gonna be a cost savings.

421
00:14:54,120 --> 00:14:55,260
Where does the superintendent

422
00:14:55,260 --> 00:14:57,270
think the cost savings
are gonna come from?

423
00:14:57,270 --> 00:15:02,270
By eliminating district
IT and audit personnel.

424
00:15:02,640 --> 00:15:04,560
So how are you gonna react to this?

425
00:15:04,560 --> 00:15:05,880
Well go ahead and put me on pause,

426
00:15:05,880 --> 00:15:06,870
put some notes down,

427
00:15:06,870 --> 00:15:09,990
and let's talk about this
shared responsibility

428
00:15:09,990 --> 00:15:12,783
and why we probably don't
feel so good about this plan.

429
00:15:15,810 --> 00:15:17,970
So this approach doesn't
acknowledge at all,

430
00:15:17,970 --> 00:15:20,040
the inherent shared responsibility

431
00:15:20,040 --> 00:15:21,360
in client computing,

432
00:15:21,360 --> 00:15:24,510
that we can't put the onus for everything

433
00:15:24,510 --> 00:15:26,100
on one side or the other.

434
00:15:26,100 --> 00:15:27,900
There is a shared responsibility.

435
00:15:27,900 --> 00:15:28,733
Remember, we looked at that

436
00:15:28,733 --> 00:15:31,170
shared responsibility matrix.

437
00:15:31,170 --> 00:15:34,590
Outsourcing absolutely does
not relieve the district

438
00:15:34,590 --> 00:15:37,200
of their governance,
their risk management,

439
00:15:37,200 --> 00:15:39,420
and their compliance responsibilities.

440
00:15:39,420 --> 00:15:40,920
And they are still responsible

441
00:15:40,920 --> 00:15:43,110
for the security and privacy

442
00:15:43,110 --> 00:15:44,610
of that student database,

443
00:15:44,610 --> 00:15:47,280
as well as, you know, payroll,

444
00:15:47,280 --> 00:15:49,653
and you know, other components as well.

445
00:15:51,330 --> 00:15:52,410
Due diligence, remember,

446
00:15:52,410 --> 00:15:54,330
due diligence is the active investigation

447
00:15:54,330 --> 00:15:56,370
before we sign a contract with a vendor

448
00:15:56,370 --> 00:15:58,230
during the lifetime of the relationship,

449
00:15:58,230 --> 00:16:00,270
and especially whenever
we're doing renewal,

450
00:16:00,270 --> 00:16:03,570
due diligence or the
investigation demands visibility.

451
00:16:03,570 --> 00:16:05,257
And part of that visibility would be,

452
00:16:05,257 --> 00:16:06,750
"Okay show us, you know,

453
00:16:06,750 --> 00:16:08,340
any security testing you've had.

454
00:16:08,340 --> 00:16:09,960
Show us who's audited you,

455
00:16:09,960 --> 00:16:11,610
and what's the results of the audit?"

456
00:16:11,610 --> 00:16:13,140
And the fact that the cloud provider

457
00:16:13,140 --> 00:16:17,013
won't provide that information
is a huge red flag.

458
00:16:18,390 --> 00:16:20,820
Now, technical and audit expertise

459
00:16:20,820 --> 00:16:22,290
are still gonna be required

460
00:16:22,290 --> 00:16:24,120
to manage the relationship.

461
00:16:24,120 --> 00:16:25,470
Particularly because we're also using

462
00:16:25,470 --> 00:16:26,880
Platform-as-a-Service,

463
00:16:26,880 --> 00:16:28,710
meaning that the student database

464
00:16:28,710 --> 00:16:31,653
is still going to be a
local responsibility.

465
00:16:33,630 --> 00:16:35,520
As I said earlier, data protection,

466
00:16:35,520 --> 00:16:38,070
still the school
district's responsibility.

467
00:16:38,070 --> 00:16:40,290
Right? They cannot outsource that.

468
00:16:40,290 --> 00:16:43,920
And lastly, it's really
strategic alignment

469
00:16:43,920 --> 00:16:46,260
that should be the significant driver,

470
00:16:46,260 --> 00:16:47,730
not cost alone.

471
00:16:47,730 --> 00:16:48,960
It'd be great if the school district

472
00:16:48,960 --> 00:16:50,220
could save some money,

473
00:16:50,220 --> 00:16:51,420
but that's not the way to do it,

474
00:16:51,420 --> 00:16:52,500
the way they're thinking about it.

475
00:16:52,500 --> 00:16:54,750
And cost alone should never be the reason

476
00:16:54,750 --> 00:16:56,370
why we make a decision.

477
00:16:56,370 --> 00:16:58,590
It should always be strategically aligned

478
00:16:58,590 --> 00:17:00,450
with the needs of an organization.

479
00:17:00,450 --> 00:17:01,590
Now, the needs of an organization

480
00:17:01,590 --> 00:17:03,180
may also be to spend less,

481
00:17:03,180 --> 00:17:06,180
but that's only gonna be one among many.

482
00:17:06,180 --> 00:17:08,310
So really kinda
understanding the situation

483
00:17:08,310 --> 00:17:10,290
and once again having the conversation

484
00:17:10,290 --> 00:17:11,520
with a decision maker

485
00:17:11,520 --> 00:17:13,650
to help them better understand

486
00:17:13,650 --> 00:17:15,660
the impact of their decisions.

487
00:17:15,660 --> 00:17:17,703
Absolutely, security and action.

488
00:17:18,660 --> 00:17:20,220
Right, there's your word cloud,

489
00:17:20,220 --> 00:17:21,510
you've got a lot here.

490
00:17:21,510 --> 00:17:23,580
Make sure that you understand
all of these concepts

491
00:17:23,580 --> 00:17:26,010
because we're gonna continue
talking about cloud,

492
00:17:26,010 --> 00:17:28,080
but we're gonna shift
focus in the next lesson,

493
00:17:28,080 --> 00:17:30,540
and look at it from a cloud
infrastructure perspective.

494
00:17:30,540 --> 00:17:32,550
So get these concepts down first

495
00:17:32,550 --> 00:17:33,630
before you move on.

496
00:17:33,630 --> 00:17:34,463
When you're ready,

497
00:17:34,463 --> 00:17:35,660
I'll see you right there.
