1
00:00:06,480 --> 00:00:08,910
- In this lesson, 10.3,
we're gonna focus in

2
00:00:08,910 --> 00:00:11,310
on the cloud infrastructure.

3
00:00:11,310 --> 00:00:14,130
As a refresher, when we
previously talked about cloud,

4
00:00:14,130 --> 00:00:16,620
we define cloud computing as a delivery

5
00:00:16,620 --> 00:00:19,740
of computing services over
the internet, the cloud,

6
00:00:19,740 --> 00:00:22,113
that scale to business needs.

7
00:00:22,980 --> 00:00:24,000
Now, in the last lesson,

8
00:00:24,000 --> 00:00:26,550
we talked about four
cloud deployment models

9
00:00:26,550 --> 00:00:28,560
and three cloud service models.

10
00:00:28,560 --> 00:00:30,360
In this lesson, we're gonna look

11
00:00:30,360 --> 00:00:32,220
at five defining characteristics

12
00:00:32,220 --> 00:00:35,730
of the cloud infrastructure,
on demand self-service,

13
00:00:35,730 --> 00:00:38,700
broad network access, resource pooling,

14
00:00:38,700 --> 00:00:41,973
rapid elasticity, and measured service.

15
00:00:43,740 --> 00:00:44,700
So let's go through each

16
00:00:44,700 --> 00:00:47,610
of those five defining
cloud characteristics.

17
00:00:47,610 --> 00:00:49,140
On-demand self-service means

18
00:00:49,140 --> 00:00:51,000
that the customers can unilaterally

19
00:00:51,000 --> 00:00:53,610
provision computing
capabilities as needed,

20
00:00:53,610 --> 00:00:55,380
really, automatically.

21
00:00:55,380 --> 00:00:57,210
Broad network access is

22
00:00:57,210 --> 00:00:59,700
that we can have a
variety of heterogeneous,

23
00:00:59,700 --> 00:01:02,703
thin or thick client platforms
that access the cloud.

24
00:01:03,720 --> 00:01:05,880
Resource pooling is really about all

25
00:01:05,880 --> 00:01:07,710
of the resources that are available

26
00:01:07,710 --> 00:01:09,180
in the cloud environment,

27
00:01:09,180 --> 00:01:12,720
that the provider's computing
resources are pooled together

28
00:01:12,720 --> 00:01:16,590
to serve multiple consumers
using a multi-tenant model

29
00:01:16,590 --> 00:01:19,440
with different physical
and virtual resources.

30
00:01:19,440 --> 00:01:23,670
And we have location independence
and location abstraction,

31
00:01:23,670 --> 00:01:27,300
whether that's country,
state, or the data center.

32
00:01:27,300 --> 00:01:28,133
We'll be talking more

33
00:01:28,133 --> 00:01:30,360
about resource pooling in just a moment.

34
00:01:30,360 --> 00:01:33,150
Rapid elasticity is all about adapting

35
00:01:33,150 --> 00:01:36,360
to the changing workload
demand by auto provisioning

36
00:01:36,360 --> 00:01:39,000
and de-provisioning these pooled resources

37
00:01:39,000 --> 00:01:41,340
to match the current demand, right?

38
00:01:41,340 --> 00:01:44,430
So our cloud provider has all
of these resources, right?

39
00:01:44,430 --> 00:01:46,320
Virtual and logical resources.

40
00:01:46,320 --> 00:01:47,790
And in rapid elasticity,

41
00:01:47,790 --> 00:01:50,460
constantly kind of moving
resources around, right,

42
00:01:50,460 --> 00:01:53,190
to meet the demand of the customers.

43
00:01:53,190 --> 00:01:55,140
And then measured service really refers

44
00:01:55,140 --> 00:01:56,730
to metering capability.

45
00:01:56,730 --> 00:01:57,900
And that's particularly important

46
00:01:57,900 --> 00:02:00,753
in environments where there's
chargeback or pay per use.

47
00:02:02,880 --> 00:02:05,310
Now the cloud infrastructure
itself is comprised

48
00:02:05,310 --> 00:02:08,580
of two layers, a physical
layer and a virtual layer.

49
00:02:08,580 --> 00:02:10,110
Sometimes that virtual
layer is referred to

50
00:02:10,110 --> 00:02:12,030
as an abstracted layer.

51
00:02:12,030 --> 00:02:14,610
Now the physical layer really has all

52
00:02:14,610 --> 00:02:17,640
of the components that build
the cloud's resource pool,

53
00:02:17,640 --> 00:02:21,240
processors, memory,
connectivity, and storage.

54
00:02:21,240 --> 00:02:24,330
And the virtual or the
abstracted layer, right,

55
00:02:24,330 --> 00:02:26,940
is where we kind of pool
those resources together

56
00:02:26,940 --> 00:02:29,730
and divide them up.

57
00:02:29,730 --> 00:02:32,880
So all clouds utilize some
form of virtual networking

58
00:02:32,880 --> 00:02:34,890
to abstract that physical network

59
00:02:34,890 --> 00:02:37,470
and create a network resource pool.

60
00:02:37,470 --> 00:02:38,303
Now, typically,

61
00:02:38,303 --> 00:02:41,550
the cloud user will provision
desired networking resources

62
00:02:41,550 --> 00:02:42,840
from that pool,

63
00:02:42,840 --> 00:02:45,390
which can then be configured,
right, within the limits

64
00:02:45,390 --> 00:02:48,393
of whatever virtualization
technique is being used.

65
00:02:50,220 --> 00:02:51,930
So how do we handle security?

66
00:02:51,930 --> 00:02:53,610
We've got cloud security groups

67
00:02:53,610 --> 00:02:56,490
that form these logical
network parameters.

68
00:02:56,490 --> 00:02:58,800
Now each cloud resource
is going to be assigned

69
00:02:58,800 --> 00:03:02,670
to at least one logical
cloud-based security group.

70
00:03:02,670 --> 00:03:04,980
Each logical cloud-based
security group is going

71
00:03:04,980 --> 00:03:06,510
to be assigned specific rules

72
00:03:06,510 --> 00:03:10,110
that govern the communication
between the security groups.

73
00:03:10,110 --> 00:03:11,280
Those rules are gonna function

74
00:03:11,280 --> 00:03:13,637
at the TCP and IP layers,
really, in regard to ports,

75
00:03:13,637 --> 00:03:18,273
and then source and
destination IP addresses.

76
00:03:21,060 --> 00:03:22,260
Now, often in the cloud,

77
00:03:22,260 --> 00:03:24,330
what we're gonna find are containers.

78
00:03:24,330 --> 00:03:28,140
Containers offer this
logical packaging mechanism

79
00:03:28,140 --> 00:03:30,330
in which applications can be abstracted

80
00:03:30,330 --> 00:03:33,240
from the environment in which they run.

81
00:03:33,240 --> 00:03:36,270
Now, containers can virtualize
CPU, memory, storage,

82
00:03:36,270 --> 00:03:40,050
network, and resources at
an operating system level,

83
00:03:40,050 --> 00:03:42,240
and sometimes referred
to as being lightweight.

84
00:03:42,240 --> 00:03:44,880
Now, containers give
developers the ability

85
00:03:44,880 --> 00:03:46,980
to create these really
predictable environments

86
00:03:46,980 --> 00:03:50,100
that are isolated from other applications.

87
00:03:50,100 --> 00:03:52,770
The term container
orchestration really refers

88
00:03:52,770 --> 00:03:57,030
to the process of managing
how containers are created

89
00:03:57,030 --> 00:03:58,623
and how they are connected.

90
00:03:59,520 --> 00:04:01,350
Now, a open source platform

91
00:04:01,350 --> 00:04:04,470
that you may have heard
of that is used to deploy

92
00:04:04,470 --> 00:04:07,260
and manage virtualized
containers is Docker.

93
00:04:07,260 --> 00:04:09,330
And a really interesting
one to get to know.

94
00:04:09,330 --> 00:04:12,600
And if you wanna know how
popular containers are,

95
00:04:12,600 --> 00:04:15,240
well, from Gmail to YouTube to search,

96
00:04:15,240 --> 00:04:18,003
everything at Google runs in containers.

97
00:04:21,000 --> 00:04:23,610
So let's look at some
geographic concepts related

98
00:04:23,610 --> 00:04:25,020
to the cloud environment.

99
00:04:25,020 --> 00:04:26,070
And bear in mind,

100
00:04:26,070 --> 00:04:28,470
this whole lesson is
just really high level,

101
00:04:28,470 --> 00:04:30,330
sort of conceptual things

102
00:04:30,330 --> 00:04:32,670
that happen in the cloud environment.

103
00:04:32,670 --> 00:04:35,820
We could spend an entire
40 hours, 80 hours,

104
00:04:35,820 --> 00:04:39,630
120 hours, just talking
about the design, you know,

105
00:04:39,630 --> 00:04:40,830
of the cloud environment

106
00:04:40,830 --> 00:04:43,180
and how it's really
structured and architected.

107
00:04:44,220 --> 00:04:46,620
So we think about
geographic concepts, right?

108
00:04:46,620 --> 00:04:50,400
We talk about regions,
availability zones, and geography.

109
00:04:50,400 --> 00:04:51,780
A region is just a set

110
00:04:51,780 --> 00:04:54,180
of connected cloud data centers deployed

111
00:04:54,180 --> 00:04:55,950
within a defined perimeter.

112
00:04:55,950 --> 00:04:58,350
An availability zone is a zone made up

113
00:04:58,350 --> 00:05:00,480
of one or more data centers equipped

114
00:05:00,480 --> 00:05:03,570
with independent power,
cooling, and networking.

115
00:05:03,570 --> 00:05:05,340
And geography is an area

116
00:05:05,340 --> 00:05:07,650
of the world containing
at least one region.

117
00:05:07,650 --> 00:05:09,780
Remember, a region was a set
of connected data centers.

118
00:05:09,780 --> 00:05:11,700
These are cloud data centers deployed

119
00:05:11,700 --> 00:05:13,650
within a defined perimeter.

120
00:05:13,650 --> 00:05:16,320
So geography can define a discreet market

121
00:05:16,320 --> 00:05:17,730
that preserves data residency

122
00:05:17,730 --> 00:05:20,520
or sovereignty and compliance boundaries.

123
00:05:20,520 --> 00:05:22,410
So based on geography,
you could say, "Okay,

124
00:05:22,410 --> 00:05:23,910
I'm going to use this cloud provider

125
00:05:23,910 --> 00:05:27,027
but my data has to stay in
a particular geography."

126
00:05:27,990 --> 00:05:31,080
Geographies allow customers
with specific data residency

127
00:05:31,080 --> 00:05:34,020
and compliance needs to
keep that data close,

128
00:05:34,020 --> 00:05:36,600
because they've been able
to specify where it is.

129
00:05:36,600 --> 00:05:39,150
Now, geographies are also
designed to be fault tolerant

130
00:05:39,150 --> 00:05:41,550
to withstand complete region failure

131
00:05:41,550 --> 00:05:42,390
through their connection

132
00:05:42,390 --> 00:05:45,483
to dedicated high-capacity
networking infrastructure.

133
00:05:47,790 --> 00:05:49,050
Now we depend on the cloud.

134
00:05:49,050 --> 00:05:50,520
So having high availability

135
00:05:50,520 --> 00:05:53,400
in the cloud is extraordinarily important.

136
00:05:53,400 --> 00:05:56,040
So we want high availability
fault tolerance.

137
00:05:56,040 --> 00:05:57,270
The high availability,

138
00:05:57,270 --> 00:05:59,310
that you'll sometimes
see abbreviated as HA,

139
00:05:59,310 --> 00:06:03,540
provides for redundancy and
automatic failover capability

140
00:06:03,540 --> 00:06:05,610
in the cloud environment.

141
00:06:05,610 --> 00:06:08,790
So what we have here is what's
known as a cloud instance.

142
00:06:08,790 --> 00:06:11,040
A cloud instance just
refers to a virtual server.

143
00:06:11,040 --> 00:06:14,790
And a high availability cloud
configuration is referred to

144
00:06:14,790 --> 00:06:16,380
as a regional instance,

145
00:06:16,380 --> 00:06:19,350
and that's designed to
provide data redundancy.

146
00:06:19,350 --> 00:06:20,820
Now, within a regional instance,

147
00:06:20,820 --> 00:06:22,020
the configuration is made up

148
00:06:22,020 --> 00:06:25,320
of a primary instance
and a standby instance.

149
00:06:25,320 --> 00:06:27,150
And through synchronous replication

150
00:06:27,150 --> 00:06:29,040
to each zone's persistent disks,

151
00:06:29,040 --> 00:06:31,200
all writes that are made
to the primary instance

152
00:06:31,200 --> 00:06:33,300
are also made to the standby instance.

153
00:06:33,300 --> 00:06:36,270
And in the event of an
instance or zone failure,

154
00:06:36,270 --> 00:06:39,690
the standby instance will
be able to take over.

155
00:06:39,690 --> 00:06:41,970
Now, if all of this
sounds pretty familiar,

156
00:06:41,970 --> 00:06:44,130
you're thinking this sounds
a lot like networking

157
00:06:44,130 --> 00:06:45,570
in my local data center.

158
00:06:45,570 --> 00:06:48,420
Well, it really is, other
than in the cloud environment,

159
00:06:48,420 --> 00:06:50,370
we just use some different terminology.

160
00:06:52,590 --> 00:06:55,140
So let's look at a high
availability flowchart.

161
00:06:55,140 --> 00:06:58,353
The primary instance sends a
per second heartbeat signal.

162
00:07:00,480 --> 00:07:02,310
And so it's always saying, "I'm working,

163
00:07:02,310 --> 00:07:04,710
I'm working, I'm working, I'm working."

164
00:07:04,710 --> 00:07:07,533
And then we have a primary
instance or a zone failure,

165
00:07:08,580 --> 00:07:11,040
and it doesn't really say
anymore, "I'm not working."

166
00:07:11,040 --> 00:07:13,233
It just stops beating.

167
00:07:14,070 --> 00:07:16,380
So the heartbeat ceases.

168
00:07:16,380 --> 00:07:20,040
The standby instance measures
that unresponsiveness.

169
00:07:20,040 --> 00:07:22,080
Was it just a yawn, just a hiccup,

170
00:07:22,080 --> 00:07:23,973
or did that heartbeat really stop?

171
00:07:25,590 --> 00:07:27,637
The standby instance
will declare an outage.

172
00:07:27,637 --> 00:07:28,897
"I declare," right,

173
00:07:28,897 --> 00:07:32,940
"that that primary instance
is no longer working."

174
00:07:32,940 --> 00:07:36,540
And the standby instance
will take over at that point.

175
00:07:36,540 --> 00:07:40,230
And reversal can either
be automatic or manual.

176
00:07:40,230 --> 00:07:41,520
So the reversal meaning

177
00:07:41,520 --> 00:07:43,950
that it was automatic for
the standby to take place

178
00:07:43,950 --> 00:07:46,260
but when we reverse back to the primary,

179
00:07:46,260 --> 00:07:48,690
it may be automatic or may be manual,

180
00:07:48,690 --> 00:07:52,473
just depending upon how the
infrastructure is configured.

181
00:07:53,310 --> 00:07:56,220
All right, that my friends was
a very, very high level look

182
00:07:56,220 --> 00:07:58,800
at the cloud infrastructure.

183
00:07:58,800 --> 00:08:01,100
So let's do a three
second challenge together.

184
00:08:02,160 --> 00:08:04,320
This mechanism virtualizes, CPU,

185
00:08:04,320 --> 00:08:06,630
memory storage, and network resources

186
00:08:06,630 --> 00:08:08,283
at the operating system level.

187
00:08:09,690 --> 00:08:11,553
1, 2, 3.

188
00:08:12,720 --> 00:08:13,713
That's a container.

189
00:08:15,000 --> 00:08:18,390
Number two, provisioning and
deprovisioning pooled resources

190
00:08:18,390 --> 00:08:20,130
to match current demand.

191
00:08:20,130 --> 00:08:21,330
How do we describe that?

192
00:08:22,170 --> 00:08:23,673
1, 2, 3.

193
00:08:24,690 --> 00:08:26,433
That's rapid elasticity.

194
00:08:28,230 --> 00:08:31,980
Number three, a set of
connected data centers deployed

195
00:08:31,980 --> 00:08:33,783
within a defined perimeter.

196
00:08:34,800 --> 00:08:36,423
1, 2, 3.

197
00:08:37,350 --> 00:08:38,193
That's a region.

198
00:08:39,480 --> 00:08:42,840
Number four, location within a region

199
00:08:42,840 --> 00:08:46,863
with independent power,
cooling, and networking.

200
00:08:48,810 --> 00:08:50,880
1, 2, 3.

201
00:08:50,880 --> 00:08:52,533
And that's an availability zone.

202
00:08:53,370 --> 00:08:55,620
And lastly, number five, comprised

203
00:08:55,620 --> 00:08:59,700
of a primary instance
and a standby instance.

204
00:08:59,700 --> 00:09:01,593
1, 2, 3.

205
00:09:02,430 --> 00:09:04,293
And that's a regional instance.

206
00:09:05,910 --> 00:09:08,970
So that brings us to a security-in-action.

207
00:09:08,970 --> 00:09:10,890
This one's about data residency.

208
00:09:10,890 --> 00:09:13,410
So let's see what we got
here in our case study.

209
00:09:13,410 --> 00:09:16,770
You work at a mid-size
financial institution.

210
00:09:16,770 --> 00:09:20,220
The most recent audit report
cited the primary data center

211
00:09:20,220 --> 00:09:23,430
no longer able to handle
the operating capacity.

212
00:09:23,430 --> 00:09:26,730
In response, your team is
advocating migrating most

213
00:09:26,730 --> 00:09:29,880
of the in-house
infrastructure to the cloud.

214
00:09:29,880 --> 00:09:33,810
Now, you present this option
to executive management.

215
00:09:33,810 --> 00:09:37,350
Their primary concern is
regulatory compliance,

216
00:09:37,350 --> 00:09:39,030
specifically control

217
00:09:39,030 --> 00:09:43,830
over where customer information
is stored and processed.

218
00:09:43,830 --> 00:09:46,200
So how are you gonna
respond to their concern?

219
00:09:46,200 --> 00:09:48,870
Okay, so you're at a
financial institution.

220
00:09:48,870 --> 00:09:50,490
We had an audit and the audit said, "Boy,

221
00:09:50,490 --> 00:09:52,860
your data center, really, it's outdated.

222
00:09:52,860 --> 00:09:55,740
And the backup data center
is really no longer able

223
00:09:55,740 --> 00:09:58,440
to handle the operating capacity."

224
00:09:58,440 --> 00:10:01,050
So your team says, "Okay, well,

225
00:10:01,050 --> 00:10:03,570
let's not have to redo everything here.

226
00:10:03,570 --> 00:10:05,070
Let's go up to the cloud."

227
00:10:05,070 --> 00:10:08,940
And executive management
says, "Well, okay,

228
00:10:08,940 --> 00:10:10,890
but we're a financial institution

229
00:10:10,890 --> 00:10:14,550
and we have regulatory compliance
we have to think about,

230
00:10:14,550 --> 00:10:17,670
and specifically, we need to have control

231
00:10:17,670 --> 00:10:21,900
over where our customer information
is stored and processed.

232
00:10:21,900 --> 00:10:24,510
We need to know where that's happening."

233
00:10:24,510 --> 00:10:27,270
So how are you gonna
respond to their concerns?

234
00:10:27,270 --> 00:10:29,160
Go ahead and put me on
pause, jot down some notes,

235
00:10:29,160 --> 00:10:31,583
and then come back and tell
me about your response.

236
00:10:33,930 --> 00:10:35,520
Well, major providers

237
00:10:35,520 --> 00:10:38,580
define a discrete market or geographies

238
00:10:38,580 --> 00:10:43,320
that preserve data residency
and compliance boundaries.

239
00:10:43,320 --> 00:10:45,360
Now, geographies allow customers

240
00:10:45,360 --> 00:10:48,510
with specific data residency
and compliance needs

241
00:10:48,510 --> 00:10:49,980
to control their data

242
00:10:49,980 --> 00:10:53,373
and application storage
and processing location.

243
00:10:54,480 --> 00:10:57,240
So it's important if you're
gonna do an RFP, right,

244
00:10:57,240 --> 00:10:59,190
and any subsequent contract,

245
00:10:59,190 --> 00:11:02,340
clearly, clearly define this requirement,

246
00:11:02,340 --> 00:11:04,410
not all providers are gonna offer it

247
00:11:04,410 --> 00:11:06,960
and it's not gonna be offered by default.

248
00:11:06,960 --> 00:11:09,180
So you wanna make sure, right,

249
00:11:09,180 --> 00:11:11,040
that whoever providers you're considering,

250
00:11:11,040 --> 00:11:11,873
and that's why you would do it

251
00:11:11,873 --> 00:11:13,920
in your RFP, request for proposal,

252
00:11:13,920 --> 00:11:15,330
can you meet this need?

253
00:11:15,330 --> 00:11:17,583
Explain to us how you do it.

254
00:11:18,450 --> 00:11:21,030
And then we wanna make sure
in the subsequent contract,

255
00:11:21,030 --> 00:11:23,100
once we have chosen a provider,

256
00:11:23,100 --> 00:11:25,020
that it is also clearly defined,

257
00:11:25,020 --> 00:11:27,660
it becomes a contractual obligation.

258
00:11:27,660 --> 00:11:29,190
So being able to see kind of all

259
00:11:29,190 --> 00:11:31,980
of these options and
alternate ways of doing things

260
00:11:31,980 --> 00:11:34,290
and having these discussions,
these conversations,

261
00:11:34,290 --> 00:11:36,600
I know I use the word
conversations over and over again

262
00:11:36,600 --> 00:11:37,680
but so much of what we do

263
00:11:37,680 --> 00:11:40,290
as security practitioners
is having conversations

264
00:11:40,290 --> 00:11:42,840
about security with other people.

265
00:11:42,840 --> 00:11:45,483
Well, doing all that,
definitely security-in-action.

266
00:11:46,470 --> 00:11:47,490
There's your word cloud.

267
00:11:47,490 --> 00:11:49,290
I think for many of you,

268
00:11:49,290 --> 00:11:51,300
most of these terms are gonna be new.

269
00:11:51,300 --> 00:11:52,650
Don't get too hung up

270
00:11:52,650 --> 00:11:55,350
on how much you need to know
about the cloud infrastructure.

271
00:11:55,350 --> 00:11:56,460
I just need you to have sort

272
00:11:56,460 --> 00:11:59,100
of this high level conceptual view.

273
00:11:59,100 --> 00:12:02,460
So take a look at these
and then when you're ready,

274
00:12:02,460 --> 00:12:03,600
head on over to the next lesson.

275
00:12:03,600 --> 00:12:04,550
I'll see you there.
