Cloud computing operations

The goal of the cloud computing operations Operations domain is to explain the requirements needed to develop, plan, implement, run, and manage the physical and logical cloud infrastructure.


You will gain an understanding of the necessary controls and resources, the best practices in monitoring and auditing, and the importance of risk assessment in both the physical and the logical cloud infrastructures.


With an understanding of specific industry compliance and regulations, you will know how to protect resources, restrict access, and apply appropriate controls in the cloud environment.


Domain Objectives


After completing this domain, you will be able to do the following: 


Describe the specifications necessary for the physical, logical, and environmental design of the data center


Identify the requirements to build and implement the physical cloud infrastructure


Define the process for running the physical infrastructure based on access, security, and availability configurations


Define the process for managing the physical infrastructure about access, monitoring, security controls, analysis, and maintenance


Identify the requirements to build and implement the logical cloud infrastructure


Define the process for running the logical infrastructure based on access, security, and availability configurations


Define the process for managing the logical infrastructure about access, monitoring, security controls, analysis, and maintenance


Identify the necessary regulations and controls to ensure compliance for the operation and management of the cloud infrastructure


Describe the process of conducting a risk assessment of the physical and logical infrastructure


Describe the process for the collection, acquisition, and preservation of digital evidence


Introduction


Datacenter design, planning, and architecture have long formed an integral part of the information technology (IT) services for providers of computing services.


Over time, these have typically evolved and grown in line with computing developments and enhanced capabilities. Data centers continue to be refined, enhanced, and improved upon globally; however, they still rely heavily on the same essential components to support their activities (power, water, structures, connectivity, security, and more).


Implementing a secure design when creating a data center involves many considerations. Before making any design decisions, work with senior management and other key stakeholders to identify all compliance requirements for the data center.


If you’re designing a data center for public cloud services, consider the different levels of security that will be offered to your customers.

cloud computing operations

Why do vulnerabilities exist?

Any element of technology will contain vulnerabilities, mobile or otherwise. Of course, there is no indication as to how many vulnerabilities each will likely have; however, one very rudimentary method of determining the number of likely vulnerabilities is based on the number of lines of code.  In other words, the more the number of lines […]

Why do vulnerabilities exist? Read More »

How Data Leaking through Poorly Written Applications?

Data Leaking through poorly written applications is day to day biggest concern but threat level is medium. So How many apps do you have on your mobile device? If you can answer that question, then congratulations; that is impressive, but can you confirm what data these apps collect, and more importantly what they do with

How Data Leaking through Poorly Written Applications? Read More »

what is abuse of cloud services?

The abuse of cloud services extends beyond malicious insiders and potentially allows cyber criminals The ability to utilize such services for criminal gain.  There are multiple ways in which cloud services can be used for malicious purposes. There is no question, that for the malicious actor their job is considerably easier if their intended victims

what is abuse of cloud services? Read More »

What is Malicious Insider?

A malicious insider threat to an organization is a current or former employee, contractor, or other business partners who has or had authorized access to an organization’s network, system, or data and intentionally exceeded or misused that access in a manner that negatively affected the confidentiality, integrity, or availability of the organization’s information or information

What is Malicious Insider? Read More »

Cloud Computing Data Protection Frameworks

Cloud data protection Frameworks: Globally, a plethora of laws, regulations and other legal requirements for organizations and entities exist to protect the security and privacy of digital and other information assets. Organization for Economic Cooperation and Development—Privacy and Security Guidelines On September 9, 2013, the Organization for Economic Cooperation and Development (OECD) published a set

Cloud Computing Data Protection Frameworks Read More »

Stakeholders challenges in cloud computing

Identifying and involving the relevant stakeholders from the commencement of any cloud computing discussions are of utmost importance. Failure to do so can lead to segregation or a fractured approach to cloud decision making, as well as non-standardization across the organization about how cloud services are procured, reviewed, managed, and maintained. To objectively assess within

Stakeholders challenges in cloud computing Read More »

What is digital evidence in cyber security?

Understanding the Collection and Preservation of Digital Evidence. Forensic science is generally defined as the application of science to the law. Digital forensics, also known as computer and network forensics, has many definitions. Generally, it is considered the application of science to the identification, collection, examination, and analysis of data while preserving the integrity of

What is digital evidence in cyber security? Read More »

What is a Cloud SLA (Cloud Service-Level Agreement)?

What is Cloud SLA (Cloud Service-Level Agreement)? Its similar to a contract signed between a customer and a CSP, the Cloud SLA forms the most crucial and fundamental component of how security and operations will be undertaken. The Cloud SLA should also capture requirements related to compliance, best practices, and general operational activities to satisfy

What is a Cloud SLA (Cloud Service-Level Agreement)? Read More »

What is data processing in cloud computing?

The organization also needs to protect Data Processing mechanism as well as Data Control in life-cycle phases other than Create. Industry standards and best practices require the creation, use, and enforcement of a host of data management policies and practices, including the areas of data retention, audit, and disposal. In this section Data Control in

What is data processing in cloud computing? Read More »

What does “Cloud Management services” mean?

Cloud services management fall into three main groups: IaaS, PaaS, and SaaS. Each is discussed in the following sections. What does “IaaS” mean in cloud computing? According to “The NIST Definition of Cloud Computing,” in IaaS, “the capability provided to the consumer is to provision processing, storage, networks, and other fundamental computing resources where the

What does “Cloud Management services” mean? Read More »

What is cloud encryption?

The need for the use of Cloud encryption, cryptography and encryption is universal for the provisioning and protection of confidentiality services in the enterprise. In support of that goal, the Cloud encryption blog should ensure that he understands how to deploy and use cryptography services in a cloud environment. In addition, it’s important to integrate

What is cloud encryption? Read More »

What does “Cloud Computing Functions” mean?

Cloud Computing Functions and traditional computing and technology environments, several functions are essential for creating, designing, implementing, testing, auditing, and maintaining the relevant assets So for more understanding, we will look in this blog the Cloud Computing Functions. The same is true for cloud computing, with the following key roles representing a sample of the

What does “Cloud Computing Functions” mean? Read More »

Cloud Identity and Access Management

Cloud identity and access management is about the people, processes, and procedures used to create, manage, and destroy identities of all kinds, Whether you are dealing with system administrators or plain users of cloud services, the creation and management of identities are key in maintaining secure operations. IAM systems consist of several components, as shown

Cloud Identity and Access Management Read More »

What is cloud application security?

Developers often face challenges when working in a new and unfamiliar environment. that’s why the organization faces challenges with cloud application security. For instance, they may be used to working in a certain language or framework that may not be available to them on a particular platform. There is also a serious lack of documentation

What is cloud application security? Read More »

Why Cloud Computing Matters in e-discovery?

E-discovery is depending on whether an organization is employing a hybrid, public, or community cloud, there are issues that the organization has to understand. The extra dynamic is the presence of a third party the cloud service provider (CSP) so the organization must understand how laws and regulations apply to the cloud. In other words,

Why Cloud Computing Matters in e-discovery? Read More »

Why isms is important?

An ISMS (Internal Information Security Controls System) should exist to reduce risks related to the AIC of information and assets, while looking to strengthen the stakeholder confidence in the security posture of their organization in protecting such assets. Although these systems may well vary in terms of comprehensiveness, along with how the controls are applied,

Why isms is important? Read More »

Managing i cloud Infrastructure

Managing i cloud is a bit complex task so many factors need to consider, The logical design of the i cloud Cloud Environments should include measures to limit remote access to only those authorized to access resources, provide the capability to monitor the i cloud Environments, and allow for the remediation of systems in the

Managing i cloud Infrastructure Read More »

What is cloud service provider communications?

Cloud communications between the provider, its customers, its Vendors and its suppliers is critical for any environment. When you add the cloud to the mix, communication becomes even more central as a success factor overall. What is The Five Ws and One H method? The need to identify the five Ws and the one H

What is cloud service provider communications? Read More »

Top 2 types of Cloud Security Policies

Cloud Security Policies are crucial to implementing an effective data security strategy. They typically act as the connectors that hold many aspects of data security together across both technical and nontechnical components. The failure to implement and utilize policies in cloud-based (or non-cloud-based) environments would likely result in disparate parts or isolation of activities, effectively

Top 2 types of Cloud Security Policies Read More »

What to Expect from cloud Security Risk Responses?

Risk responses provides a consistent, organization-wide responses to risk by the organizational risk frame by taking these steps: Developing alternative courses of action for responding to risk (Risk Responses) Evaluating the alternative courses of action Determining appropriate courses of action consistent with organizational risk tolerance Implementing risk responses based on selected courses of action What

What to Expect from cloud Security Risk Responses? Read More »

What to Expect from computing Models?

Distributed Computing Models and distributed information systems are becoming increasingly common in conjunction with and amplified by the adoption of cloud computing services. The globalization of companies, along with collaboration and outsourcing, continues to allow organizations and users to avail themselves of distributed services. The drivers for adopting such services are many but include increasing

What to Expect from computing Models? Read More »

What is cloud supply chain management?

Supply chain management is big concern when the organizations have invested heavily to protect their key assets, resources, and intellectual property in recent years, changes to these practices present challenges and complexities. With the supply chain adjusting to include CSPs, security truly is only as good as the weakest link. Of late, many sizable and

What is cloud supply chain management? Read More »

What risk mitigation means?

Risk Mitigation and risk reduction is the approach and desired outcome when undertaking risk management and associated activities should always be to reduce and mitigate risks. Mitigation of risks reduces the exposure to a risk or the likelihood of it occurring. Risk mitigation to cloud-based assessments or environments is most often obtained by implementing additional

What risk mitigation means? Read More »

Why we need contracts in cloud computing?

To understanding and appreciating cloud computing contracts has long been the duty and focus of procurement and legal functions. Whether it is related to the single cloud computing contracts of personnel, roles, functions, or entire business functions, these have been availed and utilized globally to maximize cost benefits, plug skills gaps, and ultimately ensure that

Why we need contracts in cloud computing? Read More »

What is the chain of custody?

You must take care when gathering, handling, transporting, analyzing, reporting on, and managing evidence that the proper chain of custody or chain of evidence has been maintained. Every jurisdiction has its definitions as to what this may mean in detail; however, in general, a chain of custody and chain of evidence Why need Chain of

What is the chain of custody? Read More »

What is cloud security operations?

Cloud security operations management there are many aspects and processes of operations that need to be managed, and they often relate to each other. Cloud security operations management include the following: Information security management Configuration management Change management Incident management Problem management Release and deployment management Service-level management Availability management Capacity management Business continuity management

What is cloud security operations? Read More »

Cloud Computing Privacy Requirements (ISO/IEC 27018)

ISO/IEC 27018 addresses the cloud computing privacy aspects of cloud computing for consumers. ISO 27018 is the first international set of cloud computing privacy controls in the previous blog (How many Data Privacy Acts in the world?). The ISO published ISO 27018 on July 30, 2014, as a new component of the ISO 27001 standard.

Cloud Computing Privacy Requirements (ISO/IEC 27018) Read More »

What is Cloud Computing Network Security?

cloud Computing Network Security controls was discussed extensively earlier in this blog. You need to be able to follow and implement best practices for all security controls. About cloud Computing Network Security , consider the following general guidelines: Defense in depth VLANs Access controls Secure protocol usage (that is, IPSec and TLS) IDS/IPS system deployments

What is Cloud Computing Network Security? Read More »

What is cloud security management?

In partnership with the cloud security management professionals, you need to have a detailed understanding of the management operation of the cloud environment. As complex networked systems, clouds face the traditional computer and network security issues such as AIC. By imposing uniform management practices, clouds may be able to improve on some security updates and

What is cloud security management? Read More »

Backing Up and Restoring the Host Configuration

Host Configuration data in the cloud environment should be part of the backup plan. You should conduct routine tests and restore hosts as part of the disaster recovery plan (DRP) to validate the proper functioning of the backup system. This thought process is the same regardless of the vendor equipment being used to supply hosts

Backing Up and Restoring the Host Configuration Read More »

How to monitoring cloud performance?

Performance monitoring is essential for the secure and reliable operation of a cloud environment. Data on the performance of the underlying components may provide early indications of hardware failure Traditionally, four key subsystems are recommended for monitoring in cloud environments: Network: Excessive dropped packets Disk: Full disk or slow reads and writes to the disks

How to monitoring cloud performance? Read More »

How cloud patch management works?

Patch management is a crucial task. All organizations must perform and Regularly patch OSs, middleware, and applications to guard against newly found vulnerabilities or to provide additional functionality. Patch management is the process of identifying, acquiring, installing, and verifying patches for products and systems. Patches correct security and functionality problems in software and firmware. From

How cloud patch management works? Read More »

Google Cloud Physical Infrastructure

Big like Google Cloud Physical Infrastructure is more powerful but doesn’t matter the blue print is same for Mid-to-large corporations and government entities, independent system vendors (ISVs), and service providers use cloud infrastructure to build private and public clouds and deliver cloud computing services. Virtualization provides the foundation for cloud computing, enabling rapid deployment of

Google Cloud Physical Infrastructure Read More »

How does google cloud data center of works?

Google Data center design, planning, and architecture have long formed an integral part of the information technology (IT) services for providers of computing services. Over time, these have typically evolved and grown in line with computing developments and enhanced capabilities. Google Data center continue to be refined, enhanced, and improved upon globally; however, they still

How does google cloud data center of works? Read More »

How to install VM tools?

Securely configuring the virtualization management VM tools set is one of the most important steps when building a cloud environment. Compromising on the management VM tools may allow an attacker unlimited access to the VM, the host, and the enterprise network.Therefore, you must securely install and configure the management VM tools and then adequately monitor

How to install VM tools? Read More »

What is cloud network security?

Cloud network security is top end technology today we all using in the Data Center. When it comes to securing the network configuration, there is a lot to be concerned with. Several technologies, protocols, and services are necessary to ensure a secure and reliable network is provided to the end-user of the cloud-based services. Transport

What is cloud network security? Read More »

Business Continuity and Disaster Recovery (BCDR) Planning for IT Professionals

The creation and implementation of a fully tested BCDR Planning that is ready for the failover event have a great structural resemblance to any other IT implementation plan as well as other disaster response plans. It is wise to consult or even adapt existing IT project BCDR Planning and risk management methodologies. In this section,

Business Continuity and Disaster Recovery (BCDR) Planning for IT Professionals Read More »

How to do application security testing?

Security testing of web applications through the use of testing software is generally broken into two distinct types of automated testing tools. This section looks at these tools and discusses the importance of penetration testing, which generally includes the use of human expertise and automated tools. The section also looks at secure code reviews and

How to do application security testing? Read More »

Secure software development life cycle in cloud computing

The Secure software development life cycle in cloud computing is one of the most interesting concept. Although some view a single point-in-time vulnerability scan as an indicator of trustworthiness, much more important is a holistic evaluation of the people, processes, and technology that delivered the software and will continue to maintain it. Several software development

Secure software development life cycle in cloud computing Read More »

How cloud software development lifecycle works?

The cloud further heightens the need for applications to go through a software development lifecycle process  Following are the phases in all software development lifecycle process models: Business and security requirements and standards are being determined. This phase is the main focus of the project managers and stakeholders. Meetings with managers, stakeholders, and users are

How cloud software development lifecycle works? Read More »

Business Continuity and Disaster (BCDR) Recovery Strategy for IT Professionals

Business Continuity and Disaster Recovery (BCDR) Strategy for IT Professionals We already discussed BCDR scenarios. Although the departing positions are different and each situation requires a tailored approach, there are several common components to these scenarios. A logical sequence to discuss these components is location, data replication, functionality replication, event anticipation, failover event, and return

Business Continuity and Disaster (BCDR) Recovery Strategy for IT Professionals Read More »

What are the the BCDR Risks?

There are several categories of risks to consider in the context of BCDR. First, risks are threatening the assets and support infrastructure that the BCDR plan is protecting against. Second, some risks threaten the successful execution of a BCDR plan invocation; that is, what can go wrong if and when you need to failover? Does

What are the the BCDR Risks? Read More »

How to Secure Cloud Infrastructure?

For to understand how to Secure Cloud! We need to focus on countermeasure strategies that span those levels. First, it is highly recommended that you implement multiple layers of defense against any risk. For example, in physical protection there should not be reliance on a single lock; there should be multiple layers of access control,

How to Secure Cloud Infrastructure? Read More »

How Hypervisor Is Connected to cloud?

The Hypervisor becomes important about the compute resources of a host is the ability to manage and allocate these resources effectively, either on a per-guest operating-system (OS) basis or on a per-host basis within a resource cluster. The use of reservations, limits, and shares offers the contextual ability for an administrator to allocate the compute

How Hypervisor Is Connected to cloud? Read More »

What is Cloud Storage Encryption?

Cloud Storage Encryption is an important technology to consider and use when implementing systems that allow for secure data storage and usage from the cloud. Although having encryption enabled on all data across the enterprise architecture reduces the risks associated with unauthorized data access and exposure, there are performance constraints and concerns to be addressed.

What is Cloud Storage Encryption? Read More »

What is Cloud Infrastructure?

The cloud infrastructure consists of data centers and the hardware that runs in them, including compute, storage, and networking hardware; virtualization software; and a management layer The Physical Environment of the Cloud Infrastructure Just like traditional or onsite computing, cloud computing runs on real hardware that runs in real buildings. At the contemporary scale of

What is Cloud Infrastructure? Read More »

Cloud Computing Event Sources

Event Sources have tools at your disposal that can help you filter the large number of events that take place continuously within the cloud infrastructure, allowing you to selectively focus on those that are most relevant and important. Event sources are monitored to provide the raw data on events that will be used to paint

Cloud Computing Event Sources Read More »

Supporting Continuous Operations

For Supporting Continuous Operations When applying security strategies, it is important to consider the whole picture. Technologies may have dependencies or cost implications, and the larger organizational goals should be considered . To support continuous operations, the following principles should be adopted as part of the security operations policies: Audit logging: Higher levels of assurance

Supporting Continuous Operations Read More »

What is a data protection in cloud computing?

Data-protection policies should include guidelines for the different data lifecycle phases In the cloud, The following three policies should receive proper adjustments and attention Data retention Data deletion Data archiving Data-Retention Policies A data-retention policy is an organization’s established protocol for keeping information for operational or regulatory compliance needs. The objectives of a data-retention policy

What is a data protection in cloud computing? Read More »

How many Data Privacy Acts in the world?

Data Privacy Acts, Privacy and data protection (P&DP) matters are often cited as a concern for cloud computing scenarios. The P&DP regulations affect not just those whose personal data is processed in the cloud (the data subjects) but also those (the cloud service customers) using cloud computing to process others’ data and indeed those providing

How many Data Privacy Acts in the world? Read More »

How to Implement Data Discovery?

Data Discovery implementation is the solution that provides an operative foundation for effective application and governance for any of the P&DP fulfillments Data Discovery From the customer’s perspective The customer, in his role of the data controller, has full responsibility for compliance with the P&DP laws obligations. Therefore, the implementation of data discovery solutions with

How to Implement Data Discovery? Read More »

How to do Data Classification?

Data classification as part of the information lifecycle management (ILM) process can be defined as a tool for the categorization of data to help an organization effectively answer the following questions: What data types are available? Where is certain data located? What access levels are implemented? What protection level is implemented, and does it adhere

How to do Data Classification? Read More »

How to do data discovery?

How to do data discovery ? Data discovery is a departure from traditional business intelligence in that it emphasizes interactive, visual analytics rather than static reporting. The goal of data discovery is to work with and enable people to use their intuition to find meaningful and important information in data. This process usually consists of

How to do data discovery? Read More »

What is DLP?

DLP, also known as data leakage prevention or data loss protection, describes the controls put in place by an organization to ensure that certain types of data (structured and unstructured) remain under organizational controls, in line with policies, standards, and procedures. Controls to protect data form the foundation of organizational security and enable the organization

What is DLP? Read More »

How Data Masking done?

Data Masking is a process that need to provide confidentiality protection for data in cloud environments is a serious concern for organizations. The ability to use encryption is not always a realistic option for various reasons including performance, cost, and technical abilities. As a result, additional mechanisms need to be employed to ensure that data

How Data Masking done? Read More »

Cost Benefit Analysis of Cloud Computing

Cost Benefit Analysis of Cloud Computing is often identified as a key driver for the adoption of cloud computing. The challenge with decisions being made solely or exclusively on cost savings can come back to haunt the organization or entity that failed to take a risk-based view and factor in the relevant effects that may

Cost Benefit Analysis of Cloud Computing Read More »

Business Continuity and Disaster Recovery planning

Business Continuity and Disaster Recovery planning and management is the process by which risks and threats to the ongoing availability of services, business functions, and the organization are actively reviewed and managed at set intervals as part of the overall risk-management process. The goal is to keep the business operating and functioning in the event

Business Continuity and Disaster Recovery planning Read More »

Cloud Security Posture Management

The deployment of cloud solutions, by its nature, is often deemed a technology decision by Cloud Security Posture Management; however, it’s truly a business alignment decision. Although cloud computing no doubt enables technology to be delivered and utilized uniquely, potentially unleashing multiple benefits, the choice to deploy and consume cloud services should be a business

Cloud Security Posture Management Read More »

What are Cloud Computing elements?

Cloud Computing elements is a very important concept we need to consider before moving to the cloud environment. Below, Anything as a service (XaaS): The growing diversity of services available over the Internet via cloud computing as opposed to being provided locally or on-premises. Apache CloudStack: An open-source cloud computing and IaaS platform developed to

What are Cloud Computing elements? Read More »

Cloud Computing Roles & Responsibilities

The vendor offering cloud services. The CSP will own the datacenter, employ the staff, own and manage the resources (hardware and software), monitor service provision and security, and provide administrative assistance for the customer and the customer’s data and processing needs. Cloud Computing Roles & Responsibilities Examples include Amazon Web Services (AWS), Rackspace, and Microsoft’s

Cloud Computing Roles & Responsibilities Read More »

What are the cloud boundaries in IaaS, PaaS and SaaS?

Before moving to the main important cores of the cloud we need to understand what are the boundaries of cloud computing we need to understand some concepts. In legacy environments, we had bright-line definitions of the organization’s IT perimeter. Everything inside the perimeter belonging to the organization, including data, hardware, and risk; everything outside was

What are the cloud boundaries in IaaS, PaaS and SaaS? Read More »

What is Virtualization in cloud computing?

Virtualization in cloud computing is the term creating a virtual (a logical vs. a physical) version of something, including virtual computer hardware platforms, operating systems, storage devices, and computer network resources. Computer hardware virtualization is a way of improving overall efficiency. It involves CPUs that provide support for virtualization in hardware and other hardware components that

What is Virtualization in cloud computing? Read More »

Scroll to Top