<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>I Told You So, Volume 1 - cloud-security</title>
    <subtitle>Archive, Volume 1: conference talks and papers on security and risk, 2010 to 2018.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://blog.itys.net/vol1/tags/cloud-security/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2013-06-18T00:00:00+00:00</updated>
    <id>https://blog.itys.net/vol1/tags/cloud-security/atom.xml</id>
    <entry xml:lang="en">
        <title>Cloud Security</title>
        <published>2013-06-18T00:00:00+00:00</published>
        <updated>2013-06-18T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/cloudsecurity-isc2tc/"/>
        <id>https://blog.itys.net/vol1/posts/cloudsecurity-isc2tc/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/cloudsecurity-isc2tc/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The (ISC)2 Twin Cities Area Chapter presentation Cloud Security by Matthew J.
Harmon at the 2013 Annual Meeting introduces the fundamentals of virtualization
and cloud computing, emphasizing both their transformative potential and the
security considerations they entail.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;cloud-technology&quot;&gt;Cloud Technology&lt;&#x2F;h2&gt;
&lt;p&gt;First, Harmon unpacks virtualization basics like defining hypervisors (Type 1
and Type 2), guests, and core virtualization architecturesand maps these
concepts onto cloud service models such as Software-as-a-Service (SaaS),
Infrastructure-as-a-Service (IaaS), and Anything-as-a-Service. He highlights key
benefits including server consolidation, rapid provisioning and decommissioning
of resources, auto-patching and silent upgrades, reduced operational overhead,
and the ability to harvest processing power on demand. This framing positions
cloud computing as a natural extension of traditional virtualization that
delivers scale, flexibility, and cost efficiency.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;security-and-privacy-risks&quot;&gt;Security and Privacy Risks&lt;&#x2F;h2&gt;
&lt;p&gt;Second, the presentation shifts to the security and privacy risks inherent in
cloud environments. Harmon details confidentiality challenges in multi-tenant
platformswhere co-located data often lacks provider-managed encryption and
availability threats stemming from service outages, contractual lock-in, or
disputes with providers. He also addresses integrity risks due to limited
transparency into vendor operations and the potential for insider threats. To
mitigate these issues, he advocates a trust but verify approach: enforce
end-to-end encryption (in transit, processing, and at rest), conduct rigorous
vendor audits, codify security requirements in contracts, and maintain
continuous risk assessments to ensure that cloud-hosted assets remain under
organizational control and resilient against data breaches.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;56461_2013-06-18_CloudSecurity-ISC2TC.pdf&quot;&gt;Cloud Security&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
