{"id":909,"date":"2019-10-18T19:49:12","date_gmt":"2019-10-18T19:49:12","guid":{"rendered":"http:\/\/customers-love-solutions.com\/?p=909"},"modified":"2019-11-21T17:14:16","modified_gmt":"2019-11-21T17:14:16","slug":"3-0-0-secure-your-cloud-applications","status":"publish","type":"post","link":"https:\/\/customers-love-solutions.com\/?p=909","title":{"rendered":"3.0.0 Secure your cloud applications"},"content":{"rendered":"\n<h4 class=\"wp-block-heading\">Security, a shared responsibility between Public Service Provider and the Business Customer.<\/h4>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"991\" height=\"1024\" src=\"http:\/\/customers-love-solutions.com\/wp-content\/uploads\/2019\/11\/20191017-AWSOMEDAY2019_3.0.0-Security_Shared_Responsibility-991x1024.jpg\" alt=\"\" class=\"wp-image-817\" srcset=\"https:\/\/customers-love-solutions.com\/wp-content\/uploads\/2019\/11\/20191017-AWSOMEDAY2019_3.0.0-Security_Shared_Responsibility-991x1024.jpg 991w, https:\/\/customers-love-solutions.com\/wp-content\/uploads\/2019\/11\/20191017-AWSOMEDAY2019_3.0.0-Security_Shared_Responsibility-290x300.jpg 290w, https:\/\/customers-love-solutions.com\/wp-content\/uploads\/2019\/11\/20191017-AWSOMEDAY2019_3.0.0-Security_Shared_Responsibility-768x794.jpg 768w, https:\/\/customers-love-solutions.com\/wp-content\/uploads\/2019\/11\/20191017-AWSOMEDAY2019_3.0.0-Security_Shared_Responsibility-594x614.jpg 594w, https:\/\/customers-love-solutions.com\/wp-content\/uploads\/2019\/11\/20191017-AWSOMEDAY2019_3.0.0-Security_Shared_Responsibility.jpg 1024w\" sizes=\"auto, (max-width: 991px) 100vw, 991px\" \/><figcaption>Shared responsibility model.<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Shared responsibilities<\/h3>\n\n\n\n<p>Security responsibility of the cloud infrastructure include: <br><br>o <strong>Design for security<\/strong> (physical structure and the software layer regulatory  <br>   compliance &amp; security)<br>o <strong>Constantly monitored<\/strong> (monitoring of security incident or compromise)<br>o <strong>Highly automated <\/strong>(responses are highly automated)<br>o <strong>Highly available<\/strong><br>o <strong>Highly accredited<\/strong> (consequences: physical environments are highly <br>   accredited)<br><br>Security responsibility of AWS for the cloud means a framework build for: <br>o <strong>Hosts, networks, software, facilities<\/strong><br>o <strong>Protection of AWS global infrastructure<\/strong><br>o <strong>Availability of 3rd-party audit reports<\/strong><br><br>But the <strong>business customer is also responsible for security<\/strong> in his layers. For example AWS provides a <strong>raw unformatted device for storage<\/strong> and the customer has to consider <strong>what data should be stored,<\/strong> which AWS <strong>services to use<\/strong>, in <strong>which region<\/strong> to <strong>store and mirror<\/strong> the data, in what <strong>content format and structure<\/strong> and <strong>who has access<\/strong>. How is the data delivered in transit and in rest. How to store, will it encrypted and how long it should be stored? <br><strong>Least necessary privileges<\/strong> is the <strong>best practice<\/strong> <strong>only need to have access not nice to have. <\/strong>The rule configuration is one core customer responsibility. In a holistic view we end in a <strong>shared responsibility model<\/strong>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Unmanaged Services<\/strong><\/h3>\n\n\n\n<p>Different industries and businesses have a variety of <strong>specific security requirements<\/strong>, only the business owner could know. The customer own everything <strong>on top of a virtual server<\/strong>. The customer owns likewise everything you format <strong>on top of a data volume<\/strong>, like an <strong>AMAZON EBS<\/strong>. AWS provides a raw device (<strong>Unmanaged Services<\/strong>) configured for security by the customer. Using <strong>Unmanaged Services<\/strong> the customers takes the most responsibility for the services.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Managed Services<\/h3>\n\n\n\n<p>For the <strong>Managed Services<\/strong> AWS takes over some of the tasks, to provide security. E.g. in the operation systems <strong>database patching &amp; installation<\/strong>, fire<strong>wall configuration, disaster recovery<\/strong> <strong>is managed by AWS<\/strong>. AWS surfaces the customer database into his Virtual Private Cloud (VPC) and it get&#8217;s the network isolation and protection of the customer. <br>AWS manage the <strong>virtual machine<\/strong>, on which <strong>SQLServer, MySQL, PostgreSQL <\/strong>or<strong> Oracle<\/strong> is running. In this case the responsibility is different shared: <strong>Operating systems and server<\/strong> are the job of AWS. The customer is managing <strong>access to the data base server<\/strong>. Likewise on <strong>AMAZON DynamoDB, S3, RDS<\/strong>, the customer don&#8217;t configure the servers on which those application environments run.<\/p>\n\n\n\n<p><strong>Unmanaged Services<\/strong><br>o Amazon EC2<br>o Amazon EBS<\/p>\n\n\n\n<p><strong>Managed Services<\/strong><br>o Amazon RDS<br>o AMAZON S3<br>o Amazon DynamoDB<\/p>\n\n\n\n<p><strong>Operations<\/strong><br>o Guest OS patching<br>o Database patching<br>o Firewall configuration<br>o Disater recovery<br>o User data<br><br>And if you follow a <strong>multi cloud approach<\/strong>, you need to align the security guidline across all Public Cloud Provider (PCP), you integrate in your cloud infrastructure. But multi cloud solution is an other topic to discuss.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security, a shared responsibility between Public Service Provider and the Business Customer. Shared responsibilities Security responsibility of the cloud infrastructure include: o Design for security (physical structure and the software layer regulatory compliance &amp; security)o Constantly monitored (monitoring of security incident or compromise)o Highly automated (responses are highly automated)o Highly availableo Highly accredited (consequences: physical [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":958,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20,21,3,9,5,19],"tags":[],"class_list":["post-909","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-aws-cloud-architecture","category-awsomeday","category-conferences","category-infrastructure","category-native-cloud","category-self-learning","clearfix","post-index","fader"],"jetpack_featured_media_url":"https:\/\/customers-love-solutions.com\/wp-content\/uploads\/2019\/11\/Thumbnail-sky-Shared_Responsibility-Security-1.jpg","_links":{"self":[{"href":"https:\/\/customers-love-solutions.com\/index.php?rest_route=\/wp\/v2\/posts\/909","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/customers-love-solutions.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/customers-love-solutions.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/customers-love-solutions.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/customers-love-solutions.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=909"}],"version-history":[{"count":17,"href":"https:\/\/customers-love-solutions.com\/index.php?rest_route=\/wp\/v2\/posts\/909\/revisions"}],"predecessor-version":[{"id":1066,"href":"https:\/\/customers-love-solutions.com\/index.php?rest_route=\/wp\/v2\/posts\/909\/revisions\/1066"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/customers-love-solutions.com\/index.php?rest_route=\/wp\/v2\/media\/958"}],"wp:attachment":[{"href":"https:\/\/customers-love-solutions.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=909"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/customers-love-solutions.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=909"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/customers-love-solutions.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=909"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}