Cloud Security Project - Choose ONE topic from attachment and follow the instructions below
1. Discuss Shared technology vulnerabilities in the cloud, 2. How does a customer know what software versions cloud providers are using? Without
that knowledge how can they do a proper risk assessment? 3. What policies should be in place for users to help reduce cloud based threats. 4. How can a consumer evaluate the physical security of their cloud provider? What
standards should apply. What external and internal barriers should be in place? What access controls? What sort of surveillance should be provided, power redundancy, and fire suppression? Is a service contract sufficient? Should physical inspection be available? What about physical location? Are their volcanoes, tornadoes, earthquakes or other natural disasters common? Is the site near political unrest? Access to water? Outside temperature? Is there a physical buffer? Should the walls be made of ballistic material to withstand explosions? Staffing
5. Discuss the four tiers of Uptime Institutes functional recommendations for physical security for data centers.
6. Which is better for security server virtualization or application isolation? Why? 7. What are desktop virtualization, storage virtualization, memory virtualization, network
virtualization? What are the security issues and benefits for each 8. The relationship of net neutrality and cloud security 9. Ensuring Proper Access Control in the Cloud? 10. Cloud security risks from misconfiguration 11. Cloud service interruptions from DDOS 12. Preventive controls for Internal (non-routable) security threats 13. Detective Controls for routable and non-routable addresses 14. How security zones, groups or domains have replaced traditional zones and tiers 15. On being a cloud broker -tasks and challenges 16. Trust boundaries and division of responsibilities 17. Elasticity effect on threat surface 18. How to insure that your cloud provider has appropriate detective and preventive controls
in place 19. How to secure virtualization layer 20. Threats to the hypervisor 21. What hardening means 22. Top ten recommendations for securing virtual servers 23. Vulnerabilities resulting from web programming frameworks 24. Preventing attacks on web applications 25. The relationship between DOS attacks and your cloud invoice 26. Good browser hygiene and cloud security 27. Compartmentalization and isolation in virtual multi-tenant environments 28. Security standards in PaaS API design 29. FIPS 30. Data Protection techniques under the The Data Accountability and Trust Act 31. Comparing block symmetric algorthms with streaming symmetric algorthms
32. Message authentication codes and hash functions. 33. Externalizing authentication: Trust Boundaries and IAM 34. Sustaining IAM with rapid turnover and job changes 35. IAM Compliance Management 36. Identity Federation Management 37. OAUTH 38. ITIL 39. ISO 27001/27002 40. Vulnerability and Risk assessment 41. Incident response 42. What can we learn from CCID (Cloud Computing Incidents Database 43. Cloud Health monitoring (internal and 3rd party) 44. Reading a Cloud Security Provider agreement 45. Discussing the data life cycle in the context of cloud computing 46. Facebook’s new privacy initiative 47. Cloud Security and the Federal Rules of Civil Procedure