cloud computing management
Risk Management Evaluation Assignment 2 ITC561
Risk Management Evaluation Assignment 2 ITC561
TABLE OF CONTENT
ASSIGNMENT’S ITEM
· EXECUTIVE SUMMARY PAGE 4
· INFORMATION SECURITY ASSESSMENT PAGE 5 – 6
· RISK MANAGEMENT ASSESSMENT PAGE 7 -11
· REFERENCE PAGE 12
Executive Summary
As we selecting Google Docs as the SaaS provider Proper actions are to be upheld when handling Google Docs servers as the software service providers. This is a challenge posed from several grounds, starting from its vulnerability to hacking and eavesdropping to the complex breakdown of the whole server. Thorough backups should be constantly made in order to maintain security of storage. Credentials provide some kind of privacy to users, and therefore, confidentiality is significant to each particular user and subscriber. Moreover, these logon credentials bar against unauthorized access, as well as providing for identification during a breach in the cloud’s network security. In as much as Google Docs provide faster access, the enlisted challenges must be delved into, and the proposed security measures enforced.
Google Docs services offer quick and efficient data storage centers that allow companies and business organizations realize higher customer and client transactions. Most of the considerations to handle clients on an expanding scale lies within these services and the promising scenarios held within the servers. Additionally, most of the transactions held within the clouds could hold moral issues, but with advancements in technological security and ethics, more services are being engineered to make up for the loopholes observed within the servers and the client providers. These software-based services are bound to last for longer periods with intermediary updates and certificate upgrading to ensure enforcement of commitment among the subscribers.
Each specific aspect of cloud computing must be considered with utmost care before deploying a specific kind of server to be used in the migration process or any other kind of attachment for provision of client services round the clock. These can only be achieved and attained through a careful model of study of the challenges of the cloud servers.
Information Security Assessment
Users own accounts separately. These require security credentials during logging in to access the account services and details. Several failed repeated attempts lead to closure of the accounts, or temporary blockage. Every user is entitled to their own accounts with no access to other person’s accounts. Super users are administrators with credentials to reset passwords and edit client information, with privileges to delete users who violate rules. Passwords must be changed occasionally to dissuade hackers from accessing critical and sensitive information. All users have different levels of access to the system, with a few users having extreme user privileges to oversee the accounts of other users, and monitor their transactions. These are the super users with ability to delete or add users into the system. Default account settings are provided for other users who might want to provide feedback. Also, passwords of all subscribed users are encrypted to ensure security.
All user information sent over the network has VPNs for remote connection. These are secure and tunneled securely through secure tunnels. The sessions created for the VPNs are destroyed to prevent tracking and unauthorized access by crackers and hackers.
All applications are enforced with SSL certificates that ensure that they are signed to prevent against alterations. Moreover, these https and SSL certificates provide for security within the network.
Cloud connections must comply with Security Assertion Markup Language for any transaction to prevent against alterations and any overwriting. All encrypted data should provide for decryption keys to be used in order to identify with information within the cloud Google Docs or Gmail servers.
Each user shall be authorized to access different levels of files on the cloud server. Only administrators are to be granted authority to edit or alter information stored in the servers. This is an entire session of setting up privileges of access to the resources that can be accessed by different persons or users within the network.
Availability is an essential part of Google Docs. In every instance, one is able to access the resources on the public cloud. With these rights and advantages comes a big challenge of confidentiality. Public cloud servers mean that every individual can access the information. Therefore, confidentiality of users’ information should be maintained by the administrators. Security key to confidentiality and both are a function of each other. This calls for utmost integrity when instituting rights to administrators.
Non-repudiation is an essential component of cloud computing which ensures that all data is valid and is secure against attacks by malwares and such kinds of viruses. This also entails digital signing of data against unauthorized copying and moving, since non-repudiation entails also copyright information.
Availability defines the whole logic of implementing any cloud-based data migration. This is due to the requirement of ease of accessibility to the particular resources by different clients and vendors. Moreover, agreement services are based on availability and this hence determines the nature and kind of services between cloud providers and the clients. Gmail offers these features of cloud connectivity with easily available connections.
Risk Management Assessment
|
A. Data Classification
|
Yes / No / NA (Not Applicable)
|
Proposed Controls
|
CONSEQUENCES
|
LIKELIHOOD
Almost certain |
Rating
|
|
|
6.1 |
Does all critical business data have an identified owner?
|
Yes |
|
Extreme |
|
High |
|
6.1 |
Data is classified according to the NSW Classifications and Labeling Guidelines?
|
No |
|
Minor |
Possible |
Low |
|
6.3 |
Is access to sensitive customer data authorized by the data owner?
|
No |
|
Catastrophic |
Almost certain |
High |
|
6.4 |
All data files and locations that may contain confidential or restricted data are documented?
|
No |
|
Catastrophic |
Likely |
High |
|
C. Backup
|
Yes / No / NA (Not Applicable)
|
Proposed Controls
|
CONSEQUENCES
|
LIKELIHOOD
|
Rating
|
|
|
6.14 |
Are backups of business critical data performed regularly?
|
Yes |
|
Major |
Almost certain |
High |
|
6.15 |
Is there an automated way to verify all backups completed?
|
No |
|
Minor |
Rare |
Low |
|
6.16 |
Do you periodically restore from backup tapes to ensure integrity?
|
No |
|
Isolated |
Rare |
Low |
|
6.17 |
Are backup tapes stored in an environmentally controlled and secure area?
|
Yes |
|
Major |
Likely |
Medium |
|
6.18 |
Are backup tapes stored off-site and how is access protected?
|
Yes |
|
Minor |
Possible |
Moderate |
|
6.19 |
Is a regular audit conducted to account for all backup tapes?
|
No |
|
Isolated |
Unlikely |
Low |
|
6.20 |
If backup tapes are ever destroyed is there a procedure?
|
Yes |
|
Catastrophic |
Almost certain |
High |
|
A. Account Management
|
Yes / No / NA |
Proposed Controls
|
CONSEQUENCES
|
LIKELIHOOD
|
Rating
|
|
|
7.1 |
Is each customer account owned or sponsored by the customer?
|
Yes |
|
Minor |
Likely |
Moderate |
|
7.2 |
Is concurrent access prohibited?
|
Yes |
|
Minor |
Almost certain |
Moderate |
|
7.3 |
Are accounts locked out after a number of failed attempts?
|
Yes |
|
Isolated |
Likely |
Moderate |
|
7.4 |
Are accounts disabled after a period of inactivity?
|
Yes |
|
Major |
Almost certain |
High |
|
7.5 |
Are accounts periodically reconciled to existing users?
|
Yes |
|
Isolated |
Likely |
Moderate |
|
7.6 |
Are privileged accounts set up for emergency access and logged and subject to regular reviews?
|
Yes |
|
Major |
Almost certain |
High |
|
7.7 |
Do you have a list of accounts with root or admin privileges
|
Yes |
|
Major |
Possible |
Moderate |
|
7.8 |
Are default system accounts disabled? (e.g. Windows default remote assistant accounts, Oracle’s default DBA account)
|
No |
|
Isolated |
Unlikely |
Low |
|
B: VPN
|
Yes / No / NA |
Proposed Controls
|
CONSEQUENCES
|
LIKELIHOOD
|
Rating
|
|
|
10.14 |
Is a personal firewall implemented for computers which use a VPN?
|
Yes |
|
Extreme |
Possible |
Moderate |
|
10.15 |
Is VPN access only granted to computers running antivirus software and a personal firewall?
|
No |
|
Minor |
Rare |
Low |
|
10.16 |
IS VPN access cancelled as soon as the business requirement is no longer needed?
|
No |
|
Minor |
Unlikely |
Low |
|
D. Cryptography
|
Yes / No / NA |
Proposed Controls
|
CONSEQUENCES
|
LIKELIHOOD
|
Rating
|
|
|
10.20 |
Is there a register of all SSL certificates and their expiry date?
|
Yes |
|
Catastrophic |
Likely |
High |
|
10.21 |
Do SSL certificates match domains?
|
Yes |
|
Catastrophic |
Almost certain |
High |
|
10.22 |
Is SSL/HTTPS enforced for all web applications accessing confidential and restricted data?
|
N/A |
|
Extreme |
Likely |
high |
|
Access/Change/BCP/Service
|
Yes / No / NA |
Proposed Controls
|
CONSEQUENCES
|
LIKELIHOOD
|
Rating
|
|
|
11.1 |
Access Control: Is the solution Security Assertion Markup Language 2.0 (SAML 2.0) compliant for authenticating users?
|
Yes |
|
Extreme |
Likely |
High |
|
11.2 |
Change Control: Authorization – what degree of granularity does the system offer in defining roles?
|
N/A |
|
|
|
|
|
11.3 |
Change Control: Isolation – what security standards are followed in the operation of the service?
|
N/A |
|
|
|
|
|
11.4 |
Change Control: Isolation – is compliance with internal security standards assessed by a compliance audit at least annually?
|
Yes |
|
Major |
Likely |
Moderate |
|
11.5 |
Change Control: Isolation – what external application vulnerability scans / assessments / audits are done and how often?
|
N/A |
|
|
|
|
|
11.6 |
Change Control: Isolation – does data transit non – Australian networks, if so where?
|
N/A |
|
|
|
|
|
11.7 |
Change Control: Isolation – is data stored outside of Australia, if so where?
|
N/A |
|
|
|
|
|
11.8 |
Business Continuity: what level of availability does the service offer?
|
N/A |
|
|
|
|
|
11.9 |
Business Continuity: what provisions are in place to exit the service?
|
N/A |
|
|
|
|
|
11.10 |
Business Continuity: what provisions are in place to protect intellectual property?
|
N/A |
|
|
|
|
|
11.11 |
Business Continuity: what provisions are in place for decryption key escrow, for encrypted solutions?
|
N/A |
|
|
|
|
|
11.12 |
Access, Change and Fault Reporting: what activity and resource usage reports are provided?
|
N/A |
|
|
|
|
|
11.13 |
Service Details: does the solution follow web standards? e.g. OWASP
|
Yes |
|
Major |
Almost certain |
high |
|
11.14 |
Service Details: if handling credit card details, is the solution PCI-DSS compliant?
|
Yes |
|
Isolated |
Rare |
Low |
|
11.15 |
Service Details: what other auditable IT standards are followed and how often are audits performed?
|
N/A |
|
|
|
|
|
11.16 |
Service Details: are the results of audits and certifications made available to customers?
|
No |
|
Minor |
Unlikely |
Low |
Ramgovind, S., Eloff, M., & Smith, E. (2010). The management of security in cloud computing. Information Security for South Africa (ISSA), 2010, 1-7. http://ezproxy.csu.edu.au/login?url=http://dx.doi.org/10.1109/ISSA.2010.5588290
Defence Signals Directorate. (2011). Cloud Computing Security Considerations. Canberra: Department of Defence Retrieved from
http://www.asd.gov.au/infosec/cloudsecurity.htm
|
|
Page 1 |
|
|
|
|
|
|
|
Page 2 |
|
|
|
|
|