CCSP (ISC)2 Certified Cloud Security Professional Official Study Guide by O'Hara & Ben Malisow
Author:O'Hara & Ben Malisow
Language: eng
Format: epub
ISBN: 9781119277439
Publisher: Wiley
Published: 2017-04-24T15:00:00+00:00
Cryptography
Although we will not be discussing the specifics of encryption here, the CCSP candidate must be familiar with the different types of encryption, the places where it is used, and the use case for each. This is just one more example of where the CCSP can add value to the customer since most customers do not understand the different types and use cases for encryption. What follows are descriptions of several of these and how they can be effectively used as part of the overall cloud application security scheme.
Encryption of Data at Rest Data at rest, whether it be short-term or long-term storage, should be protected from multitenancy issues and similar problems. When working in the cloud, you are in a shared environment and must always be aware of possible data leakage. Therefore, encrypting data at rest is a great way to prevent anyone from seeing data that they are not authorized to see. Encryption involves the use of keys. Without access to the proper keys, the data is unreadable and unusable, which ensures its safety from prying eyes. This use of encryption also protects the consumer from what might ultimately be determined to be lawful but unwanted access to their data. There may be situations where, while your data is logically separated from someone else’s data, both sets of data are physically stored together on a hard drive that is confiscated for legal reasons. You would not want the police or other prying eyes to have access to your data even though they have a valid warrant for other data on the same drive.
Encryption of Data in Transit Encryption of data in transit is necessary for many of the same reasons, with the added threat that while data is being transmitted, unauthorized eyes might land on it or redirect it, causing data leakage. Encrypting data in transit also uses encryption keys, typically in the form of SSL certificates. The proper care of those certificates is paramount. If compromised, you have lost the keys to the kingdom. Cloud-based certificate providers spend millions of dollars on securing their operations for this very reason.
Encryption of Data While in Use Another use case of encryption that is not anywhere close to widespread adoption is something called homomorphic encryption. The idea is that if we could keep a dataset encrypted while being manipulated in memory or shared with another application, we would then never have to decrypt it, making the data transaction safer on an order of magnitudes. Another way to look at this is that homomorphic encryption will produce the same result when operating on cipher text as would occur using the same data in clear text. One impediment to the implementation of this idea is that homomorphic encryption is very slow due to the heavy mathematical calculations that are needed. Therefore, it is not an effective solution today.
The single most effective way to combat multitenancy issues, data leakage, and similar problems is by using encryption. We call the field of dealing with encryption cryptography.
Download
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.
Sass and Compass in Action by Wynn Netherland Nathan Weizenbaum Chris Eppstein Brandon Mathis(7810)
Grails in Action by Glen Smith Peter Ledbrook(7719)
Azure Containers Explained by Wesley Haakman & Richard Hooper(6859)
Configuring Windows Server Hybrid Advanced Services Exam Ref AZ-801 by Chris Gill(6857)
Running Windows Containers on AWS by Marcio Morales(6383)
Kotlin in Action by Dmitry Jemerov(5092)
Microsoft 365 Identity and Services Exam Guide MS-100 by Aaron Guilmette(5079)
Combating Crime on the Dark Web by Nearchos Nearchou(4654)
Microsoft Cybersecurity Architect Exam Ref SC-100 by Dwayne Natwick(4636)
Management Strategies for the Cloud Revolution: How Cloud Computing Is Transforming Business and Why You Can't Afford to Be Left Behind by Charles Babcock(4438)
The Ruby Workshop by Akshat Paul Peter Philips Dániel Szabó and Cheyne Wallace(4343)
The Age of Surveillance Capitalism by Shoshana Zuboff(3983)
Python for Security and Networking - Third Edition by José Manuel Ortega(3901)
The Ultimate Docker Container Book by Schenker Gabriel N.;(3565)
Learn Wireshark by Lisa Bock(3546)
Learn Windows PowerShell in a Month of Lunches by Don Jones(3530)
Mastering Python for Networking and Security by José Manuel Ortega(3376)
Mastering Azure Security by Mustafa Toroman and Tom Janetscheck(3356)
Blockchain Basics by Daniel Drescher(3329)
