A consumer can unilaterally provision computing capabilities, such as server time and network storage, as needed automatically without requiring human interaction with each service provider.
On-demand self-service
Capability type which includes eMail, storage (Box), credit card processing, and expense reporting management
SaaS
A concept that includes: Create, Store, Use, Share, Archive, Destroy.
Data Lifecycle
The preferred phase of the data lifecycle for data classification.
Create
A tool used to verify a cloud service provider against your security criteria.
SOC 2
Capabilities are available over the network and accessed through standard mechanisms that promote use by heterogeneous thin or thick client platforms (e.g., mobile phones, tablets, laptops, and workstations).
Broad Network Access
Capability type which includes cloud-based database engines, big-data services, like data warehousing.
PaaS
The encryption algorithm resides within the DBMS
Transparent Database Encryption (TDE)
How data moves across logical states, applications, formats, physical/network locations, regions, devices and users.
Data flow
A tool which includes the customer's security requirements.
Contract
The provider’s computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources dynamically assigned and reassigned according to consumer demand. There is a sense of location independence in that the customer generally has no control or knowledge over the exact location of the provided resources but may be able to specify location at a higher level of abstraction (e.g., country, state, or datacenter).
Resource Pooling
Capability type which includes virtualized servers, block storage, object storage, and networking capacity.
IaaS
Authentication credentials that allow applications and services to communicate.
Secrets
A process which assesses which business functions are most critical and determine the maximum acceptable downtime (RTO) and data loss (RPO)
Business Impact Analysis
A tool used to establish guaranteed uptime percentages.
Service Level Agreement (SLA)
Capabilities can be elastically provisioned and released, in some cases automatically, to scale rapidly outward and inward commensurate with demand. To the consumer, the capabilities available for provisioning often appear to be unlimited and can be appropriated in any quantity at any time.
Rapid Elasticity
Service category that includes volume and object storiage.
IaaS
A US standard for the protection of encryption algorithms and keys.
FIPS 140-3
A process to identify potential threats and map them against cloud-native dependencies like identity providers and APIs.
Risk Assessment
A customer who cannot leave a CSP because of proprietary data formats.
Vendor lock-in
Allocation of physical or virtual resources such that multiple tenants and their computations and data are isolated from and inaccessible to one another.
Multi-Tenancy
Service category which includes Structured and Unstructured data storage.
PaaS
Master keys are split into multiple fragments and distributed to trusted custodians. A predefined threshold is required to reconstruct the key, preventing SPOF or a malicious insider.
M-of-N Threshold Cryptography
A process that compares potential losses against the costs of deploying specific cloud security controls.
Cost-Benefit Analysis
A customer cannot access their cloud data because the cloud carrier (ISP) is experiencing an outage.
Vendor lock-out