Understand cloud computing concepts
Describe Cloud Reference Architecture
Understand Security Concepts Relevant to Cloud Computing
Understand Design Principles of Secure Cloud Computing
Evaluate Cloud Service Providers
100

A consumer can unilaterally provision computing capabilities, such as server time and network storage, as needed automatically without requiring human interaction with each service provider.

On-demand self-service

100

Capability type which includes eMail, storage (Box), credit card processing, and expense reporting management

SaaS

100

A concept that includes: Create, Store, Use, Share, Archive, Destroy.

Data Lifecycle

100

The preferred phase of the data lifecycle for data classification.

Create

100

A tool used to verify a cloud service provider against your security criteria.

SOC 2 

200

Capabilities are available over the network and accessed through standard mechanisms that promote use by heterogeneous thin or thick client platforms (e.g., mobile phones, tablets, laptops, and workstations).

Broad Network Access

200

Capability type which includes cloud-based database engines, big-data services, like data warehousing.

PaaS

200

The encryption algorithm resides within the DBMS

Transparent Database Encryption (TDE)

200

How data moves across logical states, applications, formats, physical/network locations, regions, devices and users.

Data flow

200

A tool which includes the customer's security requirements.

Contract

300

The provider’s computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources dynamically assigned and reassigned according to consumer demand. There is a sense of location independence in that the customer generally has no control or knowledge over the exact location of the provided resources but may be able to specify location at a higher level of abstraction (e.g., country, state, or datacenter).

Resource Pooling

300

Capability type which includes virtualized servers, block storage, object storage, and networking capacity.

IaaS

300

Authentication credentials that allow applications and services to communicate.

Secrets

300

A process which assesses which business functions are most critical and determine the maximum acceptable downtime (RTO) and data loss (RPO)

Business Impact Analysis

300

A tool used to establish guaranteed uptime percentages.

Service Level Agreement (SLA)

400

Capabilities can be elastically provisioned and released, in some cases automatically, to scale rapidly outward and inward commensurate with demand. To the consumer, the capabilities available for provisioning often appear to be unlimited and can be appropriated in any quantity at any time.

Rapid Elasticity

400

Service category that includes volume and object storiage.

IaaS

400

A US standard for the protection of encryption algorithms and keys.

FIPS 140-3

400

A process to identify potential threats and map them against cloud-native dependencies like identity providers and APIs.

Risk Assessment

400

A customer who cannot leave a CSP because of proprietary data formats.

Vendor lock-in

500

Allocation of physical or virtual resources such that multiple tenants and their computations and data are isolated from and inaccessible to one another.

Multi-Tenancy

500

Service category which includes Structured and Unstructured data storage.

PaaS

500

Master keys are split into multiple fragments and distributed to trusted custodians.  A predefined threshold is required to reconstruct the key, preventing SPOF or a malicious insider.

M-of-N Threshold Cryptography

500

A process that compares potential losses against the costs of deploying specific cloud security controls.

Cost-Benefit Analysis

500

A customer cannot access their cloud data because the cloud carrier (ISP) is experiencing an outage.

Vendor lock-out

M
e
n
u