What encompasses the actual data centers, servers, hardware, and facilities and forms the foundational layer of cloud security.
Physical Environment
In a cloud environment it replaces physical infrastructure with software-defined controls
Logical Design
The systematic process of evaluating the cloud infrastructure, applications, and data to identify vulnerabilities, quantify threats, and prioritize security measures.
Risk Assessment
Deployment model in which the customer has physical security responsibility
Private On-Premise
The two parameters which have to be defined to ensure an effective cloud BC/DR strategy
Recovery Time Objective (RTO) and Recovery Point Objective (RPO)
It represents the foundational nervous system of cloud infrastructure.
Network and communications
It implements a defense-in-depth model utilizing secured perimeters, facility shell hardening, restricted data halls, and granular rack-level access controls.
Physical design
The process of discovering and documenting all cloud assets.
Identification
The best method of data deletion for CSP stored data which is at the CSP location.
Cryptographic Erase/Crypto-shredding
Capacity
Operates at the subnet level as the first layer of defense, using rule-based stateless packet filtering to allow or deny traffic
Network Access Control Lists (NACLs)
In a secure data center, it protects the physical-to-logical boundary.
Environmental design
Defining threat scenarios using methodologies like STRIDE to identify spoofing, tampering, and denial of service across the customers architecture.
Threat mapping
The recommended version of encryption for data-in-transit.
TLS 1.3
Maintained and isolated write-once-read-many backups to prevent ransomware or rogue administrators from deleting historical data.
Immutable backups
It abstracts physical hardware into software-based logical pools.
Virtualization
It requires the integration of fault tolerance, zero-trust access, and automated infrastructure to ensure continuous operation under stress.
Design resilience
Specific weaknesses or flaws in cloud infrastructure, platforms, or applications.
Vulnerabilities
The recommended version of data encryption for data-at-rest.
AES256
The process where Recovery Time Objective and Recovery Point Objective are determined.
Business Impact Analysis (BIA)
The central command center used to orchestrate and configure the cloud infrastructure.
Management Plane
It involves utilizing multiple, redundant ISPs with cables entering a data center from distinct geographical points.
Multi-vendor pathway connectivity
An acronym used to identify negative risk treatment options.
MATA, Mitigate, Accept, Transfer, Avoid
The recommended control for data-in-use.
Digital Rights Management (DRM)
The type of plan testing which requires production to be shut down completely.
Full-interruption testing