ITIL 4 Acquiring Managing Cloud Services Certification Course: Agree - Shared Responsibilities
All cloud stakeholders must understand:
- CSP responsiblities
- Consumer organization responsibilities
Differentiate CSP partner responsibilities
Responsibilities vary depending on:
- Hosting
- Services consumed
- Partner and broker use
- Terms and conditions
- Compliance
Consumer:
- Ensures security
- Understands CSP security responsibilities
- Reviews audit results
CSPs don´t review security for individual consumers
Consumer defines:
- Secure cloud usage
- Security tool usage
Check differences between CSPs´shared responsibilities
Responsibilities if service in-house ?
All responsibilities assigned ?
Factors affecting responsibilities:
- Service relationship
- Service type
- Integration
- Laws and regulations
Cloud consumer and CSP never share responsibility: each controls its own area of ownership for security
Consumer audit access and configures security
Consumer organization security responsiblity: when it moves application, data, containers, workloards to the cloud
CSP security responsibility for other activities like physical infrastructure
Define security responsibilities
Work with CSP
Meet security needs
Reduce costs
Dedicated security approach for each:
- Environment
- Application
- Service
Weakest link defines security
CSP provides standard, proven security
Consumer security developed when needed
Consumer security must work within CSP framework
1. Shared responsibility model Model defines:
Model outlines responsibility for:
Responsibilities vary:
|
Define responsibilities to reduce risk
CSP never has full responsibility
Understand responsibilities before CSA
Key factors:
- Service relationship
- Service package
- Tailoring
- Integration
- Regulation
In-house: service provider responsible for all security
Cloud environment: security responsibility shared
Security ownership clearly defined
Secure environment with less operational overhead
Security gaps affect all systems
CSP security standardized
Consumer security less comprehensive
Include security in CSP agreement
1.1 Provider and consumer responsibilities
Cloud vendor controls:
- Physical infrastructure security
- Surveillance and security (CSP systems)
- Network security
- Resource management
- Access control
- Monitoring and security
- Emergency response
- Business continuity planning
- Virtualization and segmentation
Consumer responsibilities:
- Identity and access controls
- Data security and security management
- Business processes using cloud
Single security aspects never shared
Consumer and CASP have total control over their responsibilities
Consumer right to audit verification
Ensure non-CSP responsibilities are managed
Go back to ITIL 4 Acquiring Managing Cloud Services Certification Course: Agree to finish this chapter or to the main page ITIL 4 Acquiring Managing Cloud Services Certification Course.
Interesting Topics
-
Be successfully certified ITIL 4 Managing Professional
Study, study and study, I couldn’t be successfully certified without studying it, if you are interested...
-
Be successfully certified ITIL 4 Strategic Leader
With my ITIL 4 Managing Professional certification (ITIL MP) in the pocket, it was time to go for the...
-
Hide visual and change background color based on selection
Some small tricks to customize the background colour of a text box...
-
Stacked and clustered column chart or double stacked column chart
In excel, I use a lot the combination of clustered and stacked chart...