
336
Security Information and Event Management – Software Development Lifecycle
review questions, 118 –121
risks by deployment model, 97–104
risks by service model, 104 –106
shared cloud platform risks and
responsibilities, 95–97, 96
summary, 116
virtualization, 106–112
written labs, 117
data lifecycle, 73–77, 73
egress monitoring, 85–86
encryption, 79–81
exam essentials, 86–87
general considerations, 33
IaaS, 32
KVMs, 199
logical frameworks, 129–130
networking, 130–131
obscuring data, 81–83, 83
PaaS, 32
redundancy, 187–190, 189
remote administrative access
responsibilities, 129
review questions, 88–91
SaaS, 32–33
sensitive data, 33–36
SIEM, 84
storage architectures, 78–79
summary, 86
written labs, 87
Security Assertion Markup Language
(SAML), 162
Security Information and Event Management
(SIEM), 84
security misconfigurations in application
security, 169
security monitoring in community clouds, 99
security operations centers, 201
continuous monitoring, 201–202
incident management, 202–203
Security Rule, 245
Security, Trust, Assurance, and Risk (STAR)
program, 141, 286–287
selection of controls, cloud provider
responsibilities, 132–133
self-assessment in Open Certification
Framework, 286
sensitive data, 33
application security, 169
description, 16
encryption, 35
hardening devices, 33–35
layered defenses, 35–36
sensitivity in data classification, 48
service-level agreements (SLAs), 17–18, 242,
281–284
service models in cloud computing, 10–11, 10
service providers, evaluating, 203
shards, 198–199
share phase in data lifecycle, 75–76
shared cloud platform risks and
responsibilities, 95–97, 96
shared monitoring and testing, 142–143
shared policy, 142
shuffling, 82
side channel attacks in virtualization, 107
SIEM (Security Information and Event
Management), 84
Simian Army, 193–194
simplicity in cloud computing, 9
single points of failure (SPOFs), 28–29
single sign-on (SSO), 161
skillset threats in IaaS, 105
SLAs (service-level agreements), 17–18, 242,
281–284
SOC reports for audits, 140, 262–263
software as a service (SaaS)
application security, 154
overview, 10–11, 10
responsibilities, 96, 96
risks, 106
security considerations, 32–33
shared responsibilities, 133–134
Software Development Lifecycle (SDLC),
156–158, 156