Top Banner
http://clean-clouds.com Application Security in Cloud http://clean-clouds.com
18
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Application Security in Cloud

http://clean-clouds.com

Application Security in Cloud

http://clean-clouds.com

Page 2: Application Security in Cloud

http://clean-clouds.com

Application Security in Cloud

Security as a after thought SDLC

Page 3: Application Security in Cloud

http://clean-clouds.com

Reason of Concern:◦ Lack of Control ◦ Cloud related Issues◦ Changes in SDLC ◦ Unknown Risks (Needs to Identify)

Areas to restructure◦ Security◦ Application◦ SDLC

Page 4: Application Security in Cloud

http://clean-clouds.com

Traditional SDLC

Page 5: Application Security in Cloud

http://clean-clouds.com

Cloud Specific SDLC

Page 6: Application Security in Cloud

http://clean-clouds.com

Page 7: Application Security in Cloud

http://clean-clouds.com

SaaS

Concerns Responsibilities Solutions

Page 8: Application Security in Cloud

http://clean-clouds.com

Identity & Access Management

SAML XACML OAuth OpenID OATH OpenAuth

Page 9: Application Security in Cloud

http://clean-clouds.com

PaaS

Concerns Responsibilities Solutions

Page 10: Application Security in Cloud

http://clean-clouds.com

IaaS

Concerns Responsibilities Solutions

Page 11: Application Security in Cloud

http://clean-clouds.com

Different Aspects

Training to DevelopersData ValidationTraditional SecurityApplication Penetration testing Encryption

Page 12: Application Security in Cloud

http://clean-clouds.com

Automation

Application security policy automation Automation of auditing Policy as a Service

◦Benefits ◦Automatic Security Policy Enforcement in the Cloud

◦Automatic Policy Monitoring into the Cloud

◦Automatic Updating

Page 18: Application Security in Cloud

http://clean-clouds.com

Thank You