波音游戏-波音娱乐城赌球打不开

V. Hardening Steps to Secure Cloud Computing Environment - Platform as a Service

by JUCC ISTF

/* The following article is extracted from the "Information Security Newsletter" published by the JUCC IS Task Force. */

PaaS is intended to enable developers to build their own applications on top of the platform supported by cloud service providers. As a result, it tends to be more extensible than SaaS, at the expense of customer-ready features. In the case of PaaS, it is the responsibility of the universities' system administrators to effectively manage the same level of security measures provided by the cloud providers for protecting the underlying infrastructure components to ensure basic service availability and integrity levels.

1. Logical Access

Unauthorised access to universities' data in the cloud platform should be restricted. One of the best approaches to data access control is using the least privilege rule - i.e. access to particular data shall only be granted to authorised personnel on a need-to-know basis.

Individual users shall be authenticated on their own behalf. The universities are recommended to deploy user-centric authentication method that adopts a single set of credentials at multiple sites.

 

2. Application Development

PaaS provides a framework of building blocks to construct customised applications based on customers' own needs. Same as IaaS, application development within PaaS environment also require consideration on security throughout the SDLC.

However, since less operational controls can be obtained by PaaS customers, application design and implementation may require additional steps to achieve the same level of security as IaaS counterparts. For example, extra data encryption mechanism shall be implemented with the application logic if secure protocols (e.g. SSL, HTTPS, etc.) cannot be utilised on PaaS platform.

 

3. Portability and Interoperability

When shifting from IaaS to PaaS, vendor lock-in (dependency) turns out to be a critical security issue if a university may have to change its cloud service provider in the future, portability and interoperability must be considered. With PaaS, the expectation is that certain degree of application modification will be necessary to achieve portability. The focus is minimising the amount of program re-writing while maintaining or enhancing security controls, along with achieving a successful data migration.

When possible, the university shall develop the cloud platform components with a standard syntax and open APIs. The university should also understand:

  • What tools are available for secure data transfer, backup, and restore?
  • How base services like monitoring, logging, and auditing would transfer over to a new cloud provider?
  • What security control functions are provided by legacy cloud provider and how they would translate by the new provider?
  • What is the impact on performance and availability of the application when migrating to a new PaaS platform?

 

References:

 


[Previous section] [Next section]

百家乐官网长胜攻略| 百家乐官网破解秘籍| 维也纳国际娱乐城| 百家乐的规则博彩正网| 百家乐官网de概率| 圣淘沙百家乐现金网| 岳西县| 游戏机百家乐的技巧| qq百家乐官网网络平台| 大发888网页在线游戏| 百家乐官网桌布呢布| 立博百家乐官网游戏| 贵族百家乐的玩法技巧和规则| 金百家乐官网网站| 凯时娱乐城官网| 正品百家乐地址| 自贡百家乐官网娱乐场开户注册 | 大发888官网注册送58| 百家乐体育宝贝| 百家乐官网单机游戏免费| 威尼斯人娱乐会所| 百家乐视频对对碰| 百家乐官网路珠多少钱| 丹江口市| 大发888更名网址6| 正品百家乐电话| 伯爵百家乐官网娱乐| 百家乐官网路单网下载| 星际百家乐娱乐城| 百家乐有哪几种| 百家乐官网博彩资讯论坛| 大发888是什么东| 找查百家乐玩法技巧| 稳赢的百家乐投注方法| 新乐园百家乐官网娱乐城| 巴登娱乐城| 大发888注册送28| 威尼斯人娱乐平台博彩投注平| ea百家乐打水| 百家乐下路教学| 百家乐singapore|