Trust and Security in a Cloud Environment
摘要
The threeCloud Computing general securitySecurity concepts are Confidentiality, Integrity, and Availability. This chapter focuses on the surveillance and predictive aspects of information securityInformation Security. The chapter provides definitions of trust and trustworthy. The difference between trust calculations and actually being trustworthy is described. NIST's comprehensive threat modeling exercises using popular methods are introduced. Several tools are available for securitySecurity assessment and tracking. Two tools are discussed in some detail: 1) the Common Vulnerability Scoring System (CVSS) for evaluating vulnerabilities and 2) Common Vulnerabilities and Exposures (CVE) is a searchable database of publicly disclosed information securitySecurity issues. Guidance is provided on how to identify cloud threat modeling security objectives, set the scope of assessments, identify threats, identify design vulnerabilities, develop mitigations and controls, and communicate a call-to-action. The two main types of approaches are those that focus on the securitySecurity of cloud infrastructure and those that focus on the security of cloud applications.