What are the three major categories of data security controls?
What are the cloud data storage types?
What tools are available to control what data goes into cloud?
DLP tools are challenged by encrypted connections.
How do you use access controls to secure data in the cloud?
Fine grained access controls (entitlement matrix)
Frequently validate that controls meet your requirements
What are various ways of protecting data at rest?
What are IaaS Encryption Options?
What are PaaS Encryption Options?
What are SaaS encryption options?
What are key management options available to customers?
What is an example of leveraging data architectures to improve security?
Run application components in different virtual networks (e.g. VPCs)
Bridge them by using the provider’s network -e.g. message queue (e.g. SQS)
For an attacker to succeed, they’d have to breach both the customer and the providers virtual networks.