Security Basics mailing list archives

Re: Private Cloud


From: barat () poczta fm
Date: Wed, 21 Dec 2011 11:49:08 +0100

Hi,

I was working for a private cloud solution issued by one of the biggest IT market players.

There are lots of the books which describe the cloud computing from the security point of view:

Cloud Security: A Comprehensive Guide to Secure Cloud Computing
Securing the Cloud: Cloud Computer Security Techniques and Tactics
Cloud Computing: Implementation, Management, and Security

but in my opinion the private cloud security boils down to the security of Your network infrastructure and the security 
of each provisioned system in Your cloud.

It depends what kind of solution do You want to use (vmware/kvm/xen etc) - some of the providers let You to use their 
security solutions (ex. vlans for vSphere) - using the vlans lets You to separate each of virtual machine/group of vms 
from the network connection point of view.

You can also protect Your whole infrastructure using IDS which will check the patterns of the network attacks.

You should focus on the security of each virtual machine template/appliance You will prepare. The security of each 
operating systems in the cloud depends from the configuration and the way of deployment, You should to remember about 
applying the latest security patches to each system You want to deploy in Your private infrastructure.

Considering security of Your private cloud You should also focus on High Availability (HA) solution, but everything 
depends from the customer requirements.


Just let me know if You have any questions.


PS:
One of the interesting topic I didn't investigate yet is the shared storage used among the private/public cloud. I'm 
wondering if its possible the user A may recovery the data of the virtual machine/operating system which was 
removed/deleted by user B.

Regards
Lukasz Baratowicz  

"Thugzclub Thugzclub" <thugzclub () googlemail com> pisze:
I am working on a project where we a creating private cloud for a
customer. The client has a reasonable set of requirement and I am
fairly happy with it from a security perspective.

However, I wonder if there are any specific cloud standards
/guidelines that we should adhere to. We have the basic like
AV,Firewalls/VPN but I am keen to demonstrate to the client that we
are following industry standards best practise.

Cheer

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, 
how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, 
purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for 
set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital 
certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------





------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: