IR in the cloud: developing a plan of action
As discussed earlier, when we talk about cloud computing, we are talking about a shared responsibility between the cloud provider and the company that is contracting the service. The level of responsibility will vary according to the service model:
- For SaaS, most of the responsibility is on the cloud provider; in fact, the customer's main responsibility is essentially to keep their on-premises infrastructure protected (including the endpoint that is accessing the cloud resource).
- For PaaS, the customer is responsible for securing applications, data, and user access. The PaaS provider secures the operating system and the physical infrastructure.
- For IaaS, most of the responsibility lies on the customer's side, including vulnerability and patch management.
Understanding the division of responsibility is important in order to understand the data gathering boundaries for IR purposes. In an IaaS environment...