Chapter 10: Engaging with Cloud Providers
In previous chapters, we have covered cloud infrastructure fundamentals, common threats in cloud environments, and how to handle compliance and regulation. This chapter will cover fundamental steps prior to working with cloud services, such as engaging with cloud providers.
In the traditional data center, we control everything – from physical to logical security controls. To get assurance when working with cloud providers, there are several options, such as the following:
- Conduct a risk assessment prior to engaging with a cloud provider – one good option is to review SOC2 Type 2 reports (what controls the cloud provider has set and how effective they are).
- Have a good contract that clearly sets the obligations of the cloud provider (such as an Service Level Agreement (SLA) for handling security incidents and an SLA to notify us as customers).
- Conduct a penetration test at least once every 12 months on the system...