Chapter 3. Cloud Architecture and Design Principles
Topics covered in this chapter include:
-
Security concepts (such as cryptography, threat versus risk, identity and access management)
-
Design principles and patterns
-
Business continuity/disaster recovery
Building infrastructure and supporting applications in the cloud, as with on premises, relies on several foundational concepts. No matter where the resource is, protecting it on behalf of the business and its customers is the priority of security professionals. While there are several technical concepts that need to be factored in, many solutions are designed and architected to be business focused. Security is not only about protecting confidentiality, after all. Availability is a significant consideration, and while higher availability is easier using a cloud provider with all the resources and geographic zones it offers, you will ultimately need to keep in mind that the burden of protecting your data belongs to you, not the cloud provider.
Before designing any solution, it’s important to understand the threats that could impact what you are doing. This way, you can ensure you have appropriate controls in place to protect against the manifestation of those threats. As with so much else with cloud computing, high-level threats are going to be very similar to threats to on-premises organizations.
Tip
This does not mean that on premise is the same as cloud. Although the concepts will be the same, the specific controls you ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access