← → navigate · ESC index · Back to quit
SCIA 120 · Week 13
cover · 01/30
Introduction to Secure Computing and Information Assurance

Cloud Computing Security

Author: Dr. Zhijiang Chen (Frostburg State University)

Tech darkAI line artReading-based content
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where cloud computing security affects users, data, or operations.
InstructorHow would you recognize cloud computing security in a real organization?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Cloud computing has fundamentally transformed how organizations…
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 01PROTECT - DETECT - RESPONDCloud Computing...Cloud computing...ControlEvidence
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
agenda · 02/30
Overall Page

Overall roadmap

The week moves from core definitions to practical security decisions.

Introduction

Core reading concept for Week 13.

Cloud Service Models

Core reading concept for Week 13.

Infrastructure as a Service (IaaS)

Core reading concept for Week 13.

Platform as a Service (PaaS)

Core reading concept for Week 13.

Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where overall roadmap affects users, data, or operations.
InstructorHow would you recognize overall roadmap in a real organization?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Introduction
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 02PROTECT - DETECT - RESPONDOverall roadmapIntroductionCloud Service...Infrastructure...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
objectives · 03/30
03 objectives

Learning objectives

Students should explain, apply, and evaluate the week’s main security ideas.

Explain Introduction.
Explain Cloud Service Models.
Explain Infrastructure as a Service (IaaS).
Explain Platform as a Service (PaaS).
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where learning objectives affects users, data, or operations.
InstructorHow would you recognize learning objectives in a real organization?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Explain Introduction.
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 03POLICY - TOOL - TEST - EVIDENCELearning...Explain...Explain Cloud...Evidence
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
application · 04/30
04 application

Opening scenario

Use a realistic scenario to anchor Cloud Computing Security in operational decision-making.

Cloud computing has fundamentally transformed how organizations build, deploy, and manage information systems.
What once required months of procurement, physical hardware installation, and data center operations now takes minutes — and can be provisioned, scaled, or decommissioned through…
Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP) collectively host the workloads of the world's most critical organizations: governments, hospitals,…
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where opening scenario affects users, data, or operations.
InstructorIf this issue appeared in a campus or business system, what evidence would you collect first?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Cloud computing has fundamentally transformed how organizations…
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 04POLICY - TOOL - TEST - EVIDENCEOpening scenarioCloud computing...What once...Amazon Web...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
definition · 05/30
05 definition

Introduction

Cloud computing has fundamentally transformed how organizations build, deploy, and manage information systems.

Cloud computing has fundamentally transformed how organizations build, deploy, and manage information systems.
What once required months of procurement, physical hardware installation, and data center operations now takes minutes — and can be provisioned, scaled, or decommissioned through…
Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP) collectively host the workloads of the world's most critical organizations: governments, hospitals,…
This shift in infrastructure brings enormous operational benefits but also introduces new and subtle security risks.
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where introduction affects users, data, or operations.
InstructorWhat problem does introduction help us understand?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Cloud computing has fundamentally transformed how organizations…
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 05POLICY - TOOL - TEST - EVIDENCEIntroductionCloud computing...What once...Amazon Web...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
concept · 06/30
06 concept

Cloud Service Models

Cloud services are typically classified into three models, which differ in what the cloud provider manages versus what the customer is responsible for:

Cloud services are typically classified into three models, which differ in what the cloud provider manages versus what the customer is responsible for:
Cloud Service Models connects to risk, controls, and evidence.
Cloud Service Models connects to risk, controls, and evidence.
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where cloud service models affects users, data, or operations.
InstructorHow would you recognize cloud service models in a real organization?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Cloud services are typically classified into three models, which…
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 06RISK = ASSET x THREAT x IMPACTCloud Service...Cloud services...ControlEvidence
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
application · 07/30
07 application

Infrastructure as a Service (IaaS)

IaaS provides virtualized computing infrastructure: virtual machines, block storage volumes, virtual networks, and load balancers.

IaaS provides virtualized computing infrastructure: virtual machines, block storage volumes, virtual networks, and load balancers.
The customer provisions and manages operating systems, middleware, applications, and data.
The provider manages the physical hardware, hypervisor, and data center infrastructure.
Examples: AWS EC2, Azure Virtual Machines, Google Compute Engine, AWS S3 (object storage), Azure Blob Storage.
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where infrastructure as a service (iaas) affects users, data, or operations.
InstructorIf this issue appeared in a campus or business system, what evidence would you collect first?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: IaaS provides virtualized computing infrastructure: virtual machines,…
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 07POLICY - TOOL - TEST - EVIDENCEInfrastructure...IaaS provides...The customer...The provider...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
evidence · 08/30
08 evidence

Platform as a Service (PaaS)

PaaS provides a managed platform for deploying applications, abstracting away OS management, runtime maintenance, and infrastructure scaling.

PaaS provides a managed platform for deploying applications, abstracting away OS management, runtime maintenance, and infrastructure scaling.
The customer deploys their application code and data; the provider manages everything below: the OS, runtime, middleware, and infrastructure.
Examples: AWS Elastic Beanstalk, Azure App Service, Google App Engine, AWS RDS (managed database), Heroku.
PaaS shifts significant security responsibility to the provider — the customer no longer patches the OS or manages the runtime.
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where platform as a service (paas) affects users, data, or operations.
InstructorHow would you recognize platform as a service (paas) in a real organization?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: PaaS provides a managed platform for deploying applications,…
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 08POLICY - TOOL - TEST - EVIDENCEPlatform as a...PaaS provides a...The customer...Examples AWS...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
definition · 09/30
09 definition

Software as a Service (SaaS)

SaaS delivers complete applications over the internet.

SaaS delivers complete applications over the internet.
The customer simply uses the application; the provider manages everything: infrastructure, platform, application, and runtime.
Examples: Microsoft 365, Google Workspace, Salesforce, Workday, Slack, Zoom.
In SaaS, the provider manages nearly all security.
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where software as a service (saas) affects users, data, or operations.
InstructorWhat problem does software as a service (saas) help us understand?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: SaaS delivers complete applications over the internet.
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 09POLICY - TOOL - TEST - EVIDENCESoftware as a...SaaS delivers...The customer...Examples...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
concept · 10/30
10 concept

The Shared Responsibility Model

The shared responsibility model is the most important concept in cloud security.

The shared responsibility model is the most important concept in cloud security.
It defines the boundary between what the cloud provider secures and what the customer must secure.
This boundary shifts depending on the service model.
Key Concept — Shared Responsibility : The cloud provider is responsible for the security of the cloud (physical infrastructure, hardware, hypervisors, managed service platforms).
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where the shared responsibility model affects users, data, or operations.
InstructorHow would you recognize the shared responsibility model in a real organization?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: The shared responsibility model is the most important concept in…
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 10POLICY - TOOL - TEST - EVIDENCEThe Shared...The shared...It defines the...This boundary...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
application · 11/30
11 application

Cloud Deployment Models

Organizations deploy cloud resources in several ways: Public Cloud : Resources are provisioned on infrastructure shared with other cloud tenants (logical isolation, not physical).

Organizations deploy cloud resources in several ways: Public Cloud : Resources are provisioned on infrastructure shared with other cloud tenants (logical isolation, not physical).
This is the model offered by AWS, Azure, and GCP.
Cost-efficient and highly scalable, but subject to the shared responsibility model.
Private Cloud : Cloud infrastructure dedicated exclusively to one organization, either hosted on-premises (using platforms like OpenStack or VMware vSphere) or dedicated-tenancy…
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where cloud deployment models affects users, data, or operations.
InstructorIf this issue appeared in a campus or business system, what evidence would you collect first?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Organizations deploy cloud resources in several ways: Public Cloud :…
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 11POLICY - TOOL - TEST - EVIDENCECloud...Organizations...This is the...Cost-efficient...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
evidence · 12/30
12 evidence

Misconfiguration

Misconfiguration is the leading cause of cloud data breaches.

Misconfiguration is the leading cause of cloud data breaches.
The most notorious example is publicly accessible Amazon S3 buckets.
By default, S3 buckets are private, but a single misconfigured access control policy or a "Block Public Access" setting being disabled can expose all bucket contents to the entire…
Between 2017 and 2020, hundreds of organizations inadvertently exposed billions of records through misconfigured S3 buckets, including government agencies, major corporations, and…
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where misconfiguration affects users, data, or operations.
InstructorHow would you recognize misconfiguration in a real organization?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Misconfiguration is the leading cause of cloud data breaches.
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 12POLICY - TOOL - TEST - EVIDENCEMisconfigurationMisconfiguration...The most...By default S3...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
definition · 13/30
13 definition

Insecure APIs

Cloud management APIs (AWS API, Azure ARM, GCP API) are powerful attack surfaces.

Cloud management APIs (AWS API, Azure ARM, GCP API) are powerful attack surfaces.
Every action that can be performed in a cloud console can also be performed via API, with no security control beyond valid credentials.
API keys and access tokens that are leaked — in source code, in log files, in GitHub repositories — grant full access to cloud resources.
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where insecure apis affects users, data, or operations.
InstructorWhat problem does insecure apis help us understand?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Cloud management APIs (AWS API, Azure ARM, GCP API) are powerful…
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 13POLICY - TOOL - TEST - EVIDENCEInsecure APIsCloud...Every action...API keys and...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
concept · 14/30
14 concept

Account Hijacking

Cloud accounts represent the highest-value credential in modern attack campaigns.

Cloud accounts represent the highest-value credential in modern attack campaigns.
Compromising cloud credentials (IAM user access keys, federated identity credentials, or management console passwords) can grant access to all resources in an account.
Phishing campaigns specifically targeting DevOps engineers and cloud administrators are common.
MFA is essential for all cloud console access.
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where account hijacking affects users, data, or operations.
InstructorHow would you recognize account hijacking in a real organization?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Cloud accounts represent the highest-value credential in modern…
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 14POLICY - TOOL - TEST - EVIDENCEAccount...Cloud accounts...Compromising...Phishing...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
application · 15/30
15 application

Data Breaches and Insider Threats

Sensitive data stored in cloud environments — customer PII, intellectual property, regulated data — can be exfiltrated by external attackers who compromise access credentials or…

Sensitive data stored in cloud environments — customer PII, intellectual property, regulated data — can be exfiltrated by external attackers who compromise access credentials or…
Encryption, data loss prevention (DLP) controls, and detailed access logging are essential countermeasures.
Data Breaches and Insider Threats connects to risk, controls, and evidence.
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where data breaches and insider threats affects users, data, or operations.
InstructorIf this issue appeared in a campus or business system, what evidence would you collect first?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Sensitive data stored in cloud environments — customer PII,…
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 15POLICY - TOOL - TEST - EVIDENCEData Breaches...Sensitive data...Encryption data...Evidence
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
evidence · 16/30
16 evidence

Shadow IT

Shadow IT refers to cloud resources provisioned by employees or teams without the knowledge or approval of IT and security teams.

Shadow IT refers to cloud resources provisioned by employees or teams without the knowledge or approval of IT and security teams.
When individual developers spin up EC2 instances, S3 buckets, or SaaS subscriptions outside formal procurement processes, those resources may bypass security controls, not be…
Cloud Access Security Brokers (CASBs) and cloud security posture management (CSPM) tools help detect and govern shadow IT.
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where shadow it affects users, data, or operations.
InstructorHow would you recognize shadow it in a real organization?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Shadow IT refers to cloud resources provisioned by employees or teams…
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 16POLICY - TOOL - TEST - EVIDENCEShadow ITShadow IT...When individual...Cloud Access...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
definition · 17/30
17 definition

AWS IAM

AWS Identity and Access Management (IAM) is the access control system for all AWS services.

AWS Identity and Access Management (IAM) is the access control system for all AWS services.
Key components: - Users : Long-term identities for humans or applications.
Best practice: minimize IAM users; use roles instead.
- Groups : Collections of users sharing the same policies.
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where aws iam affects users, data, or operations.
InstructorWhat problem does aws iam help us understand?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: AWS Identity and Access Management (IAM) is the access control system…
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 17POLICY - TOOL - TEST - EVIDENCEAWS IAMAWS Identity...Key components...Best practice...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
concept · 18/30
18 concept

Azure Active Directory

Azure Active Directory (Azure AD, now called Microsoft Entra ID) serves as the identity foundation for Azure, Microsoft 365, and integrated third-party SaaS applications.

Azure Active Directory (Azure AD, now called Microsoft Entra ID) serves as the identity foundation for Azure, Microsoft 365, and integrated third-party SaaS applications.
Azure Active Directory connects to risk, controls, and evidence.
Azure Active Directory connects to risk, controls, and evidence.
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where azure active directory affects users, data, or operations.
InstructorHow would you recognize azure active directory in a real organization?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Azure Active Directory (Azure AD, now called Microsoft Entra ID)…
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 18RISK = ASSET x THREAT x IMPACTAzure Active...RiskControlEvidence
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
application · 19/30
19 application

Encryption in the Cloud

Encryption at Rest : Data stored in cloud services (S3, RDS, EBS volumes, Azure Blob Storage) should be encrypted at rest.

Encryption at Rest : Data stored in cloud services (S3, RDS, EBS volumes, Azure Blob Storage) should be encrypted at rest.
AWS, Azure, and GCP all offer default encryption with provider-managed keys, but organizations requiring greater control use customer-managed keys (CMKs) via Key Management…
Encryption in Transit : All data transmitted between clients and cloud services, and between cloud services internally, should use TLS 1.2 or 1.3.
Most cloud services enforce this by default, but it must be explicitly required for legacy protocols and internal service communication.
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where encryption in the cloud affects users, data, or operations.
InstructorIf this issue appeared in a campus or business system, what evidence would you collect first?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Encryption at Rest : Data stored in cloud services (S3, RDS, EBS…
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 19POLICY - TOOL - TEST - EVIDENCEEncryption in...Encryption at...AWS Azure and...Most cloud...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
evidence · 20/30
20 evidence

Virtual Private Cloud (VPC)

A Virtual Private Cloud (VPC) is an isolated virtual network within a cloud provider's infrastructure.

A Virtual Private Cloud (VPC) is an isolated virtual network within a cloud provider's infrastructure.
Organizations deploy their cloud resources within VPCs, controlling IP address ranges (CIDR blocks), subnets, route tables, and network gateways.
Proper VPC design involves: - Public subnets : For resources that need direct internet access (load balancers, NAT gateways, bastion hosts).
- Private subnets : For resources that should not be directly accessible from the internet (application servers, databases, internal services).
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where virtual private cloud (vpc) affects users, data, or operations.
InstructorHow would you recognize virtual private cloud (vpc) in a real organization?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: A Virtual Private Cloud (VPC) is an isolated virtual network within a…
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 20POLICY - TOOL - TEST - EVIDENCEVirtual Private...A Virtual...Organizations...Proper VPC...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
definition · 21/30
21 definition

Security Groups and NACLs

Security Groups are stateful virtual firewalls attached to individual resources (EC2 instances, RDS databases, Lambda functions).

Security Groups are stateful virtual firewalls attached to individual resources (EC2 instances, RDS databases, Lambda functions).
They filter traffic based on protocol, port, and source/destination IP or security group.
Because security groups are stateful, return traffic is automatically allowed for permitted inbound connections.
Network Access Control Lists (NACLs) are stateless firewall rules applied at the subnet level.
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where security groups and nacls affects users, data, or operations.
InstructorWhat problem does security groups and nacls help us understand?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Security Groups are stateful virtual firewalls attached to individual…
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 21POLICY - TOOL - TEST - EVIDENCESecurity Groups...They filter...Because...Network Access...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
concept · 22/30
22 concept

AWS CloudTrail and CloudWatch

AWS CloudTrail records all API calls made in an AWS account — who made the call, from where, at what time, and what was the result.

AWS CloudTrail records all API calls made in an AWS account — who made the call, from where, at what time, and what was the result.
CloudTrail is the essential audit log for AWS and must be enabled in all regions, with logs protected from tampering (S3 bucket with Object Lock or delivered to a separate…
CloudTrail enables detection of: unauthorized access attempts, privilege escalation, IAM changes, data exfiltration via unusual data transfer, and cryptomining via unauthorized…
Amazon CloudWatch monitors resource metrics and application logs, and can trigger alarms and automated responses.
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where aws cloudtrail and cloudwatch affects users, data, or operations.
InstructorHow would you recognize aws cloudtrail and cloudwatch in a real organization?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: AWS CloudTrail records all API calls made in an AWS account — who…
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 22VERIFY - MONITOR - IMPROVEAWS CloudTrail...CloudTrail is...CloudTrail...Amazon...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
application · 23/30
23 application

Azure Monitor and Microsoft Defender for Cloud

Azure Monitor collects metrics and logs from Azure resources and applications.

Azure Monitor collects metrics and logs from Azure resources and applications.
Microsoft Defender for Cloud (formerly Azure Security Center) provides continuous security assessment, threat detection, and recommendations for Azure resources.
Azure Sentinel (Microsoft Sentinel) is a SIEM and SOAR platform natively integrated with Azure and Microsoft 365.
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where azure monitor and microsoft defender for cloud affects users, data, or operations.
InstructorIf this issue appeared in a campus or business system, what evidence would you collect first?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Azure Monitor collects metrics and logs from Azure resources and…
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 23POLICY - TOOL - TEST - EVIDENCEAzure Monitor...Microsoft...Azure Sentinel...Evidence
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
evidence · 24/30
24 evidence

Cloud Compliance

Cloud providers publish SOC 2 Type II reports; customers must also achieve their own SOC 2 compliance for their cloud-hosted services.

Cloud providers publish SOC 2 Type II reports; customers must also achieve their own SOC 2 compliance for their cloud-hosted services.
- FedRAMP (Federal Risk and Authorization Management Program) : A U.S.
government program standardizing security assessment and authorization for cloud services used by federal agencies.
AWS GovCloud, Azure Government, and GCP Government Cloud offer FedRAMP-authorized environments.
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where cloud compliance affects users, data, or operations.
InstructorHow would you recognize cloud compliance in a real organization?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Cloud providers publish SOC 2 Type II reports; customers must also…
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 24RISK = ASSET x THREAT x IMPACTCloud ComplianceCloud providers...- FedRAMP...government...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
vocabulary · 25/30
25 vocabulary

Key terms to keep

Vocabulary becomes useful when students can connect terms to scenarios and evidence.

Introduction
Cloud Service Models
Infrastructure as a Service (IaaS)
Platform as a Service (PaaS)
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where key terms to keep affects users, data, or operations.
InstructorHow would you recognize key terms to keep in a real organization?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Introduction
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 25POLICY - TOOL - TEST - EVIDENCEKey terms to...IntroductionCloud Service...Infrastructure...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
comparison · 26/30
26 comparison

Compare: Introduction vs. Cloud Service Models

Comparing related ideas helps students avoid shallow memorization.

Where Introduction applies.
Where Cloud Service Models applies.
How the difference changes the security decision.
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where compare: introduction vs. cloud service models affects users, data, or operations.
InstructorHow would you recognize compare: introduction vs. cloud service models in a real organization?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Where Introduction applies.
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 26POLICY - TOOL - TEST - EVIDENCECompare:...Where...Where Cloud...How the...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
application · 27/30
27 application

Applied decision checkpoint

Students should translate concepts into a defensible security decision.

Identify the asset or process at risk.
Choose a preventive, detective, or corrective control.
Explain what evidence would prove the control is working.
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where applied decision checkpoint affects users, data, or operations.
InstructorIf this issue appeared in a campus or business system, what evidence would you collect first?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Identify the asset or process at risk.
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 27RISK = ASSET x THREAT x IMPACTApplied...Identify the...Choose a...Explain what...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
review · 28/30
28 review

Review questions

Retrieval practice should ask students to define, compare, apply, and evaluate.

Define one core concept in plain language.
Compare two controls or threats from the week.
Apply one idea to a campus or business system.
Evaluate why a solution might fail in practice.
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where review questions affects users, data, or operations.
InstructorWhat is the one sentence takeaway for review questions?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Define one core concept in plain language.
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 28POLICY - TOOL - TEST - EVIDENCEReview questionsDefine one core...Compare two...Apply one idea...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
bridge · 29/30
29 bridge

Bridge to lab and assessment

The reading should transfer into evidence-based lab work and written explanations.

Collect evidence, not just screenshots.
Explain what the artifact proves.
Connect the proof back to risk and control selection.
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where bridge to lab and assessment affects users, data, or operations.
InstructorHow would you recognize bridge to lab and assessment in a real organization?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Collect evidence, not just screenshots.
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 29VERIFY - MONITOR - IMPROVEBridge to lab...Collect...Explain what...Connect the...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck
SCIA 120 · Week 13
closing · 30/30
30 closing

Takeaway

The central takeaway from Week 13 is to reason from risk to evidence to action.

Cloud Computing Security
Security is a decision process, not just a tool list.
Use the reading to justify practical choices.
Classroom Dialog
ScenarioA campus technology team is reviewing a realistic Week 13 incident where takeaway affects users, data, or operations.
InstructorHow would you recognize takeaway in a real organization?
StudentThis concept helps us decide what is at risk, what evidence to check, and which control would reduce harm. For this slide, the key clue is: Cloud Computing Security
Teaching point: Push the answer beyond a definition: name the asset, identify the risk, choose evidence, and justify a practical control.
GAMMA-STYLE VISUAL - SLIDE 30POLICY - TOOL - TEST - EVIDENCETakeawayCloud Computing...Security is a...Use the reading...
Dr. Zhijiang Chen · Frostburg State University
Week 13 deck