惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Troy Hunt's Blog
GbyAI
GbyAI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
月光博客
月光博客
Engineering at Meta
Engineering at Meta
The Register - Security
The Register - Security
阮一峰的网络日志
阮一峰的网络日志
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
F
Fortinet All Blogs
博客园 - 司徒正美
博客园 - 聂微东
T
Tailwind CSS Blog
MyScale Blog
MyScale Blog
Microsoft Security Blog
Microsoft Security Blog
Jina AI
Jina AI
A
About on SuperTechFans
Y
Y Combinator Blog
N
Netflix TechBlog - Medium
V
V2EX
I
InfoQ
WordPress大学
WordPress大学
小众软件
小众软件
The Cloudflare Blog
Recent Announcements
Recent Announcements
U
Unit 42
The Last Watchdog
The Last Watchdog
P
Palo Alto Networks Blog
Vercel News
Vercel News
罗磊的独立博客
H
Hackread – Cybersecurity News, Data Breaches, AI and More
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
M
MIT News - Artificial intelligence
Project Zero
Project Zero
美团技术团队
L
LangChain Blog
S
Security @ Cisco Blogs
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Last Week in AI
Last Week in AI
W
WeLiveSecurity
S
Securelist
H
Hacker News: Front Page
K
Kaspersky official blog
Martin Fowler
Martin Fowler
Know Your Adversary
Know Your Adversary
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
J
Java Code Geeks
P
Proofpoint News Feed
有赞技术团队
有赞技术团队
Google Online Security Blog
Google Online Security Blog
D
DataBreaches.Net

博客园 - asheng

JavaScript UI选型及Jquery EasyUI使用经验谈 五年之痒 敏捷软件开发 嫁给程序员吧!!! Cute Editor for .NET v6.4 Java与.NET的WebServices相互调用 用户体验5大要素 【转】LINQ To XML 入门(3) 【转】LINQ To XML 入门(2) 【转】LINQ To XML 入门(1) 学写Windows Service 微软发布ASP.NET MVC框架1.0正式版 Web定时任务 CSS分类编写方法 JS中错误处理(2) JS中错误处理(1) Log4Net OWC画图表 - asheng - 博客园 好员工为什么会变坏
云计算风险识别
asheng · 2010-12-06 · via 博客园 - asheng

云计算风险识别

Policy and organizational risks(政策和组织风险)

1)Lock-in (锁定,服务锁定 无替代者)

2)Loss of governance (失去治理)

3)Compliance challenges(合规挑战)

4)Loss of business reputation due to co-tenant activities(由于共享活动而导致的商业信誉损失)

5)Cloud service termination or failure(云服务终止或失败)

6)Cloud provider acquisition (云服务提供者的获得)

7)Supply chain failure(供应链断裂)

二 Technical risks (技术风险)

1)Resource exhaustion (under or over provisioning) (资源枯竭)

2)Isolation failure (孤立)

3)Cloud provider malicious insider - abuse of high privilege roles(云供应商的内部恶意攻击者——滥用特权) 

4)Management interface compromise (manipulation, availability of infrastructure)(管理界面的危害——基础设施可获得性,操纵)

5)Intercepting data in transit(传输中的数据截取)

6)Data leakage on up/download, intra-cloud(数据泄漏)

7)Insecure or ineffective deletion of data (不安全的或无效的数据删除)

8)Distributed denial of service (DDoS 分布式拒绝服务攻击)

9)Economic denial of service (EDOS经济拒绝服务)

10)Loss of encryption keys(密钥丢失)

11)Undertaking malicious probes or scans(进行恶意探测或扫描)

12)Compromise service engine (危害服务引擎)

13)Conflicts between customer hardening procedures and cloud environment(客户强化程序与云环境之间的冲突)

三 Legal risks(法律风险)

1)Subpoena and e-discovery

2)Risk from changes of jurisdiction(管辖变更风险)

3)Data protection risks (数据保护风险)

4)Licensing risks(许可风险)

Risks not specific to the cloud(非云服务特定风险)

1)Network breaks(网络中断)

2)Network management (ie, network congestion / mis-connection / non-optimal use) (网络管理)

3)Modifying network traffic(网络流量变化)

4)Privilege escalation(权限扩大)

5)Social engineering attacks (ie, impersonation)(社会工程攻击

6)Loss or compromise of operational logs(丢失或泄漏操作日志)

7)Loss or compromise of security logs (manipulation of forensic investigation)(修饰或泄漏安全日志)

8)Backups lost, stolen(备份丢失、被盗)

9)Unauthorized access to premises (including physical access to machines and other facilities)(未授权访问)

10)Theft of computer equipment (计算机设备失窃)

11)Natural disasters(自然灾害)

//****************************************
  by: Amen cnblogs博客  转载请注明出处
//****************************************