From the course: Cloud Data, Platform, and Applications Security by Pearson

Unlock this course with a free trial

Join today to access over 25,200 courses taught by industry experts.

Cloud infrastructure risk assessment

Cloud infrastructure risk assessment

Well, if you're already a CISSP, there is very little in this lesson that'll be a surprise to you. It's basically traditional risk management, risk assessment, but applied to a cloud data center. So, of course, we have to define risk, and it's not the same for every organization, but here's some standard terms. Once you have an inherent or total risk, that's the posture, that's your status, that's your state. That is your existing baseline, okay? Your existing risk and vulnerability posture. It's basically where are you now without implementing any additional safeguards or controls. Now residual risk is what you have left over after you introduce controls, administrative, technical, physical. So these are the countermeasures that you've added, and so whatever's left over after the gap analysis is your residual risk. Now realize there's no one-size-fits-all. It could be applied to an asset, an asset class, a building, a campus, a floor of a building, however you want to apply this, but…

Contents