Posts

Showing posts with the label Cloud Security

Security Groups vs NACLs Explained: Cloud Firewalls for Cloud+

Security groups are the instance-level firewall in cloud platforms. They are compared constantly with network access control lists, and the comparison is one of the most reliably examined points in cloud networking. The core distinction: stateful versus stateless Security groups are stateful. If you allow inbound traffic on port 443, the response is automatically permitted outbound. The platform tracks the connection and allows return traffic without a matching rule. Network ACLs are stateless. Every packet is evaluated independently. Allowing inbound 443 does not permit the response — you must also allow the outbound traffic, and because responses come from ephemeral ports you generally have to allow a wide ephemeral range outbound. That single difference explains most misconfigurations. A NACL that permits inbound HTTPS but nothing outbound produces a connection that establishes and then appears to hang, and the ephemeral port range is the thing people forget. The full compari...

CASB Explained: Cloud Access Security Brokers for the Security+ Exam

A cloud access security broker sits between users and cloud services, giving an organisation visibility and control over data in services it does not own or operate. The problem it solves is specific. When applications ran in your data centre, your firewall, DLP and monitoring saw everything. When they moved to SaaS, that visibility disappeared — traffic goes straight from the user to the provider, and the provider's logs are all you get. The four pillars CompTIA and the industry describe CASB capability in four categories, and they are worth learning as a set. Visibility. Which cloud services are in use, by whom, with what data. This is where shadow IT discovery lives — most organisations discover they are using several times more cloud services than they believed. Compliance. Identifying regulated data in cloud services and enforcing the rules that apply to it, including residency constraints. Data security. DLP applied to cloud data, encryption, tokenisation and control...