With rapidly changing architecture and API-driven automation, cloud platforms come with unique security challenges and opportunities. In this updated second edition, you'll examine security best practices for multivendor cloud environments, whether your company plans to move legacy on-premises projects to the cloud or build a new infrastructure from the ground up.
Developers, IT architects, and security professionals will learn cloud-specific techniques for securing popular cloud platforms such as Amazon Web Services, Microsoft Azure, and IBM Cloud. IBM Distinguished Engineer Chris Dotson shows you how to establish data asset management, identity and access management (IAM), vulnerability management, network security, and incident response in your cloud environment.
• Learn the latest threats and challenges in the cloud security space
• Manage cloud providers that store or process data or deliver administrative control
• Learn how standard principles and concepts--such as least privilege and defense in depth--apply in the cloud
• Understand the critical role played by IAM in the cloud
• Use best tactics for detecting, responding, and recovering from the most common security incidents
• Manage various types of vulnerabilities, especially those common in multicloud or hybrid cloud architectures
• Examine privileged access management in cloud environments
This edition also covers privileged access management in cloud environments; an expanded look into applying zero trust principles; additional controls around cloud development and test environments; and up-to-date information on authentication of users and systems.
AI Reading Assistant
Whole-book reading guide from stratified index samples; jump to passages in the text
Tip the Site
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat Pay
Alipay
Open WeChat or Alipay and scan. No login required.
AI guide
# Practical Cloud Security: A Guide for Secure Design and Deployment, 2nd Edition
## 【One-Line Pitch】
A practical, vendor-neutral guide for developers, IT architects, and security professionals who need to design, deploy, and operate secure workloads across AWS, Azure, and IBM Cloud—covering everything from IAM and encryption to incident response and zero trust. If you're moving to the cloud or already there but unsure what's actually *your* responsibility, this book gives you a clear framework to stop guessing and start securing.
## 【Book Arc】
- **Opening (~0%–9%)**: Establishes the book's scope and updates for the 2nd edition—privileged access management, zero trust, cloud dev/test environments, workload identity verification, and software supply chain protection with SBOM. Sets expectations for chapter exercises and solutions.
- **Early (~9%–25%)**: Introduces the foundational mindset—asset-oriented risk thinking, threat actor personas (criminals, hacktivists, insiders, state actors), and the shared responsibility model. Emphasizes that cloud providers secure the *cloud*, not *your* applications and data, and warns against common misunderstandings.
- **Early (~25%–34%)**: Covers risk management essentials—likelihood × impact, aggregated risks, and compliance drivers (GDPR, FedRAMP, ITAR). Transitions into data asset management: tagging, tokenization, and encryption strategies for data at rest, in motion, and in use.
- **Middle (~34%–47%)**: Dives deep into encryption trade-offs—client-side vs. server-side, confidential computing, cryptographic erasure, and the dangers of DIY crypto. Shifts to cloud asset management, highlighting how cloud provisioning breaks traditional IT gatekeeping and creates shadow IT problems.
- **Middle (~47%–end)**: Explores cloud asset types (compute, storage, network), container security challenges (shared kernel attack surface), and moves into detection, response, and recovery—including monitoring protective systems, applications, administrators, and auditing infrastructure.
## 【Key Takeaways】
- **The shared responsibility model is the #1 concept to internalize** (Early): Cloud providers secure the infrastructure; *you* secure your data, applications, and configurations. Misunderstanding this leads to both wasted worry and missed risks.
- **Start with an asset-oriented approach, not a threat-first one** (Early): Identify what you need to protect (especially data) before designing defenses. Create threat actor personas—criminals, hacktivists, insiders, state actors—and keep them visible when making design decisions.
- **Risk = likelihood × impact, but don't stop there** (Early): Watch for aggregated risks where two low-probability events combine into a severe outcome. Compliance requirements (GDPR, FedRAMP, ITAR) should inform—not replace—your security design.
- **Encryption is about trade-offs, not just bits** (Middle): More bits don't automatically mean more security—implementation flaws break encryption more often than brute force. Use well-tested libraries and follow NIST SP 800-131A recommendations; never roll your own crypto.
- **Client-side encryption gives you control but costs functionality** (Middle): When you hold the keys, the server can't search, index, or scan your data. For most organizations, well-tested cloud-managed encryption is the pragmatic choice unless you have very low risk tolerance and budget to match.
- **Cryptographic erasure solves the "can't delete data" problem** (Middle): Instead of overwriting massive files, encrypt data and destroy the key—a 256-bit key wipe can make a multiterabyte file unrecoverable, wherever its copies exist.
- **Cloud breaks traditional asset management—embrace incremental inventory** (Middle): Anyone with a credit card can provision resources, creating shadow IT at scale. Don't wait for a perfect solution; start with your most security-relevant assets (data storage and compute) and expand incrementally.
- **Containers have a fundamentally different attack surface than VMs** (Middle): The shared kernel exposes hundreds of system calls, making container escapes a real risk. This isn't a reason to avoid containers, but it demands different security thinking than hypervisor-based isolation.
## 【Reading Tips】
- **Skim the service delivery model overview** (IaaS/PaaS/SaaS) if you're already cloud-familiar—the author admits the lines are blurring, and the real value is in the shared responsibility discussion that follows.
- **Deep-read Chapter 2 on data asset management**—the encryption trade-offs, tokenization, and cryptographic erasure sections are the most actionable content in the book, with direct implementation guidance.
- **Pay special attention to the risk management section** even if you've done security work before—the aggregated risk discussion and compliance mapping (GDPR, FedRAMP, ITAR) are practical and often overlooked.
- **Use the chapter exercises as a self-check**—the author added them specifically for this edition, and answers are in the appendix. They're designed to test whether you can *apply* concepts, not just recall them.
- **If you're in a multicloud or hybrid environment**, focus on the asset categorization and container security sections—these address the complexity that single-cloud guides often ignore.
## 【Coverage Limits】
This guide covers the book's foundational principles, data asset management, encryption strategies, and asset/container security. The excerpts do not cover the later chapters on network security, IAM implementation details, incident response procedures, or the zero trust and privileged access management content in depth—those sections require reading the full book.
##
e from the world of user experience design, you may want to imagine a member of each applicable group, give them a name, jot down a little about that “person...
available from some cloud providers and are managed only by US personnel. Global PCI DSS If you’re handling credit card information, the Payment Card Industr...
o know about all assets that are relevant to your security. If you are coming into an environment with a large number of existing cloud assets, keep in mind ...
hese systems can alert you when one of your certificates is due to expire, if you’re not using automation (such as tools implementing the ACME protocol) to r...
on to manage the identities of cloud administrators in your organization, along with the access that you have granted those identities to all of the services...
crets are dangerous things that should be handled carefully. Here are some princi‐ ples for managing secrets: • Secrets should be easy to change at regular i...
cate and authorize administrators against an identity store. Note that in a container environment, executing commands may not even be needed for normal maint...
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.
Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat PayAlipay
Open WeChat or Alipay and scan. No login required.
Add Tag
Enter tag name (max 50 characters)
Share E-Book
Practical Cloud Security A Guide for Secure Design and Deployment, 2nd Edition (Chris Dotson)(Z-Library)
Scan QR code with your phone to access
Copy the link or scan the QR code to access this e-book on your phone
Share E-Book via Email
Please enter email address
Donation Statistics
¥.00
Total Donations
0
Donation Count
Practical Cloud Security A Guide for Secure Design and Deployment, 2nd Edition (Chris Dotson)(Z-Library)
Find Your Favorite Books
Only registered users can comment after logging in. Comments need to be reviewed by administrators before being displayed
Loading comments...
Reply to Comment
Edit Comment