CCSP Domain 2: Cloud Data Security

Introduction

The Certified Cloud Security Professional certification, or CCSP, is a certification hosted by the joint effort of (ISC)2 and the Cloud Security Alliance (CSA). This exciting credential is designed for cloud-based information security professionals and ensures that the certification holder has acquired the requisite skills, knowledge and abilities in cloud implementation, security design, controls, operations and compliance with applicable regulations.

The CCSP certification exam comprises six domains: Architectural Concepts and Design Requirements, Cloud Data Security, Cloud Platform and Infrastructure Security, Operations, Cloud Application Security and Legal and Compliance. This article will detail the Cloud Data Security domain of the CCSP exam and what candidates preparing for the CCSP certification can expect on the exam.

The Cloud Data Security domain of CCSP currently accounts for 20% of the material covered by the CCSP certification exam.

Below you will find an exploration of the different subsections of this domain and what information you can expect to be covered on the CCSP certification exam.

2.1 Understand Cloud Data Lifecycle (CSA Guidance)

The first subsection of Domain 2 of the CCSP certification exam is all about understanding the cloud data life cycle as introduced in the Securosis Blog and later assimilated into the CSA guidance. What this accomplishes is it enables the organization to map all the different phases of the cloud data life cycle as against required controls for each phase of the life cycle.

It is important to note that the data life cycle serves as a framework to map use cases, with regard to data access and assisting in the development of relevant controls for each state of the life cycle. It is also important to note that the life cycle referenced is intended to serve as a standardized approach to data life cycle and security.

Phases

The (Read more...)

*** This is a Security Bloggers Network syndicated blog from InfoSec Resources authored by Greg Belding. Read the original post at: http://feedproxy.google.com/~r/infosecResources/~3/OGv4hW29Q70/

Recent Posts

NewDay Scores with TigerGraph Cloud to Fight Financial Fraud

Leading UK Credit Card Consumer Finance Company Uses Advanced Graph Analytics to Intercept Fraudulent Credit Card Applications, Boost Anti-Fraud Efforts…

48 mins ago

VMRay Closes $25 Million Series B

Digital+ Partners Leads Continuation Funding Round in Growing Automated Threat Analysis & Detection Provider, Closing its Series B Round at…

3 hours ago

The Hacker Mind Podcast: Hacking OpenWRT

For three years OpenWRT had a severe validation problem with its download package manager, until a fuzz tester found and…

3 hours ago

Goodbye to Flash – if you’re still running it, uninstall Flash Player now

It’s time to say a final “Goodbye” to Flash. (Or should that be “Good riddance”?) With earlier this week seeing…

3 hours ago

Being a Defender

1. Be a student of (information security, network security, cyber security). Always strive to know what the latest tactics, trends,…

4 hours ago

Smart DNS: Delivering the Best Subscriber Experience

This is the second in a series of blog posts that discuss how smart DNS resolvers can enhance ongoing network…

4 hours ago