This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "Category:OWASP Cloud ‐ 10 Project"
Line 1: | Line 1: | ||
==== Main ==== | ==== Main ==== | ||
− | == Goal == | + | == Goal == |
Goal of the project is to maintain a list of top 10 security risks faced with the Cloud Computing and SaaS Models. List will be maintained by input from community, security experts and security incidences at cloud/SaaS providers. | Goal of the project is to maintain a list of top 10 security risks faced with the Cloud Computing and SaaS Models. List will be maintained by input from community, security experts and security incidences at cloud/SaaS providers. | ||
− | == Audience == | + | == Audience == |
Audience for the project will be organizations planning on leveraging external cloud environment to host their applications or rent application in a SaaS model (Software as a Service). Aim of the "OWASP Cloud-10" list is to help balance security risks with the cost advantage that the Cloud and SaaS model provides. We expect the Cloud and SaaS providers to be indirect audience for "OWASP Cloud-10", when they try to showcase their security controls to potential customers against this list. | Audience for the project will be organizations planning on leveraging external cloud environment to host their applications or rent application in a SaaS model (Software as a Service). Aim of the "OWASP Cloud-10" list is to help balance security risks with the cost advantage that the Cloud and SaaS model provides. We expect the Cloud and SaaS providers to be indirect audience for "OWASP Cloud-10", when they try to showcase their security controls to potential customers against this list. | ||
− | == Managing OWASP Cloud-10 List (Pre-Alpha) == | + | == Managing OWASP Cloud-10 List (Pre-Alpha) == |
“OWASP Cloud-10” list will be maintained by input from, community, security experts and security incidences at cloud/SaaS providers. | “OWASP Cloud-10” list will be maintained by input from, community, security experts and security incidences at cloud/SaaS providers. | ||
Line 24: | Line 24: | ||
==== OWASP Cloud-10 List ==== | ==== OWASP Cloud-10 List ==== | ||
− | == Initial pre-alpha list of OWASP Cloud-10 Security Risks == | + | == Initial pre-alpha list of OWASP Cloud-10 Security Risks == |
{| cellpadding="2" border="1" | {| cellpadding="2" border="1" | ||
Line 63: | Line 63: | ||
'''<center>Table 1: Top 10 Cloud - Security Risks</center>''' | '''<center>Table 1: Top 10 Cloud - Security Risks</center>''' | ||
− | == Other OWASP Cloud-10 Candidates == | + | == Other OWASP Cloud-10 Candidates == |
*Service Availability Risk | *Service Availability Risk | ||
Line 83: | Line 83: | ||
==== Roadmap (Status) ==== | ==== Roadmap (Status) ==== | ||
− | == Alpha State == | + | == Alpha State == |
#'''Identify and publish a first draft of potential "OWASP Cloud-10" candidates (July 2009)''' | #'''Identify and publish a first draft of potential "OWASP Cloud-10" candidates (July 2009)''' | ||
Line 89: | Line 89: | ||
#Get initial community feedback by discussing it in various blogs, discussion forums etc. (till Aug-Sept 2009) | #Get initial community feedback by discussing it in various blogs, discussion forums etc. (till Aug-Sept 2009) | ||
− | == Beta State == | + | == Beta State == |
#Publish the first (beta) list of "OWASP Cloud-10" (Oct 2009) | #Publish the first (beta) list of "OWASP Cloud-10" (Oct 2009) | ||
Line 99: | Line 99: | ||
==== Reference ==== | ==== Reference ==== | ||
− | == Related Efforts == | + | == Related Efforts == |
#Cloud Security Alliance - http://www.cloudsecurityalliance.org/ | #Cloud Security Alliance - http://www.cloudsecurityalliance.org/ | ||
#IDC Aug 2008 Survey (Security #1) Challenge for Cloud/On-Demand Models - http://blogs.idc.com/ie/?p=210 | #IDC Aug 2008 Survey (Security #1) Challenge for Cloud/On-Demand Models - http://blogs.idc.com/ie/?p=210 | ||
− | == Related OWASP Projects == | + | == Related OWASP Projects == |
#OWASP Top Ten Project | #OWASP Top Ten Project | ||
Line 113: | Line 113: | ||
==== Contributors ==== | ==== Contributors ==== | ||
− | == Project Leaders == | + | == Project Leaders == |
− | [[:User:vinaykbansal|'''Vinay Bansal''']]<br>[[User:Shankar Babu Chebrolu|Shankar Babu Chebrolu]]<br> [[User:Martin G. Nystrom|Martin G. Nystrom]]<br> [[User:Jim Born|Jim Born]] | + | [[:User:vinaykbansal|'''Vinay Bansal''']]<br>[[User:Shankar Babu Chebrolu|Shankar Babu Chebrolu]]<br> [[User:Martin G. Nystrom|Martin G. Nystrom]]<br> [[User:Jim Born|Jim Born]] |
− | [http://www.owasp.org/index.php/User:Ken_Huang Ken Huang] | + | [http://www.owasp.org/index.php/User:Ken_Huang Ken Huang] |
== Contributors == | == Contributors == |
Revision as of 20:22, 21 October 2009
Main
Goal
Goal of the project is to maintain a list of top 10 security risks faced with the Cloud Computing and SaaS Models. List will be maintained by input from community, security experts and security incidences at cloud/SaaS providers.
Audience
Audience for the project will be organizations planning on leveraging external cloud environment to host their applications or rent application in a SaaS model (Software as a Service). Aim of the "OWASP Cloud-10" list is to help balance security risks with the cost advantage that the Cloud and SaaS model provides. We expect the Cloud and SaaS providers to be indirect audience for "OWASP Cloud-10", when they try to showcase their security controls to potential customers against this list.
Managing OWASP Cloud-10 List (Pre-Alpha)
“OWASP Cloud-10” list will be maintained by input from, community, security experts and security incidences at cloud/SaaS providers.
Each of the identified risk in "OWASP Cloud-10" will provide details on:
- Various Risk Scenarios
- Real World Examples
- Possible Mitigations and Security Controls
- Reference to any related Incident
OWASP Cloud-10 List
Initial pre-alpha list of OWASP Cloud-10 Security Risks
C1 - Privacy of Users | [Placeholder] - User's private and PII data gets stored in the cloud |
C2 - Enterprise Data Hosted Outside in Cloud | |
C3 - Accountability and Ownership of Data Security | |
C4 - Federating User Identity | |
C5 - Secondary Usage of Data | |
C6 - Demonstrating Regulatory Compliance | |
C7 - SLA - Building Right Level of insurance and accountability | |
C8 - Vendor Lock-In | |
C9 - Data Backup and Disaster Recovery | |
C10 - Direct Exposure to Development and Production Environments |
|
Other OWASP Cloud-10 Candidates
- Service Availability Risk
- Multi-Tenancy
- Integration between cloud and internally hosted services
- Patching and Vulnerability Management
- Lack of Transparency in Internal Security Controls and difficulty/complexity of auditing
- Enterprise Intranets exposed directly on Internet (if they move on a Public Cloud)
This needs to be debated and for each of these we may need to add a separate page-holder with the following details.
- Various Risk Scenarios
- Real World Examples
- Possible Mitigation and Security Controls
- Reference to any related Incident
Roadmap (Status)
Alpha State
- Identify and publish a first draft of potential "OWASP Cloud-10" candidates (July 2009)
- Ask contributors to collect more data and details on each of the risk item. (till Aug 2009)
- Get initial community feedback by discussing it in various blogs, discussion forums etc. (till Aug-Sept 2009)
Beta State
- Publish the first (beta) list of "OWASP Cloud-10" (Oct 2009)
- Identify additional candidates
- ……. (repeat steps as in Alpha)
Reference
Related Efforts
- Cloud Security Alliance - http://www.cloudsecurityalliance.org/
- IDC Aug 2008 Survey (Security #1) Challenge for Cloud/On-Demand Models - http://blogs.idc.com/ie/?p=210
Related OWASP Projects
- OWASP Top Ten Project
- OWASP Legal Project
Contributors
Project Leaders
Vinay Bansal
Shankar Babu Chebrolu
Martin G. Nystrom
Jim Born
Contributors
Project Details
PROJECT INFO What does this OWASP project offer you? |
RELEASE(S) INFO What does this OWASP project release offer you? | ||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
Subcategories
This category has the following 2 subcategories, out of 2 total.
Pages in category "OWASP Cloud ‐ 10 Project"
The following 14 pages are in this category, out of 14 total.
C
- Cloud - Top 5 Risks with PAAS
- Cloud Top 5 Risks with IAAS
- Cloud-10 Accountability and Data Ownership
- Cloud-10 Incidence Analysis and Forensic Support
- Cloud-10 Infrastructure Security
- Cloud-10 Multi Tenancy and Physical Security
- Cloud-10 Regulatory Compliance
- Cloud-10 Risks with Cloud IT Foundation Tier
- Cloud-10 Risks with SaaS
- Cloud-10 Service and Data Integration
- Cloud-10 User Identity Federation
- Cloud-10 User Privacy and Secondary Usage of Data