Hello, my name is James Youngblood. And in this module, defensible security architecture, we're gonna be talking about cloud environment. And specifically for this lesson, we're gonna be talking about what is the cloud. The National Institute of Standards and Technology issued a special report title 800-145, Five Characteristics of Cloud Computing. You'll need to know these five characteristics because you will be having to address these as you work with cloud service providers. The first characteristic is cloud computing must be a measured service. So resource usage can be monitored, controlled, and reported. The second one is a rapid elasticity. So with rapid elasticity, resources can be expanded or contracted based on the needs. Resources can be provisioned and released to scale according to the customer's demand. The third one is broad network access. So with broad network access, resources are available over the network and accessed through standard devices, such as PCs, laptops, tablets, and smartphones, and so on. Number four is resource pooling. And basically this is the provider's computing resources are pooled and they serve multiple consumers using a multi-tenant mode with different physical and virtual resources dynamically assigned and reassigned according to the customer's demand. The fifth characteristic is on-demand self-service. So a consumer can unilaterally provision computing capabilities, such as server time and network storage, as needed automatically without requiring human interaction with each service provider. Now, just to give you a brief understanding of what each of these are. We want it to be a measured service because, first of all, cloud service providers need to be able to know exactly how much of their services you've used so they know how much to charge you. Rapid elasticity, a good example of this will be this month I need one terabyte of storage space. The next month I'm gonna need two terabytes of storage space, and the month after that, I only need 512 gigabytes. My cloud service provider needs to be able to expand my storage space. They need to be able to expand the resources I'm using and contract them according to my demands. So when we're dealing with broad network access, we call it broad network access because there's a broad range of devices that can actually access these services. PCs, Macs, laptops, tablets, smartphones. Now, resource pooling is where the cloud service provider, they have a massive amount of resources. They have a massive amount of processing power, of storage space, of network bandwidth, and all of these are gonna be shared amongst all their consumers. Each consumer will be given just a little bit of the resources that they have. And I say a little bit, but it's actually gonna be dependent upon what the consumer actually needs and pays for. The last one being the on-demand self-service is I don't want to have to be required to contact my cloud service provider and speak to a person every time I need to make a change to my services. I need to be able to have a central way that I can log in and change those things myself. So those are the five characteristics of cloud computing, but we also need to talk about a few other things here. There's four different deployment models when we're talking about cloud computing and those four are gonna be public, private, community, and hybrid. The cloud infrastructure for the public cloud is provisioned for open use by the general public. Now, it may be owned or managed and operated by a business or some kind of an academic university or government organization, or it may be a combination of it, but the infrastructure exists on the premises of the cloud provider. When we're dealing with private cloud, the cloud infrastructure is provisioned for exclusive use by a single organization. That single organization may have multiple business units, like we may have our marketing department and our sales department, so it may be multiple business units, but it's for one organization. Now, it may be owned and managed and operated by the organization itself, or it actually might be a third party, or we may actually have a combination of both of them. The difference between the private cloud and public cloud is the infrastructure may exist either onsite at the company or onsite at the cloud service provider if there's a third party. When we're talking about number three, which is the community cloud, the cloud infrastructure's provisioned for exclusive use by a specific community of consumers from organizations that have shared concerns. Understand this could be a collection of schools, it could be a group of businesses in the local community, it could be a civic group that partners with other civic groups in the community. The point being is, is that it's gonna be for several different organizations and they share certain concerns and certain needs as far as with their cloud services. Now it may be owned, managed, and operated by one or more of the organizations in the community, but it may also be managed by a third party. It may be some combination of both of them. The infrastructure may exist on the premises of one of those community members, or it may exist as part of the third party that's providing the services. So dealing with the hybrid cloud, the cloud infrastructure is a composition of two or more distinct cloud infrastructures. So it may be that it's a private and a community cloud, or it may be a private and public cloud, or it may be a community and public cloud, but there's gonna be a combination of two of them. What you need to understand when we're dealing with the hybrid cloud whichever two distinct infrastructures there are they're gonna remain unique entities, but they are bound together by standardized or proprietary technology that's going to enable data and application portability. So basically we can kinda low balance between the two network clouds. And finally, I wanna talk about the service models that are part of cloud infrastructure and part of cloud computing. The first one is software as a service, and you'll see this as SaaS. And basically you need to know the consumer is gonna be using the cloud provider's applications that are running on the cloud provider's infrastructure. The consumer doesn't have any way of managing anything. They just use the application and that's it. So platform as a service, which is PaaS, in this one, the consumer installs on the cloud provider's infrastructure applications that the consumer either created or they acquire. We still are seeing in a platform as a service model that the consumer does not get to control any of the infrastructure. None of that is under the guidance of the consumer. That's all still managed by the cloud service provider. The final one is the infrastructure as a service. This is where things get a little bit different. Consumer provisions, all the processing, storage and networks and other fundamental computing resources where the consumer's able to deploy and run any software that they wish to, and that can actually include operating systems and applications. The consumer still does not manage or control the underlying cloud infrastructure but they do have control over operating systems, storage and deployed applications. There is possible limited control of certain networking components, such as a host firewall. In each of these, the service provider is going to be the one that manages all of the infrastructure, all the underlying infrastructure. The consumer with software as a service, they just get to run software, that's it. With platform as a service, they can deploy their own software that they have acquired or that they have created. And infrastructure as a service, they get to set up exactly what processors, what storage, what memory, and all of those things. They get to determine all of that. They still don't control the underlying infrastructure, but they get to set up all of the rest of that. Thank you for watching this lesson on cloud computing and cloud environment and what exactly is the cloud. Join me in my next video as I talk about what the role of the cloud service provider is in security architecture.