CloudSecurityAlliance/CSA-Guidance

1.1.2.3 diagram

Opened this issue · 3 comments

It is difficult to understand the 'Trusted' and 'untrusted'. I think 'known' and 'unknown' may be better.

it isn't just known though- "known" could be nearly anyone, while "trusted" is known and approved. but Iwill leave this issue open for more feedback.

trusted is a great term and in common use wrt cloud assurance and architecture discussions. Possibly needs a definition for both trusted/untrusted added?

pve commented

In my training sessions i typically explain this as: the consumer controls who the (other) users are.
Private cloud IMHO is about isolation, as a consumer you require your provider to provision resources exclusive to you, and isolate you well enough from other tenants. The consumer decides whether or not the provisioning is exclusive enough. By extension, that means that the consumer should decide/control who the other users are on those resources.