CloudSecurityAlliance/CSA-Guidance

comments/suggestions

Opened this issue · 0 comments

line 7: "It is a technology, a collection of technologies, an operational model, a business model, and more."
I would propose to add "a development model" before "operational model" to make a reference to the devops associated trend.

line 187: about the metastructure. I would propose to make a note on network HSM.

line 213: I would propose to add something about the "nested cloud". Like, "the roles are even more hard to define when some nested technology is considered (eg. https://www.ravellosystems.com/)".

line 221: I would propose to go beyond "document". For instance mentioning that the cloud provider should also provide some API auditing capabilities to enable the cloud consumer to perform security analysis, resource change tracking, and compliance auditing. May be another place is more relevant than line 221?

Regards