Skip to content
Menu
Cloud Gal 42
  • Home
Cloud Gal 42

Secure Cloud Data Center Design – Part 3

September 2, 2021September 1, 2021 by admin

Physical and Environmental Protection

ISO/IEC TS 22237-2 Protection and Availability Classes

ISO/IEC TS 22237-2 lists multiple layers of security referred to as classes. Each class has a guidance profile that specifies the proper controls that should exist at each layer. Outer layers have less stringent control guidance than inner layers. The two topics of control for build/design are protection class and availability class.

Protection classes are consigned to spaces within a data center. As you arrive at the most central location, or the core, in the data center, you will find the systems that garner the greatest levels of protection as they are the most critical and highly valued. An example of the classes and associated system are illustrated below.

Often least privilege is associated with minimizing access rights on digital systems, but to have holistic security we also need to apply least privilege to physical space and perimeters we set for that space. The relationship to personnel access is outlined in the chart that follows.

Availability classes are connected to power distribution and can maintain resilience during disruption. The classes are defined as:

  • Class 1: Single-path (no resilience) where planned maintenance or unplanned outage causes services outages in dependent systems
  • Class 2: Single-path (resilience is provided by redundancy of components) with no redundant environmental controls or telecommunication cabling
  • Class 3: Multipath (resilience provided by redundancy of systems) resilience and concurrent repair/operate solution; environmental controls contain redundant components with multipath telecommunication cabling using fixed infrastructure
  • Class 4: Multipath (fault tolerant even during maintenance) along with multipath environmental controls by redundant systems and multipath telecommunication cabling using fixed infrastructure with diverse pathways

Related

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Role of AI/ML in Cybersecurity
  • QuickGuide: Security on OCI
  • The Cloud Management Plane
  • Secure Installation and Configuration of Virtualized Cloud Datacenters
  • Cloud Datacenter: Hardware-specific Security Configuration Requirements

Recent Comments

  • Rafael on Installing Debian on OCI
  • Jorge on Installing Debian on OCI
  • admin on Installing Debian on OCI
  • Andreas on Installing Debian on OCI
  • admin on Installing Debian on OCI

Archives

  • December 2022
  • February 2022
  • September 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • February 2021
  • January 2021
  • November 2020
  • October 2020

Categories

  • aws
  • bcdr
  • cloud
  • cloudsecurity
  • compliance
  • informationsecurity
  • oracle
  • pci
  • QuickGuide
  • security
©2025 Cloud Gal 42 | Powered by WordPress and Superb Themes!