{"id":4791,"date":"2022-03-30T16:43:09","date_gmt":"2022-03-30T14:43:09","guid":{"rendered":"https:\/\/preventista.sk\/info\/?p=4791"},"modified":"2022-03-31T14:53:47","modified_gmt":"2022-03-31T12:53:47","slug":"rizika-sucast-cloud-sveta","status":"publish","type":"post","link":"https:\/\/preventista.sk\/info\/rizika-sucast-cloud-sveta\/","title":{"rendered":"Rizik\u00e1 \u2013 s\u00fa\u010das\u0165 Cloud sveta (5.\u010das\u0165 miniseri\u00e1lu)"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Prin\u00e1\u0161ame v\u00e1m \u010fal\u0161\u00ed \u010dl\u00e1nok, ktor\u00fd sa venuje bezpe\u010dnosti cloudov. V&nbsp;predch\u00e1dzaj\u00facich \u010dl\u00e1nkoch sme hovorili o tom, \u017ee faktor zdie\u013eania zdrojov poskytovan\u00fdch a&nbsp;vyu\u017e\u00edvan\u00fdch vo forme cloud slu\u017eieb m\u00f4\u017ee ma\u0165 ekonomick\u00fd pr\u00ednos (Economy of the Scale). Z\u00e1rove\u0148 v\u0161ak prin\u00e1\u0161a zdie\u013eanie zodpovednosti za spr\u00e1vne a&nbsp;bezpe\u010dn\u00e9 pou\u017e\u00edvanie cloud slu\u017eieb. Nielen poskytovate\u013e cloud slu\u017eby je zodpovedn\u00fd za jej bezpe\u010dn\u00e9 prev\u00e1dzkovanie, ale aj odberate\u013e m\u00e1 povinnos\u0165 dodr\u017eiava\u0165 ist\u00e9 pravidl\u00e1 bezpe\u010dn\u00e9ho spr\u00e1vania sa v&nbsp;cloudovom prostred\u00ed. Nevhodn\u00e9, alebo nezodpovedn\u00e9 pou\u017e\u00edvanie cloudov\u00fdch zdrojov a slu\u017eieb m\u00f4\u017ee ma\u0165 dopad na bezpe\u010dnos\u0165 \u010di u\u017e pou\u017e\u00edvania cloudov\u00fdch slu\u017eieb, alebo spracovania citliv\u00fdch d\u00e1t v&nbsp;cloudovom prostred\u00ed. Rovnako ako nezodpovedn\u00e9 spr\u00e1vanie sa v&nbsp;\u017eivote, aj nezodpovedn\u00e9 spr\u00e1vanie sa v&nbsp;cloudovom prostred\u00ed n\u00e1s vystavuje riziku.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img data-recalc-dims=\"1\" decoding=\"async\" data-attachment-id=\"4680\" data-permalink=\"https:\/\/preventista.sk\/info\/predstavujeme-vam-cloud-prirodzenu-sucast-nasich-zivotov\/cloud-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/Cloud-2.png?fit=940%2C788&amp;ssl=1\" data-orig-size=\"940,788\" data-comments-opened=\"1\" data-image-title=\"Cloud-2\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/Cloud-2.png?fit=700%2C587&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/Cloud-2.png?resize=700%2C587&#038;ssl=1\" alt=\"\" class=\"wp-image-4680\" width=\"700\" height=\"587\" srcset=\"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/Cloud-2.png?resize=700%2C587&amp;ssl=1 700w, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/Cloud-2.png?resize=450%2C377&amp;ssl=1 450w, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/Cloud-2.png?resize=320%2C268&amp;ssl=1 320w, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/Cloud-2.png?resize=768%2C644&amp;ssl=1 768w, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/Cloud-2.png?w=940&amp;ssl=1 940w\" sizes=\"(max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">V&nbsp;predch\u00e1dzaj\u00facich \u010dl\u00e1nkoch sme si pripomenuli niektor\u00e9 vybrat\u00e9 z\u00e1kladn\u00e9 bezpe\u010dnostn\u00e9 po\u017eiadavky, pri\u010dom predpoklad\u00e1me, \u017ee ich cloud slu\u017eby maj\u00fa, napr\u00edklad:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>miesto ulo\u017eenia a&nbsp;spracovania d\u00e1t je len v&nbsp;dohodnut\u00fdch d\u00e1tov\u00fdch centr\u00e1ch alebo lokalit\u00e1ch (napr. v&nbsp;r\u00e1mci Eur\u00f3pskej \u00fanie),<\/li><li>je nasaden\u00e9 vhodn\u00e9 a&nbsp;dostato\u010dn\u00e9 oddelenie (segreg\u00e1cia) d\u00e1t r\u00f4znych odberate\u013eov cloud slu\u017eieb,<\/li><li>cloud umo\u017e\u0148uje kontrolovate\u013en\u00fd a&nbsp;neobmedzen\u00fd pr\u00edstup k vypublikovan\u00fdm&nbsp;d\u00e1tam a slu\u017eb\u00e1m,<\/li><li>vlastnosti cloud slu\u017eieb preukazuj\u00fa s\u00falad s po\u017eiadavkami&nbsp;legislat\u00edvy a&nbsp;regul\u00e1torov ak je tak\u00fdto s\u00falad po\u017eadovan\u00fd,<\/li><li>cloudov\u00e1 slu\u017eba m\u00e1 schopnos\u0165 zabezpe\u010di\u0165 dostupnos\u0165, integritu a&nbsp;d\u00f4vernos\u0165 d\u00e1t, napr\u00edklad vyu\u017eit\u00edm techn\u00edk<ul><li>\u0161ifrovania (zamedzenia \u010ditate\u013enosti d\u00e1t pre toho, kto nem\u00e1 pr\u00edstup k&nbsp;\u0161ifrovaciemu k\u013e\u00fa\u010du)<\/li><\/ul><ul><li>riadenia pr\u00edstupu k&nbsp;d\u00e1tam (len opr\u00e1vnen\u00fd pou\u017e\u00edvate\u013e uvid\u00ed d\u00e1ta, aj to len tie, na ktor\u00e9 m\u00e1 povolenie)<\/li><\/ul><ul><li>auditovania (z\u00edskavanie z\u00e1znamov o&nbsp;tom, \u010do sa s&nbsp;d\u00e1tami stalo \u2013 stopovanie\/trekovanie)<\/li><\/ul><ul><li>redundancie (vytv\u00e1ranie tie\u0148ov\u00fdch slu\u017eieb, ktor\u00e9 s\u00fa schopn\u00e9 prevzia\u0165 \u00falohu prim\u00e1rnej slu\u017eby ak z&nbsp;ak\u00fdchko\u013evek d\u00f4vodov vypadne, alebo sa stane nedostupnou)<\/li><\/ul><\/li><li>cloudov\u00e1 slu\u017eba m\u00e1 schopnos\u0165 mana\u017eova\u0165 a&nbsp;monitorova\u0165 slu\u017eby aplik\u00e1ci\u00ed v&nbsp;cloude s&nbsp;cie\u013eom predch\u00e1dza\u0165 ne\u017eelan\u00fdm v\u00fdpadkom, alebo r\u00f4znym prev\u00e1dzkov\u00fdm a&nbsp;bezpe\u010dnostn\u00fdm incidentom<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">V&nbsp;ide\u00e1lnom pr\u00edpade cloudov\u00e1 slu\u017eba sp\u013a\u0148a v\u0161etky, alebo v\u00e4\u010d\u0161inu vy\u0161\u0161ie spomenut\u00fdch bodov technicky aj zmluvne, a&nbsp;z\u00e1rove\u0148 m\u00e1 z\u00e1kazn\u00edk mo\u017enos\u0165 to aj skontrolova\u0165. Av\u0161ak v skuto\u010dnosti nie v\u017edy je mo\u017en\u00e9 jednoducho splni\u0165 v\u0161etky body. Niektor\u00e9 m\u00f4\u017eu by\u0165 extr\u00e9mne n\u00e1kladn\u00e9 alebo pre dan\u00fa slu\u017ebu nedostupn\u00e9. Potom m\u00e1 z\u00e1kazn\u00edk dve mo\u017enosti, bu\u010f od zmluvy odst\u00fapi\u0165, alebo n\u00e1js\u0165 n\u00e1hradn\u00e9 rie\u0161enie, resp. in\u00fa cestu. Alternat\u00edvnou mo\u017enos\u0165ou ako sa vysporiada\u0165 s&nbsp;nesplnen\u00edm vy\u0161\u0161ie uveden\u00fdch po\u017eiadaviek &#8211; &nbsp;pokia\u013e s\u00fa z&nbsp;r\u00f4znych d\u00f4vodov povinn\u00e9 &#8211; je transformova\u0165 ich do riadenia riz\u00edk pou\u017e\u00edvania tej-ktorej cloudovej slu\u017eby. Av\u0161ak, v&nbsp;niektor\u00fdch pr\u00edpadoch, kedy doch\u00e1dza k&nbsp;spracov\u00e1vaniu alebo ukladaniu d\u00e1t s&nbsp;n\u00edzkou \u00farov\u0148ou citlivosti v cloude, nie je nevyhnutn\u00e9 aby dan\u00e1 cloud slu\u017eba v\u0161etky vy\u0161\u0161ie uveden\u00e9 po\u017eiadavky sp\u013a\u0148ala.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Najm\u00e4 pri spracov\u00e1van\u00ed citlivej\u0161\u00edch inform\u00e1ci\u00ed nie je mo\u017en\u00e9 od niektor\u00fdch po\u017eiadaviek upusti\u0165. Pokia\u013e po\u017eadovan\u00e9 bezpe\u010dnostn\u00e9 funkcie aplik\u00e1cia alebo slu\u017eba v&nbsp;cloude nem\u00e1, ani nie je mo\u017en\u00e9 ich na po\u017eiadanie doplni\u0165, a&nbsp;z\u00e1rove\u0148 nie je mo\u017en\u00e9 konkr\u00e9tnu cloudov\u00fa slu\u017ebu nepou\u017e\u00edva\u0165, potom riziko tak\u00e9hoto &#8211; nie \u00faplne bezpe\u010dn\u00e9ho &#8211; pou\u017eitia cloudovej slu\u017eby treba identifikova\u0165 a&nbsp;zhodnoti\u0165 jeho mo\u017en\u00fd dopad pre pr\u00edpad, ak by sa zhodou okolnost\u00ed materializovalo, t.j. stalo sa re\u00e1lnym (ve\u013emi podobne, ako pri v\u00fdbere stravovacieho zariadenia hodnot\u00edme ak\u00e1 je jeho \u00farove\u0148 a&nbsp;kvalita, preto\u017ee sa nechceme jedlom priotr\u00e1vi\u0165, resp. ak n\u00e1m lek\u00e1r prik\u00e1\u017ee dodr\u017eiava\u0165 di\u00e9tu, h\u013ead\u00e1me stravovacie zariadenie, ktor\u00e9 po\u017eiadavky sp\u013a\u0148a).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">T\u00fdm, ako identifikova\u0165 hrozbu, n\u00e1sledne rozpozna\u0165 riziko ktor\u00e9 z&nbsp;hrozby vypl\u00fdva, vyhodnoti\u0165 pravdepodobnos\u0165 toho, \u017ee sa hrozba napln\u00ed a&nbsp;riziko sa pretav\u00ed do ur\u010dit\u00e9ho dopadu sa zaober\u00e1 metodika riadenia riz\u00edk. Cie\u013eom tohto \u010dl\u00e1nku nie je zah\u013abi\u0165 sa do metodiky samotnej, ale pouk\u00e1za\u0165 na niektor\u00e9 naj\u010dastej\u0161ie sa vyskytuj\u00face rizik\u00e1 pou\u017e\u00edvania cloud slu\u017eieb, s&nbsp;ktor\u00fdmi sme sa mali mo\u017enos\u0165 stretn\u00fa\u0165 a&nbsp;zhodnoti\u0165 mo\u017enosti minimaliz\u00e1cie dopadov t\u00fdchto riz\u00edk (risk mitigation).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Napriek tomu, \u017ee sa tento \u010dl\u00e1nok nevenuje metodike riadenia riz\u00edk, pre potreby pochopenia mo\u017enej rizikovosti pou\u017e\u00edvania cloud slu\u017eieb je nutn\u00e9 spomen\u00fa\u0165 nieko\u013eko d\u00f4le\u017eit\u00fdch pojmov, bez ktor\u00fdch sa pri identifik\u00e1cii riz\u00edk a&nbsp;ich mo\u017en\u00fdch dopadov nezaob\u00eddeme:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Citlivos\u0165 d\u00e1t<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">D\u00e1ta \u2013 v&nbsp;z\u00e1vislosti od ich povahy alebo obsahu \u2013 maj\u00fa r\u00f4znu \u00farove\u0148 citlivosti. Niektor\u00e9 s\u00fa verejne pr\u00edstupn\u00e9, in\u00e9 s\u00fa predmetom tajomstva. Pozn\u00e1me nieko\u013eko \u00farovn\u00ed citlivosti d\u00e1t:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Verejn\u00e9 \u2013 d\u00e1ta, ktor\u00e9 nie s\u00fa citliv\u00e9, ka\u017ed\u00fd m\u00f4\u017ee ma\u0165 k&nbsp;nim pr\u00edstup<\/li><li>Intern\u00e9 \u2013 d\u00e1ta, ktor\u00e9 s\u00fa dostupn\u00e9 uzavretej spolo\u010dnosti alebo skupine, napr. vn\u00fatro-firemn\u00e9 inform\u00e1cie, ktor\u00e9 s\u00fa dostupn\u00e9 v\u0161etk\u00fdm zamestnancom, av\u0161ak na verejnos\u0165 nepatria<\/li><li>Citliv\u00e9 \u2013 d\u00e1ta, ktor\u00e9 s\u00fa&nbsp;predmetom ochrany, v\u00e4\u010d\u0161inou s\u00fa k&nbsp;dispoz\u00edcii len definovan\u00fdm opr\u00e1vnen\u00fdm osob\u00e1m a&nbsp;ich prezradenie m\u00f4\u017ee sp\u00f4sobi\u0165 napr\u00edklad prezradenie obchodn\u00e9ho tajomstva, po\u0161kodenie dobr\u00e9ho mena, alebo sa m\u00f4\u017ee jedna\u0165 o&nbsp;\u00fadaje, ktor\u00e9 s\u00fa&nbsp;predmetom ochrany zo z\u00e1kona ako napr\u00edklad z\u00e1kon o&nbsp;ochrane osobn\u00fdch \u00fadajov (Z\u00e1k 18\/2018 z.z.) alebo obchodn\u00fd z\u00e1konn\u00edk a&nbsp;pod.<\/li><li>Ve\u013emi citliv\u00e9 \u2013 d\u00e1ta, ktor\u00e9 s\u00fa&nbsp;predmetom utajenia \u010di u\u017e z&nbsp;legislat\u00edvnych, alebo aj in\u00fdch d\u00f4vodov, m\u00f4\u017eu ma\u0165 strategick\u00fd v\u00fdznam pre spolo\u010dnos\u0165, organiz\u00e1ciu alebo z\u00e1ujmov\u00fa skupinu. Ich prezradenie m\u00f4\u017ee sp\u00f4sobi\u0165 z\u00e1va\u017en\u00e9 dopady na \u013eud\u00ed, zdravie alebo majetok<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Pri identifik\u00e1cii riz\u00edk je prvorad\u00e9 pochopi\u0165, s&nbsp;ak\u00fdmi d\u00e1tami m\u00e1me do\u010dinenia, t.j. d\u00e1ta ktorej \u00farovne citlivosti sa v&nbsp;cloud slu\u017ebe alebo aplik\u00e1cii maj\u00fa sprac\u00fava\u0165. \u00darove\u0148 citlivosti d\u00e1t definuje rozsah a&nbsp;mieru ochrann\u00fdch a&nbsp;bezpe\u010dnostn\u00fdch opatren\u00ed, ktor\u00e9 m\u00e1&nbsp;ma\u0165 cloud slu\u017eba, pomocou ktorej chceme d\u00e1ta spracov\u00e1va\u0165, alebo v&nbsp;ktorej chceme d\u00e1ta uklada\u0165.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sk\u00f4r, ako sa rozhodneme vy\u017e\u00edva\u0165 konkr\u00e9tnu cloud slu\u017ebu, je d\u00f4le\u017eit\u00e9 pos\u00fadi\u0165 nielen citlivos\u0165 d\u00e1t, ktor\u00e9 do cloudu vlo\u017e\u00edme, ale aj bezpe\u010dnostn\u00e9 funkcie, ktor\u00e9 m\u00e1 cloudov\u00e1 slu\u017eba k&nbsp;dispoz\u00edcii. M\u00e1me na mysli existuj\u00face bezpe\u010dnostn\u00e9 funkcie cloudovej slu\u017eby, ale&nbsp;aj tie,&nbsp;ktor\u00e9 sme sami schopn\u00ed ovplyvni\u0165 tak, aby bolo cel\u00e9 pou\u017eitie dostato\u010dne bezpe\u010dn\u00e9 (slu\u017eby, ktor\u00e9 sami zapneme, alebo inak nastav\u00edme \u2013 napr\u00edklad nastavenie dostato\u010dne siln\u00e9ho pou\u017e\u00edvate\u013esk\u00e9ho hesla).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Pri hodnoten\u00ed cloud slu\u017eby sa m\u00f4\u017ee sta\u0165, \u017ee zist\u00edme, \u017ee ochrann\u00e9 funkcie aplik\u00e1cie v&nbsp;cloude s\u00fa do takej miery nedostato\u010dn\u00e9, \u017ee sa rozhodneme rad\u0161ej dan\u00fa slu\u017ebu nepou\u017e\u00edva\u0165, ne\u017e by sme mali podst\u00fapi\u0165 pr\u00edli\u0161 ve\u013ek\u00e9 riziko, ktor\u00e9 by mohlo vies\u0165 k&nbsp;neprimeran\u00fdm negat\u00edvnym dopadom. Toto sa st\u00e1va hlavne pri SaaS slu\u017eb\u00e1ch (vi\u010f. <em>SaaS \u2013 Software-as-a-Service v&nbsp;\u010dl\u00e1nku <\/em><a href=\"https:\/\/preventista.sk\/info\/cloud-stavebny-prvok-firiem-vysvetlenie-ponuky-sluzieb-2-cast-miniserialu\/\"><em>Cloud \u2013 stavebn\u00fd prvok firiem<\/em><\/a>), ktor\u00e9 s\u00fa stavan\u00e9 tak, \u017ee miera mo\u017enosti ovplyvni\u0165 ich bezpe\u010dnos\u0165 zo strany odberate\u013ea je takmer nulov\u00e1.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Pr\u00edklady riz\u00edk cloudov\u00fdch slu\u017eieb<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em><u>N\u00e1zov rizika:<\/u><\/em> <strong><em>Nevyhovuj\u00face umiestnenie d\u00e1t<\/em><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em><u>Popis:<\/u><\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">D\u00e1ta spracov\u00e1van\u00e9 cloudovou slu\u017ebou s\u00fa trvalo umiestnen\u00e9 v&nbsp;d\u00e1tovom centre, ktor\u00e9ho geografick\u00e1 lokalita nie je vyhovuj\u00faca. Jedn\u00e1 sa o&nbsp;ulo\u017eenie d\u00e1t v&nbsp;d\u00e1tovom centre, ktor\u00e9 je fyzicky umiestnen\u00e9 v&nbsp;krajine s&nbsp;tzv. nedostato\u010dnou \u00farov\u0148ou bezpe\u010dnosti (vi\u010f. <a href=\"https:\/\/dataprotection.gov.sk\/uoou\/sk\/content\/prenos-do-krajin-zarucujucich-primeranu-uroven-ochrany\">https:\/\/dataprotection.gov.sk\/uoou\/sk\/content\/prenos-do-krajin-zarucujucich-primeranu-uroven-ochrany<\/a>)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em><u>N\u00e1vrh na zn\u00ed\u017eenie dopadu rizika:<\/u><\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Pokia\u013e je to mo\u017en\u00e9, zmluvne dohodn\u00fa\u0165 vyu\u017eitie DC umiestnen\u00e9ho vo vhodnej lokalite, nemenite\u013enos\u0165 tohto umiestnenia, a&nbsp;dohodn\u00fa\u0165 met\u00f3du kontroly uplat\u0148ovania dohodnutej podmienky. Z\u00e1rove\u0148 technicky zabezpe\u010di\u0165 nastavenie vyu\u017e\u00edvania vhodn\u00e9ho regi\u00f3nu umiestnenia DC (napr. zvoli\u0165 regi\u00f3n EU, alebo konkr\u00e9tne mesto v&nbsp;r\u00e1mci EU v&nbsp;nastaveniach slu\u017eby)<ins>.<\/ins><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em><u>N\u00e1zov rizika:<\/u><\/em> <strong><em>Nedostato\u010dn\u00e1 ochrana d\u00e1t v&nbsp;\u00falo\u017eisku<\/em><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em><u>Popis:<\/u><\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">D\u00e1ta ulo\u017een\u00e9 v&nbsp;permanentnom \u00falo\u017eisku cloudovej slu\u017eby nie s\u00fa dostato\u010dne chr\u00e1nen\u00e9, preto\u017ee nie je adekv\u00e1tne obmedzen\u00e1 ich \u010ditate\u013enos\u0165.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em><u>N\u00e1vrh na zn\u00ed\u017eenie dopadu rizika:<\/u><\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ochrana d\u00e1t v&nbsp;\u00falo\u017eisku m\u00f4\u017ee by\u0165 zv\u00fd\u0161en\u00e1 vyu\u017eit\u00edm \u0161ifrovania, t.j. met\u00f3dy utajenia &#8211; \u201ezne\u010ditate\u013enenia\u201c obsahu, ktor\u00e1 umo\u017en\u00ed zobrazi\u0165 d\u00e1ta v&nbsp;\u010ditate\u013enom tvare len vtedy, ak je k&nbsp;dispoz\u00edcii k\u013e\u00fa\u010d na roz\u0161ifrovanie d\u00e1t. Existuje viacero mo\u017enost\u00ed, ako zrealizova\u0165 \u0161ifrovanie. \u00da\u010dinnos\u0165 ochrany d\u00e1t \u0161ifrovan\u00edm je z\u00e1visl\u00e1 od met\u00f3dy ochrany samotn\u00e9ho \u0161ifrovacieho k\u013e\u00fa\u010da. &nbsp;Pozn. Pokia\u013e vhodn\u00fdm sp\u00f4sobom neumiestnime a&nbsp;neochra\u0148ujeme \u0161ifrovac\u00ed k\u013e\u00fa\u010d, met\u00f3da je ne\u00fa\u010dinn\u00e1. Naviac,&nbsp;zapnutie \u0161ifrovania m\u00f4\u017ee ma\u0165 \u010fal\u0161ie negat\u00edvne dopady, napr. zn\u00ed\u017eenie v\u00fdkonnosti celej aplik\u00e1cie.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em><u>N\u00e1zov rizika:<\/u><\/em> <strong><em>Nevyhovuj\u00face z\u00e1lohovanie d\u00e1t<\/em><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em><u>Popis:<\/u><\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">D\u00e1ta spracov\u00e1van\u00e9 cloud slu\u017ebou nie s\u00fa z\u00e1lohovan\u00e9 v\u00f4bec, alebo s\u00fa z\u00e1lohovan\u00e9 nevhodn\u00fdm sp\u00f4sobom (t.j. s\u00fa&nbsp;pren\u00e1\u0161an\u00e9 do neschv\u00e1lenej lokality d\u00e1tov\u00e9ho centra, napr\u00edklad mimo kraj\u00edn s&nbsp;dostato\u010dnou \u00farov\u0148ou bezpe\u010dnosti)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em><u>N\u00e1vrh na zn\u00ed\u017eenie dopadu rizika:<\/u><\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Toto riziko je mo\u017en\u00e9 minimalizova\u0165 zvolen\u00edm vhodnej strat\u00e9gie z\u00e1lohovania. Pri vo\u013ebe sp\u00f4sobu z\u00e1lohovanie je d\u00f4le\u017eit\u00e9 ur\u010di\u0165 frekvenciu a&nbsp;rozsah z\u00e1lohovania, vhodn\u00e9 umiestnenie z\u00e1lohy a&nbsp;sp\u00f4sob a&nbsp;frekvenciu testovania kvality a&nbsp;sp\u00f4sobilosti, resp. platnosti z\u00e1lohy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Z\u00e1lohovanie m\u00f4\u017ee by\u0165 v&nbsp;niektor\u00fdch pr\u00edpadoch dizajnovou s\u00fa\u010das\u0165ou cloud slu\u017eby, \u010do znamen\u00e1, \u017ee sp\u00f4sob a&nbsp;frekvencia z\u00e1lohovania je prirodzenou s\u00fa\u010das\u0165ou slu\u017eby samotnej (pon\u00faka ju dod\u00e1vate\u013e cloudu), len je potrebn\u00e9 ju zapn\u00fa\u0165, t.j. inicializova\u0165 vykon\u00e1vanie z\u00e1lohovania, popr\u00edpade zvoli\u0165 frekvenciu a&nbsp;miesto ulo\u017eenia. V&nbsp;takomto pr\u00edpade vykon\u00e1 z\u00e1lohu poskytovate\u013e v&nbsp;s\u00falade s&nbsp;dohodnut\u00fdmi alebo zvolen\u00fdmi parametrami. Z\u00e1rove\u0148 je d\u00f4le\u017eit\u00e9 ukotvi\u0165 sp\u00f4sob a&nbsp;met\u00f3du z\u00e1lohovania v&nbsp;zmluvn\u00fdch podmienkach, rovnako ako aj met\u00f3du kontroly platnosti z\u00e1lohy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u017divot s&nbsp;cloudov\u00fdmi slu\u017ebami m\u00e1 svoje rizik\u00e1. V&nbsp;\u010dl\u00e1nku sme zhrnuli z\u00e1kladn\u00e9 po\u017eiadavky na cloud z&nbsp;poh\u013eadu bezpe\u010dnosti a&nbsp;to, \u017ee nesplnenie na\u0161ich po\u017eiadaviek prin\u00e1\u0161a rizik\u00e1. Rizik\u00e1 je mo\u017en\u00e9 zmier\u0148ova\u0165, alebo s&nbsp;nimi \u017ei\u0165. Pre lep\u0161ie pochopenie riz\u00edk v&nbsp;cloude sme priniesli nieko\u013eko pr\u00edkladov riz\u00edk cloud slu\u017eieb.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Koloto\u010d zmien v&nbsp;cloud slu\u017eb\u00e1ch je skuto\u010dne ve\u013emi r\u00fdchly, a&nbsp;zmeny sa realizuj\u00fa so skuto\u010dne vysokou frekvenciou. Av\u0161ak, nie v\u0161etky zmeny s\u00fa u\u017eito\u010dn\u00e9 a&nbsp;pr\u00ednosn\u00e9. Niektor\u00e9 zmeny s\u00fa&nbsp;do takej miery nevyhovuj\u00face, \u017ee prin\u00e1\u0161aj\u00fa potrebu cloud slu\u017ebu opustit. Rovnako ako na rizikovos\u0165 cloud prostredia je potrebn\u00e9 by\u0165 pripraven\u00fd aj na potrebu z&nbsp;tohto prostredia od\u00eds\u0165, t.j. ma\u0165 pripraven\u00fa tzv. exit strat\u00e9giu, alebo exit pl\u00e1n. A&nbsp;tejto t\u00e9me sa budeme venova\u0165 v&nbsp;nasleduj\u00facej \u010dasti miniseri\u00e1lu.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Prin\u00e1\u0161ame v\u00e1m \u010fal\u0161\u00ed \u010dl\u00e1nok, ktor\u00fd sa venuje bezpe\u010dnosti cloudov. V&nbsp;predch\u00e1dzaj\u00facich \u010dl\u00e1nkoch sme hovorili o tom, \u017ee faktor zdie\u013eania zdrojov poskytovan\u00fdch a&nbsp;vyu\u017e\u00edvan\u00fdch vo forme cloud slu\u017eieb m\u00f4\u017ee ma\u0165 ekonomick\u00fd pr\u00ednos (Economy of the Scale). Z\u00e1rove\u0148 v\u0161ak prin\u00e1\u0161a zdie\u013eanie zodpovednosti za spr\u00e1vne a&nbsp;bezpe\u010dn\u00e9 pou\u017e\u00edvanie cloud slu\u017eieb. Nielen poskytovate\u013e cloud slu\u017eby je zodpovedn\u00fd za jej bezpe\u010dn\u00e9 prev\u00e1dzkovanie, ale [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[4],"tags":[136],"class_list":["post-4791","post","type-post","status-publish","format-standard","hentry","category-itbezp","tag-cloud"],"aioseo_notices":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":4852,"url":"https:\/\/preventista.sk\/info\/odchod-exit-z-cloudu-6-cast-miniserialu\/","url_meta":{"origin":4791,"position":0},"title":"Odchod (EXIT) z Cloudu (6.\u010das\u0165 miniseri\u00e1lu)","author":"Iveta \u0160\u0165avinov\u00e1","date":"10. m\u00e1ja 2022","format":false,"excerpt":"Povestn\u00e9 \u201eumenie od\u00eds\u0165\u201c, ke\u010f nastane \u010das je pre \u013eud\u00ed \u010dasto \u0165a\u017ek\u00e9. Pre prostredie cloudu patr\u00ed toto umenie medzi strategick\u00e9 schopnosti. V\u00a0\u010dl\u00e1nku o\u00a0rizik\u00e1ch pou\u017e\u00edvania cloud rie\u0161en\u00ed, aplik\u00e1ci\u00ed a slu\u017eieb (vi\u010f Rizik\u00e1 \u2013 s\u00fa\u010das\u0165 Cloud sveta) bolo spomenut\u00e9, \u017ee zmeny v\u00a0cloude sa realizuj\u00fa dod\u00e1vate\u013eom cloud rie\u0161enia s vysokou frekvenciou, av\u0161ak nie v\u0161etky\u2026","rel":"","context":"V &quot;Bezpe\u010dnos\u0165&quot;","block_context":{"text":"Bezpe\u010dnos\u0165","link":"https:\/\/preventista.sk\/info\/category\/itbezp\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/Cloud-2.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/Cloud-2.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/Cloud-2.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/Cloud-2.png?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":4672,"url":"https:\/\/preventista.sk\/info\/cloud-stavebny-prvok-firiem-vysvetlenie-ponuky-sluzieb-2-cast-miniserialu\/","url_meta":{"origin":4791,"position":1},"title":"Cloud &#8211; stavebn\u00fd prvok firiem, vysvetlenie ponuky slu\u017eieb (2.\u010das\u0165 miniseri\u00e1lu)","author":"Iveta \u0160\u0165avinov\u00e1","date":"24. janu\u00e1ra 2022","format":false,"excerpt":"Firmy v\u00a0r\u00e1mci svojich aktiv\u00edt sa potrebuj\u00fa orientova\u0165 v\u00fdlu\u010dne na svoj biznis, aby vedeli dobre a\u00a0spr\u00e1vne a\u00a0v\u010das reagova\u0165 na zmeny trhu. St\u00e1le menej a\u00a0menej sa chc\u00fa zaobera\u0165 spr\u00e1vou svojho IT. Pre firmy je jednoduch\u0161ie zdie\u013ea\u0165 v\u00fdpo\u010dtov\u00e9 a\u00a0d\u00e1tov\u00e9 zdroje a\u00a0prenies\u0165 zodpovednos\u0165 za riadenie na in\u00fa firmu. Cloud sa\u00a0 pomaly, ale isto st\u00e1va\u2026","rel":"","context":"V &quot;Bezpe\u010dnos\u0165&quot;","block_context":{"text":"Bezpe\u010dnos\u0165","link":"https:\/\/preventista.sk\/info\/category\/itbezp\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/image.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/image.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/image.png?resize=525%2C300&ssl=1 1.5x"},"classes":[]},{"id":4708,"url":"https:\/\/preventista.sk\/info\/cloud-stavebne-prvky-a-hranice-zodpovednosti-3-cast-miniserialu\/","url_meta":{"origin":4791,"position":2},"title":"Cloud \u2013 stavebn\u00e9 prvky a\u00a0hranice zodpovednosti (3.\u010das\u0165 miniseri\u00e1lu)","author":"Iveta \u0160\u0165avinov\u00e1","date":"31. janu\u00e1ra 2022","format":false,"excerpt":"Cloudov\u00e9 syst\u00e9my pon\u00fakaj\u00fa neuverite\u013en\u00e9 mo\u017enosti, nielen pre naplnenie jednoduch\u00fdch t\u00fa\u017eob klientov ako je vytvorenie prostredia na ukladanie d\u00e1t a\u00a0v\u00fdpo\u010dtov\u00fd v\u00fdkon. N\u00e1jde sa tam miesto aj na zlo\u017eitej\u0161ie v\u00fdpo\u010dtov\u00e9 \u00falohy, firmy si ved\u00fa v\u00a0aplik\u00e1ci\u00e1ch v\u00a0cloude \u00fa\u010dtovn\u00edctvo a\u00a0niektor\u00e9 kompletn\u00fa kancel\u00e1riu. Av\u0161ak pri tomto to v\u00f4bec nekon\u010d\u00ed, ke\u010f m\u00e1te z\u00e1ujem, viete sa zaregistrova\u0165\u2026","rel":"","context":"V &quot;Bezpe\u010dnos\u0165&quot;","block_context":{"text":"Bezpe\u010dnos\u0165","link":"https:\/\/preventista.sk\/info\/category\/itbezp\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/Cloud-2.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/Cloud-2.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/Cloud-2.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/Cloud-2.png?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":4726,"url":"https:\/\/preventista.sk\/info\/preco-sa-cloud-podoba-olympijskemu-bazenu-4-cast-miniserialu\/","url_meta":{"origin":4791,"position":3},"title":"Pre\u010do sa cloud podob\u00e1 olympijsk\u00e9mu baz\u00e9nu? (4.\u010das\u0165 miniseri\u00e1lu)","author":"Iveta \u0160\u0165avinov\u00e1","date":"17. febru\u00e1ra 2022","format":false,"excerpt":"Predch\u00e1dzaj\u00faci \u010dl\u00e1nok (Cloud \u2013 stavebn\u00e9 prvky a\u00a0hranice zodpovednosti) pribli\u017euje stavebn\u00e9 prvky cloudu, ktor\u00e9 je mo\u017en\u00e9 vyu\u017ei\u0165 v\u00a0s\u00falade s\u00a0na\u0161imi potrebami vyu\u017ei\u0165 slu\u017eby, ktor\u00e9 cloud prostredie poskytuje. Niekedy potrebujeme vyu\u017ei\u0165 len infra\u0161trukt\u00farne slu\u017eby, t.j. pam\u00e4\u0165ov\u00fd a\u00a0procesorov\u00fd v\u00fdkon, alebo \u00falo\u017eisko, inokedy je potrebn\u00e9 vyu\u017ei\u0165 sk\u00f4r komplexnej\u0161ie slu\u017eby. V\u00a0z\u00e1vislosti od typu zapojen\u00fdch\u00a0 slu\u017eieb sa\u2026","rel":"","context":"V &quot;Bezpe\u010dnos\u0165&quot;","block_context":{"text":"Bezpe\u010dnos\u0165","link":"https:\/\/preventista.sk\/info\/category\/itbezp\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/02\/image-1.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/02\/image-1.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/02\/image-1.png?resize=525%2C300&ssl=1 1.5x"},"classes":[]},{"id":4670,"url":"https:\/\/preventista.sk\/info\/predstavujeme-vam-cloud-prirodzenu-sucast-nasich-zivotov\/","url_meta":{"origin":4791,"position":4},"title":"Predstavujeme v\u00e1m Cloud \u2013 prirodzen\u00fa s\u00fa\u010das\u0165 na\u0161ich \u017eivotov (1.\u010das\u0165 miniseri\u00e1lu)","author":"Iveta \u0160\u0165avinov\u00e1","date":"18. janu\u00e1ra 2022","format":false,"excerpt":"Asi ka\u017ed\u00fd z\u00a0n\u00e1s za\u017eil pocit, \u017ee skuto\u010dn\u00e9 pochopenie probl\u00e9mu nastane a\u017e v\u00a0momente, ke\u010f sa ho s\u00e1m sna\u017e\u00ed niekomu vysvetli\u0165, resp. ke\u010f sa na tak\u00e9 vysvetlenie pripravuje Pozit\u00edvna reakcia, vidite\u013ene porozumenie a\u00a0\u00fasmev posluch\u00e1\u010da (rozumej nie IT-\u010dk\u00e1ra) v\u00a0takom pr\u00edpade ur\u010dite pote\u0161\u00ed \ud83d\ude0a A\u00a0e\u0161te viac pote\u0161\u00ed, ke\u010f si posluch\u00e1\u010di adoptuj\u00fa pojmy a\u00a0pr\u00edklady tak,\u2026","rel":"","context":"V &quot;Bezpe\u010dnos\u0165&quot;","block_context":{"text":"Bezpe\u010dnos\u0165","link":"https:\/\/preventista.sk\/info\/category\/itbezp\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/Cloud-2.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/Cloud-2.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/Cloud-2.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2022\/01\/Cloud-2.png?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":2768,"url":"https:\/\/preventista.sk\/info\/outsourcing-informacnych-technologii-a-bezpecnost\/","url_meta":{"origin":4791,"position":5},"title":"Outsourcing informa\u010dn\u00fdch technol\u00f3gi\u00ed a bezpe\u010dnos\u0165","author":"Redakcia","date":"5. augusta 2015","format":false,"excerpt":"In\u0161tit\u00facie verejnej spr\u00e1vy podobne ako firmy a organiz\u00e1cie zo s\u00fakromn\u00e9ho sektora vyu\u017e\u00edvaj\u00fa outsourcing ako jednu zo strat\u00e9gi\u00ed boja s ch\u00fdbaj\u00facimi profesion\u00e1lmi a\u00a0nedostatkom finan\u010dn\u00fdch prostriedkov pre\u00a0oblas\u0165 informa\u010dn\u00fdch a\u00a0komunika\u010dn\u00fdch technol\u00f3gi\u00ed. Je ale n\u00e1kup IT slu\u017eieb pre zabezpe\u010denie kritick\u00fdch procesov a\u00a0bezpe\u010dnosti organiz\u00e1cie u\u00a0dod\u00e1vate\u013ea v\u017edy spr\u00e1vnou vo\u013ebou? Outsourcing je v\u00a0s\u00fa\u010dasnosti ob\u013e\u00faben\u00fdm sp\u00f4sobom optimaliz\u00e1cie n\u00e1kladov\u2026","rel":"","context":"V &quot;Bezpe\u010dnos\u0165&quot;","block_context":{"text":"Bezpe\u010dnos\u0165","link":"https:\/\/preventista.sk\/info\/category\/itbezp\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/08\/cover.jpg?fit=700%2C400&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/08\/cover.jpg?fit=700%2C400&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/08\/cover.jpg?fit=700%2C400&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/08\/cover.jpg?fit=700%2C400&ssl=1&resize=700%2C400 2x"},"classes":[]}],"_links":{"self":[{"href":"https:\/\/preventista.sk\/info\/wp-json\/wp\/v2\/posts\/4791","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/preventista.sk\/info\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/preventista.sk\/info\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/preventista.sk\/info\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/preventista.sk\/info\/wp-json\/wp\/v2\/comments?post=4791"}],"version-history":[{"count":4,"href":"https:\/\/preventista.sk\/info\/wp-json\/wp\/v2\/posts\/4791\/revisions"}],"predecessor-version":[{"id":4824,"href":"https:\/\/preventista.sk\/info\/wp-json\/wp\/v2\/posts\/4791\/revisions\/4824"}],"wp:attachment":[{"href":"https:\/\/preventista.sk\/info\/wp-json\/wp\/v2\/media?parent=4791"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/preventista.sk\/info\/wp-json\/wp\/v2\/categories?post=4791"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/preventista.sk\/info\/wp-json\/wp\/v2\/tags?post=4791"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}