Unit 2: SLA management and security
Cloud Computing notes · PTU syllabus (PGCA1937)
On this page
Unit summary
Cloud services are governed by contracts and must be secured. This unit covers SLA management approaches, types and life cycle, automated policy-based management, cloud security, brokered cloud storage access, storage location and tenancy, encryption, and auditing and compliance.
After this unit you can
- Explain SLAs, their types and life cycle
- Explain automated policy-based management
- Explain cloud security, brokered access and tenancy
- Explain encryption, auditing and compliance in the cloud
PTU syllabus topics
- SLA management approaches
- types and life cycle
- automated policy-based management
- cloud security
- brokered cloud storage access
- storage location and tenancy
- encryption
- auditing and compliance
Availability
Uptime of the service
99.9% (about 8.8 hours downtime a year)
Response time
Speed of replies
Under 200 ms
Throughput
Work done per second
1,000 requests/second
Support
Time to respond to incidents
Within 1 hour for critical issues
Topic 1
Service level agreements
- An SLA is a contract between provider and customer defining the service, measurable performance targets (SLOs), responsibilities, and remedies (service credits) if targets are missed.
- Service description
- What is provided
- Availability
- E.g., 99.95% monthly uptime
- Performance
- Response time, throughput
- Support
- Response times by severity
- Security and data
- Backup, location, privacy
- Penalties
- Service credits for breaches
- Exclusions
- Planned maintenance, customer faults
Allowed downtime
(1 − availability) × period
99.9% monthly
About 43.8 minutes in a 30.4-day month
99.99% monthly
About 4.4 minutes
Topic 2
Types of SLA
Customer-based
One customer covering all services they use
A college's agreement for all its cloud services
Service-based
One service for all customers
Standard storage SLA published by a provider
Multi-level
Corporate, customer and service levels combined
Large enterprise contract
Infrastructure vs application SLA
Machine availability vs end-to-end application performance
IaaS uptime vs web response time
Topic 3
SLA management approaches and life cycle
- Approaches: provider-managed (provider monitors and reports), customer or third-party monitored (independent tools), and automated SLA management using policies and monitoring agents.
Topic 4
Automated policy-based management
- Policy-based management uses rules ("if CPU above 75% for 5 minutes, add an instance"; "delete backups older than 90 days") that the platform enforces automatically to meet SLAs and control cost.
- 1Monitor metrics and logs
- 2Compare with policies and SLOs
- 3Decide actions (scale, migrate, restart, alert)
- 4Execute through orchestration APIs
- 5Record and report
- Examples: auto-scaling policies, AWS Config rules and Azure Policy for compliance, lifecycle policies for storage, budget alerts.
Topic 5
Cloud security
- Shared responsibility model: the provider secures the cloud infrastructure; the customer secures data, identities, configurations and applications.
- Risks: misconfiguration, weak identity management, insecure APIs, data breaches, account hijacking, insider threats, vendor lock-in, compliance gaps.
- Controls: identity and access management with MFA, encryption at rest and in transit, key management, logging and monitoring, backups, security posture management, certifications (ISO 27001, SOC 2), MeitY empanelment for government workloads.
Topic 6
Brokered cloud storage access
- In a brokered model, clients never talk to storage directly: a proxy (broker) authenticates requests and forwards them to storage, so a compromised client cannot reach the storage system's credentials.
- 1Client sends a request to the broker
- 2Broker authenticates and checks authorisation
- 3Broker requests data from storage using its own credentials
- 4Storage returns data to the broker
- 5Broker returns data to the client
- Modern equivalents: pre-signed URLs with short expiry, API gateways and token-based access (IAM roles).
Topic 7
Storage location and tenancy
- Storage location: customers must know and control the region where data is stored for latency and legal reasons — e.g., RBI's requirement that payment system data be stored only in India; DPDP Act rules on cross-border transfer.
Meaning
Dedicated hardware or instance for one customer
Many customers share infrastructure, logically isolated
Cost
Higher
Lower
Isolation
Strong
Depends on hypervisor and access controls
Example
Dedicated hosts
Standard SaaS and IaaS
Topic 8
Encryption in the cloud
- Data at rest
- Server-side encryption of disks and objects (AES-256)
- Data in transit
- TLS for all connections
- Data in use
- Confidential computing with secure enclaves
- Key management
- Provider-managed keys, customer-managed keys in a KMS, or bring your own key (BYOK) and hardware security modules
- Client-side encryption
- Data encrypted before upload; provider never sees plaintext
Topic 9
Auditing and compliance
- Auditing: logging who did what and when (AWS CloudTrail, Azure Activity Log), reviewed regularly and protected from tampering.
- ISO/IEC 27001 and 27017
- Information security and cloud-specific controls
- ISO/IEC 27018
- Protection of personal data in public clouds
- SOC 2
- Service organisation controls reports
- PCI DSS
- Card payment data
- MeitY empanelment
- Cloud services for Indian government
- DPDP Act, 2023
- Indian personal data protection
- Under the shared responsibility model, certifications cover the provider's part; customers must still configure and audit their own workloads.
Key terms
- SLA
- Contract specifying service levels and remedies
- SLO
- Measurable target within an SLA
- Policy-based management
- Automatic enforcement of operational rules
- Multi-tenancy
- Many customers sharing infrastructure with isolation
- Key management service
- Cloud service storing and controlling encryption keys
Quick revision
- SLA contents; availability arithmetic; customer-, service- and multi-level SLAs.
- SLA life cycle; management approaches.
- Policy-based automation loop.
- Shared responsibility; brokered access; data location; single vs multi-tenancy.
- Encryption at rest, in transit, in use; KMS, BYOK; audit logs; ISO 27001/27017/27018, SOC 2, PCI DSS.
Important exam questions
Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).
Short-answer questions
- Q1.What is an SLA?
- Q2.Calculate monthly downtime allowed by 99.9% availability.
- Q3.Name the phases of the SLA life cycle.
- Q4.What is brokered cloud storage access?
- Q5.Distinguish single and multi-tenancy.
- Q6.What is BYOK?
Long-answer questions
- Q1.Explain SLAs, their types and life cycle.
- Q2.Explain automated policy-based management.
- Q3.Explain cloud security, brokered access and storage location issues.
- Q4.Explain encryption, auditing and compliance in the cloud.
Stuck on this unit?
Message SBS on WhatsApp for help with Cloud Computing, or to ask about studying M.Sc IT at Synetic.
