managing risk and s ecurity in the cloud

14

Upload: jacqui

Post on 14-Jan-2016

43 views

Category:

Documents


0 download

DESCRIPTION

Managing Risk and S ecurity in the cloud. Stuart Strathdee / Chief Security Advisor. Session outline. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Managing Risk and  S ecurity in the cloud
Page 2: Managing Risk and  S ecurity in the cloud

Managing Risk and Security in the cloud.

Stuart Strathdee / Chief Security Advisor

Page 3: Managing Risk and  S ecurity in the cloud

Session outline

No cloud strategy is complete without a comprehensive risk management plan. In this session, you can learn more about how Microsoft addresses security, regulatory compliance, the potential for data to cross borders, and interoperability to prevent 'Cloud Lock'.

Page 4: Managing Risk and  S ecurity in the cloud

If this is how you do Threat Analysis, then this presentation is not for you.

Translating the Threat relation[[ trs av −! dt ]] := [[ trs ]] [[ av ]] of [[ dt ]] attacking the system[[ trs av −! v ]] := [[ trs ]] [[ av ]] of [[ v ]] being exploited[[ trs av −! ts(l ) ]] := [[ trs ]] [[ av ]] of [[ ts(l ) ]] being initiated

To illustrate how a diagram is translated we will use the threat diagram in Fig. 5

Fig. 5. Threat diagram

Page 5: Managing Risk and  S ecurity in the cloud

AUSTRAC provides help: http://www.austrac.gov.au/files/risk_management_tool.pdf

Page 7: Managing Risk and  S ecurity in the cloud

Get your head in the cloud.

Page 8: Managing Risk and  S ecurity in the cloud

Why where doesn’t matter.

Page 9: Managing Risk and  S ecurity in the cloud

On premise

Off premise

Page 10: Managing Risk and  S ecurity in the cloud

Why cloud represents greater profitability for partners.

• Allows transitioning of resources from low margin business to high margin business.

• Provides the customer with service levels which would have been prohibitively expensive on an individual scale. Think standards compliance.

• Reduces the exposure for customers and partners.

Page 11: Managing Risk and  S ecurity in the cloud

Case Study time.

Page 12: Managing Risk and  S ecurity in the cloud

Starting today, you can….• Focus more of your

resources on high profit aspects of your business.

• Deliver competitive advantages to your customers.

• Have Microsoft be the foundation for both you and your customers in transforming your businesses.

Page 13: Managing Risk and  S ecurity in the cloud

Acknowledgements:• International Standards Organisation: http://www.iso.org• AUSTRAC• SourceForge.net for the CORAS Security Risk Modelling

Language.• Bsi Group. Http://www.bsigroup.com• http://am3218.k12.sd.us/Event/Wall.htm• http://photosdie.typepad.com• http://www.jhartfound.org• http://www.fashion-res.com• http://www.jodixonjeweller.co.uk/

Page 14: Managing Risk and  S ecurity in the cloud