what is cloud security, and can i have some?

32
What is Cloud Security, and Can I have Some?

Upload: john-kinsella

Post on 18-Dec-2014

180 views

Category:

Technology


2 download

DESCRIPTION

 

TRANSCRIPT

Page 1: What is Cloud Security, and Can I Have Some?

What is Cloud Security, andCan I have Some?

Page 2: What is Cloud Security, and Can I Have Some?

Introduction

• John Kinsella - CISSP, CCSK• BoD – Silicon Valley Cloud Security Alliance• Co-chair, CSA Portability and App Sec• New secure cloud product in alpha testing

Page 3: What is Cloud Security, and Can I Have Some?

Where I’m from

Page 4: What is Cloud Security, and Can I Have Some?

Overview

o Definition and issueso Legalo Operationso Best Practices

Page 5: What is Cloud Security, and Can I Have Some?

Essential Characteristics

• NIST Definition:– On demand, self service– Broad network access– Resource pooling– Rapid elasticity– Measured service

Page 6: What is Cloud Security, and Can I Have Some?

No cloudwashing

Page 7: What is Cloud Security, and Can I Have Some?

3 Types of clouds

3 Types of Clouds:

Page 8: What is Cloud Security, and Can I Have Some?

Software as a Service (SaaS)

• A system that is fully hosted and managed• Less flexible for end user• More trust involved• Best example: webmail

Page 9: What is Cloud Security, and Can I Have Some?

Platform as a Service (PaaS)

• Provides framework for user to develop final solution

• More flexible than SaaS, requires developers• Possibly still shared information• Potentially less portable

Page 10: What is Cloud Security, and Can I Have Some?

Infrastructure as a Service (IaaS)

• A system that is fully hosted and managed• Most Flexibility• Most control, but not complete• Best example: “Virtual Private Servers”

Page 11: What is Cloud Security, and Can I Have Some?

How IaaS, PaaS, and SaaS fit

Page 12: What is Cloud Security, and Can I Have Some?

Deployment Models

• Public• Private• Hybrid

Page 13: What is Cloud Security, and Can I Have Some?

Legal

o Discoveryo Governanceo Compliance

Page 14: What is Cloud Security, and Can I Have Some?

It’s a Global Stage

Page 15: What is Cloud Security, and Can I Have Some?

Geopolitical Issues

Page 16: What is Cloud Security, and Can I Have Some?

Legal Discovery

• Frequently overlooked• Jurisdiction• Shared environment

Page 17: What is Cloud Security, and Can I Have Some?

Governance

• It’s your problem.– SLAs– Contract negotiation (see: Eli Lilly)– No physical control– Risk Management– Metrics

Page 18: What is Cloud Security, and Can I Have Some?

Compliance/audit

• Regulation hasn’t changed – just implementation• Understand your compliance requirements –

then apply them to the cloud.• Don’t blindly trust provider’s audit – what was

audited?• Right to audit

Page 19: What is Cloud Security, and Can I Have Some?

It’s a Mapping Thing

From CSA Guidance v2.1

Page 20: What is Cloud Security, and Can I Have Some?

Operations

o Where does your information go?o Does your data travel with you?o Who should have access to your cloud?o Incident response and forensicso Encryption

Page 21: What is Cloud Security, and Can I Have Some?

Information Lifecycle Management

• Cloud requires high awareness of data location, sharing, archival and destruction

• Your data, not your equipment• “Delete” doesn’t mean what you think it

means

Page 22: What is Cloud Security, and Can I Have Some?

Portability

• Ability to quickly pull anchor and move providers

• Interoperability between clouds is a plus

Page 23: What is Cloud Security, and Can I Have Some?

Portability smells of hype.

Page 24: What is Cloud Security, and Can I Have Some?

Identity Management

• Scale – single VM or 10,000 email users?• In-house or 3rd party ID provider?• Federation• Authentication• Authorization

Page 25: What is Cloud Security, and Can I Have Some?

Business Continuity

• Don’t forget about backups or DR sites• Cloud is only as good as network attached• An attack on your cloud-neighbor is an attack

on you

Page 26: What is Cloud Security, and Can I Have Some?

Incident Response

• The dance of incident response varies based off…– Providers– Cloud type– Client type– Data sensitivity– Jurisdictions/regulations

Page 27: What is Cloud Security, and Can I Have Some?

Forensics

• Cloud brings us some great advantages from a forensics point of view:

– Very easy to image system for evidence– Can monitor users without detection– Very easy to spin up a new VM to replace

compromised system

Page 28: What is Cloud Security, and Can I Have Some?

Cons to Cloud-Forensics

• Hardware-based tools suddenly inefficient• In shared environments, tracking compromise

across customers may become difficult

Page 29: What is Cloud Security, and Can I Have Some?

Encryption and Key Management

• One of the most important aspects of cloud security

• Security of encryption depends on protection of key

Page 30: What is Cloud Security, and Can I Have Some?

Best Practices

• Encrypt data at rest and in transit• Understand and practice good key management• Consider everyone circumspect• Monitor and gather statistics on everything• Understand your privacy and information laws• Understand where your data lives – what

geographical areas your cloud covers, and where backups reside

• Do not re-invent wheels

Page 31: What is Cloud Security, and Can I Have Some?

Should I Move to The Public Cloud?

• It’s a risk management question:– How valuable is my data (to others)?– Am I willing to to the significant effort to correctly

secure my data in-house?

Page 32: What is Cloud Security, and Can I Have Some?

Questions?

www.protectedindustries.com [email protected] @johnlkinsella