How secure is the magical land of the cloud?

Mar 22, 2016

Believe it or not, the cloud is not a magical wonderland that protects your data, nor does it have any unique and unheard of risks. Of course, when something is ‘over there’, it feels like it’s less your problem. So many things that would have perhaps been a nagging feeling about a server you set up in your datacentre may feel more distant when they are running in the cloud.

Technically speaking, the cloud does not make it easier to have poor security; it may, however, make poor security feel less painful psychologically. The thing that many of us fail to understand is that the cloud is just the same technology from an on-premise environment running somewhere else. Any risks that there would have been running a CRM app like Salesforce on premises are still there in the cloud, though the share of risks is much smaller since the provider takes care of some.

Is the cloud making people complacent?

The cloud hasn’t made people more complacent to risks, but it also doesn’t seem to have made them more attentive to them either. This varies from organisation to organisation, of course. Some see the very specific language about what duties and risks are theirs in the contracts with their cloud providers and it wakes them up to all the things that may go wrong that they have forgotten.

The complacency comes from the fact that risks are still prioritised for action alongside everything else that pulls on organisations. If it will cost twice the money to fix a security risk as to increase profit margins by a third, what do you think an organisation will do? Organisations will ultimately act to further their main interests and IT security risks don’t often make the cut.

What are the most common mistakes made by enterprise users of public cloud services?

The single most common mistake users of public cloud make is to not read their contracts and understand where their responsibilities truly lie. Often people are unclear as to when and how the creation of a server in the cloud moves from the care and security of the provider to them.

I’ve run into folks who mistakenly thought their cloud provider was patching servers through some back door for them. They weren’t, and the servers went unpatched for months. Often organisations will forget that the layer of management given to them by the cloud provider will also need some security. The administrative users and rights used to configure and control the cloud systems will need to be treated just as carefully as any other privileged users in their systems.

How do you secure your data in the cloud?

Properly securing public cloud resources is, in the end, no different than securing systems running on-premises. The differences, in principle, are none; and the differences in operation are minimal. The real trick to appropriate security in the public cloud is to treat it as if it’s just another datacentre.If there are ways that you want to apply security patterns that turn out not to work because things are running in the cloud, then deal with them as exceptions. You won’t find many.

What are the potential consequences of security issues in the cloud?

The worst consequences of cloud security failures are conversations about cloud security failures. In the end, security in the cloud is only as bad as the user makes it. You could argue that the massive investments made by cloud providers to secure the underpinnings of the applications, servers, and other technologies they offer in the cloud actually makes cloud security quite a bit better.

But cloud is under a microscope because of its impact and potential. Combine that with the fact that there is this (most false) impression that the cloud is somehow less secure, and you get a multiplier for any cloud security failure that happens to occur.

Who is responsible for the internal security of a public cloud service?

Security in the public cloud will need to be a team effort just as it was on premises. There is a need for a security subject matter expert for sure. However, there will be pieces that require a cloud subject matter expert too. The real trouble here is that most organisations don’t have an appropriate process to manage and disseminate good security information for their current systems and moving to the cloud won’t magically fix that.

However, forward-looking organisations could use the opportunity afforded by a paradigm shift like moving to cloud to help establish a better process. Long standing security processes, e.g. those from SANS, are perfectly well suited to the cloud. Taking models that are proven and applying them to the new public cloud operations will definitely result in better outcomes.

Has cloud security changed over the years?

From a security perspective, cloud has been mature for years. If you look at the intimidating list of security and even compliance certifications that the major cloud providers have you can see that no IT shop except the most elite (and well-funded) have ever come close to offering a platform as well secured. They have to. If the cloud providers had a major gap in security, especially considering how much undue attention is being paid to that security, then they would be done with overnight. It’s suffice to say that if you have very poor security in the public cloud, it’s likely you brought it in with you when you walked through the door.


Jonathan Sander, VP of Product Strategy at Lieberman Software

 




Author: Jonathan Sander
View the original article here.
Published under license from ITProPortal.com

https://lifeinsys.com/user/david01
https://app.roll20.net/users/14015474/david-s
https://www.quia.com/profiles/dasmith469
https://www.divephotoguide.com/user/david01
https://photoclub.canadiangeographic.ca/profile/21326904
https://starity.hu/profil/471349-david01/
https://www.facer.io/user/fcuA6R3PWA
https://swaay.com/u/dubaimetro01/about/
https://bootstrapbay.com/user/David02
https://www.trovagas.com/author/david02/
https://mycableengineering.com/activity-feed/userId/11883
https://slideslive.com/david02?tab=about
https://outof.games/members/david02/
https://mentorship.healthyseminars.com/members/david02/
https://onlinevetjobs.com/author/david02/
http://jobboard.piasd.org/author/david02/
https://rnstaffers.com/author/david02/
https://www.bitsdujour.com/profiles/ZKxOus
https://hanson.net/users/david02
http://fid101.ldd.go.th/Activity-Feed/My-Profile/UserId/430
https://cyprus.com/author/david02/
https://ca-riverside-acr.publicaccessnow.com/ActivityFeed/MyProfile/tabid/24/UserId/21065/Default.aspx
https://www.openrec.tv/user/david02/about
http://www.in-almelo.com/User-Profile/userId/2408692
https://www.metaculus.com/accounts/profile/198168/
https://homment.com/fujScGVD3slgtJSo2Hmt
https://www.dnnsoftware.com/activity-feed/my-profile/userid/3207527
https://www.showmethesite.us/lazychicken/ActivityFeed/MyProfile/tabid/2622/UserId/552473/Default.aspx
https://buyandsellhair.com/author/davidmerchant02/
http://aldenfamilydentistry.com/UserProfile/tabid/57/userId/864985/Default.aspx
https://postgresconf.org/users/david-merchant
http://www.worldchampmambo.com/UserProfile/tabid/42/userId/391127/Default.aspx
https://www.pearltrees.com/davidmerchant02
https://useum.org/myuseum/David%2015
https://employbahamians.com/author/david02/
https://www.lotusforsale.com/author/david02/
https://guidetoiceland.is/traveler-profiles/dubaimetro01
https://medibang.com/author/26628380/
https://www.provenexpert.com/david02/
https://independent.academia.edu/DavidMerchant8
https://www.mixcloud.com/davidmerchant02/
https://public.tableau.com/app/profile/david.smith4458/vizzes
https://fitinline.com/profile/david02/
https://www.guiafacillagos.com.br/author/david02/
https://aboutcasemanagerjobs.com/author/david02/
https://www.reddit.com/user/According-Pipe-4349/
https://hfonline.org/members/david02/
https://edgeforscholars.org/author/David02/
https://boersen.oeh-salzburg.at/author/david02/
https://www.allmyusjobs.com/author/david02/
https://medium.com/@dubaimetro01/about
https://conifer.rhizome.org/david02
https://maltajobs.com.mt/author/david02/
https://solo.to/david02
https://olderworkers.com.au/author/dubaimetro01proton-me/
https://www.nieveaventura.com/author/david02/
https://fast-mag.com/author/david02/
https://therealblackfriday.com/author/david02/
https://my.djtechtools.com/users/1428921
https://allmynursejobs.com/author/david02/
https://producerbox.com/users/david02
https://willysforsale.com/author/david02/
https://maactioncinema.com/archives/author/david02
https://aboutnursinghomejobs.com/author/davidsmith02/
https://aboutdirectorofnursingjobs.com/author/davidsmith02/
https://divisionmidway.org/jobs/author/davidsmith02/
https://rndirectors.com/author/davidsmith02/
https://aboutnursernjobs.com/author/davidsmith02/
https://www.diversityofficermagazine.com/diversityjobs/author/davidsmith02/
https://worldranksite.com/author/david02-20618/
https://topbilliondirectory.com/author/david02-19255/
https://microlinksite.com/author/david02-18397/
https://schoolido.lu/user/David02/
https://crypto-potential.com/user/david-smith2
https://www.phraseum.com/user/39572
https://blog.rackons.in/profile/david02
https://blatini.com/profile/David02
http://www.fanart-central.net/user/David02/profile
https://www.zerohedge.com/user/UugyBpExMQaJ1PEunfLJLgRCuDh2
https://www.thebostoncalendar.com/user/84389
https://www.lingvolive.com/en-us/profile/5affccd8-53c7-481c-8163-1e6a751ee318/translations
https://www.pressregister.com/user/public-profile/62355
https://orangelifemagazine.com/author/david02/
https://www.adproceed.com/author/david02/
https://read-blogs.com/author/david02/
https://www.ziparticle.com/author/david02/
https://www.outlived.co.uk/author/david02/
https://classifieds.villages-news.com/author/david02
https://wayranks.com/author/david02-718065/
https://www.mangalorean.com/author/david02/
https://www.tumblr.com/davidsmith-02/758144649588293632/david
https://confengine.com/user/david-smith-3-1
https://handyclassified.com/profile/david02
https://etwinningonline.eba.gov.tr/author/david02/
https://www.vtforeignpolicy.com/author/david02/
https://shareresearch.us/profile/David02
https://www.rafabasa.com/author/david02/
https://www.flowcode.com/page/david02
https://linkpop.com/david02-slug-david02
https://fashonation.com/members/david02/profile/
https://hpad.dataone.org/s/NEZhn8JFX
https://trabajo.merca20.com/author/davidsmith02/
http://amabilis.com/?bbp_user=44909
https://start.me/u/19K1Qj/david
https://arzookanak112.xobor.de/u81_david.html
https://www.sonicbids.com/band/david02/
https://log.concept2.com/profile/2388919
https://activepages.com.au/profile/david02
https://www.popdaily.com.tw/user/459272
https://petites-annonces.commeuncamion.com/author/davidsmith02/
https://linkingdirectory.com/author/david02-17831/
https://blognow.co.in/profile/david02
https://glamorouslengths.com/author/david02/
https://www.sabahjobs.com/author/david02/
https://mercadodinamico.com.br/author/david02/
https://www.sitiosecuador.com/author/davidsmith02/
https://rnmanagers.com/author/david02/
https://progresspond.com/members/david02/
https://toparticlesdirectory.com/author/david02/
https://topacted.com/author/david02-15327/
https://my.archdaily.com/us/@david-smith-38
https://gwar.net/a/bohabs/users/163621
https://www.evtv.me/author/david02/
https://hinative.com/profiles/8234548
https://www.bigoven.com/user/davidsmith02
https://jobs.motionographer.com/employers/3225567-david
https://suzuri.jp/David02
https://maxternmedia.com/author/david02/
https://my.desktopnexus.com/davidsmith02/
https://www.kniterate.com/community/users/david02/
https://cars.yclas.com/user/david-smith-6
https://www.workathomejobsboard.com/employers/3225596-david
https://www.herlypc.es/community/profile/david02/
https://www.deviantart.com/davidsmith02/about
https://jobs.siliconflorist.com/employers/3225646-david-smith
https://eternagame.org/players/394815
https://soundcloud.com/dubaimetro01
https://list.ly/David02/lists
https://slides.com/davidsmith02
https://www.komoot.com/user/4337847745084
https://myanimelist.net/profile/davidsmith02
https://www.mountainproject.com/user/201889914/david-smith
https://www.stem.org.uk/user/1369736
https://www.anobii.com/en/011cdc68c654c023a8/profile/activity
https://foro.kechollazo.com/members/david02.14643/#about
https://yellowfever.co.nz/users/davidsmith02
https://jobs.tdwi.org/employers/3225740-david-smith
https://profile.hatena.ne.jp/davidsmith02/profile
https://bandori.party/user/209596/david02/
https://jobs.employabilitydallas.org/employers/3225755-david-smith
https://jobs.nefeshinternational.org/employers/3225758-david-smith
https://akniga.org/profile/david02/
https://desksnear.me/users/david-smith-ae9110
https://app.impactplus.com/users/david-smith-fe6a3ba6-8c79-4208-a383-7e2d9b0e950a
https://losangeles.bubblelife.com/users/dubaimetro01_b60719
https://www.diigo.com/item/note/b5rx6/8irk?k=92c94fd58c81a79c32216d80ef8b9154
https://www.rafabasa.com/author/diana01/
https://fashonation.com/members/diana01/profile/
http://amabilis.com/?bbp_user=45540
https://trabajo.merca20.com/author/diana01/
https://hpad.dataone.org/s/3i4B21VcZ
https://www.sonicbids.com/band/diana01/
https://participedia.net/user/428445
https://mikropragmata.lifo.gr/meli/23267/
https://petites-annonces.commeuncamion.com/author/diana01/
https://linkingdirectory.com/author/diana01-25276/
https://www.quora.com/profile/Diana-Walker-262
https://www.kniterate.com/community/users/diana01/
https://gravesales.com/author/diana01/
https://www.inspireglobalsolutions.com/profile/Diana8
https://www.letsknowit.com/diana25241
https://glamorouslengths.com/author/Diana01/
https://www.sitiosecuador.com/author/diana01/
https://www.beatstars.com/realdoctorsnotes/about
https://rnmanagers.com/author/diana01/
https://progresspond.com/members/diana01/
https://certified.heartmath.com/user/diana-walker/
https://profile.pmc.org/DW0282
https://bumpy-hope-641.notion.site/Diana-a518233dc6b04ab3a369f97336d420c4?pvs=25
https://www.stampstampede.org/society-stampers/members/DI01/
https://blogzone.hellobox.co/6976396/diana
https://econarticle.com/profile/Diana01
https://www.makerist.de/users/realdoctorsnotes
https://businessleed.com/author/Diana01/
https://next.nexusmods.com/profile/Dianawalker01/about-me
https://generalmagazine.org/author/diana01/
https://theduran.com/author/diana01/
https://dictanote.co/n/1065634/
https://www.fbtb.net/author/diana01/
https://www.polywork.com/diana_walker
https://utahsyardsale.com/author/diana01/
https://www.slmath.org/people/72373
https://speakerdeck.com/dianawalker01
https://www.niftygateway.com/@dianawalker1511/
https://pantip.com/profile/8384071#topics
Geeta
19/09/2024 11:41

Comment

 

Understanding the risks and rewards of public sector cloud 

Download the Whitepaper now

Partner

24Newswire
Sign up to receive latest news