enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

City Bank

Managing Data Security and Privacy Risk In Cloud Services Arrangements

Darrell Bateman, Chief Information Security Officer, City Bank

When we utilize cloud-based services that involve sharing our own confidential data or the sensitive or private data of our customers, we are entrusting the security and privacy of this data to those cloud providers. For instance, if a cloud provider suffers a cyberattack that results in the loss or exposure of this sensitive data, both parties in the cloud services arrangement should understand their obligations in responding to and mitigating the incident. By comparison, if your own organization and its infrastructure were attacked and sensitive data was exposed, you would be obligated by state, federal, and in some cases, international law, to identify and notify the affected individuals and provide adequate relief, such as free credit monitoring. Will your cloud providers take on this responsibility for the data you entrusted to them? If the answer to this question is not clear, then you may need to take steps to ensure both parties in cloud services arrangements clearly understand their responsibilities and obligations. You may also need consider what steps can be taken to minimize the risk and impact of a data breach in your third party relationships.

Here are some tips and best practices to consider before entering into cloud services arrangements that involve the transfer, processing, or storage of sensitive data.

Classify all Data in Your Organization and Maintain a Comprehensive Inventory of Systems and Third Party Providers that Store or Process this Data

Data Classification efforts must include data flow descriptions that identify the various systems, applications, and third parties that process or store your data. For each third party in your inventory, you should know the data types, volume, retention policies, and regulatory requirements associated with the data the third party has access to.

“An Essential Element Of Any Third[1]Party Or Cloud Provider Arrangement Is An Incident Response Clause That Identifies The Third Party's Obligations In Responding To Cybersecurity Incidents”

Perform Comprehensive Vetting and Continuous Monitoring of High Risk Providers

Third party arrangements that involve large amounts of sensitive data should be considered high risk and therefore be subject to a high level of review and scrutiny with regard to their information security practices, both prior to contract signature and post contract signature through regular review and monitoring. Require your third parties to provide independent audit reports such as SOC, SIG, or certifications such as ISO or PCIDSS. Proof of regulator vulnerability scanning and penetration testing can also go a long way toward providing assurance that your third parties are maintaining a high level of security. On-going security monitoring of your third party's web presence through tools and services, such as BitSight™, SecurityScoreCard™, RiskRecon™, and others are highly useful in assessing your third party's security posture.

Consider Reducing the Attack Surface by Limiting the Data Types, Volume, and Retention of Sensitive Data

When entering into third party or cloud provider arrangements, consider the principle of Least Privilege when it comes to data sharing. Share only the minimum amounts or types of data required by the third party. Consider whether such highly sensitive data elements as Social Security Number, Name, Address, Data of Birth, etc. are actually required, or whether these fields can be tokenized with unique values that still enable functionality of the service, but reduce or eliminate the threat of identity theft if exposed in a data breach. If highly sensitive data must be shared, make full use of encryption in transit and at rest, and enforce retention policies that purge data as soon as it is no longer needed by the third party. Monitor file transfers and Application Programming Interfaces (API's) where data sharing occurs to ensure that only the expected and approved data types and volume of data are shared.

Hold Third Party Cloud Providers Accountable Through Contractual Obligations

Contracts, Terms and Conditions, Master Service Agreements, etc. are written by the third party and presented to you for your review and signature before services begin. When such arrangements involve the sharing of sensitive data, a detailed review from your legal team can help identify potential issues with Data Security and Privacy. If issues of service performance or data breach occur during the term of the agreement, the parties (and the courts if disputes arise) will look to the terms and conditions of all signed agreements to determine each parties obligations. A fair and equitable agreement should protect both parties equally and never allow one party or the other to avoid responsibility for breaches of data security and privacy. An essential element of any third party or cloud provider arrangement is an Incident Response clause that clearly identifies the third party's obligations in responding to cybersecurity incidents. Such clauses should include a timeframe for notification of the affected party, as well as the general steps the third party will take to investigate and mitigate cybersecurity incidents.

Third Party and Cloud Provider arrangements enable many benefits, but organizations need to be fully aware of the risks they can pose, particularly when it comes to data security and privacy. These issues can be further complicated when considering "fourth party" arrangements - arrangement between your third party and one or more of its own third parties. Being fully aware and properly managing third party risk can help avoid or reduce the impact of data breaches involving your cloud service providers.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.

Weekly Brief