enterprisesecuritymag

| | December - 2019ENTERPRISE SECURITY8he cloud is one of the most revolutionary technologies of our times. Today, at least 81% of enterprises cutting across all industries have implemented cloud strategies, while 67% will have based all their infrastructure in cloud platforms. This is a huge number by all means, and it has led to an increase of cybercrimes targeting cloud users. Enterprises hence require to understand cloud security concerns, how they impact their security practices, and their responsibilities in providing security to their cloud environment.Cloud security is a shared responsibility Cloud consumers and providers share the responsibilities of securing the cloud. Users access cloud services through shared infrastructure and software. The providers have the responsibility of securing all shared infrastructure. This includes firewalls, hypervisors, load balancers, cloud APIs, storage networks, etc. Implemented security measures ensure multitenancy does not allow malicious users to access the data and infrastructure used by others.On their part, cloud consumers manage all security aspects related to the cloud platforms. Enterprises must ensure that employees observe sufficient security practices to prevent security incidences caused by ignorance and simple mistakes. As such, an organization must ascertain employees use secure devices to connect to their cloud accounts, and they maintain efficient password management practices. Notwithstanding, enterprises should adopt acceptable controls for authorizing and authenticating users. They are also responsible for encryption techniques to secure data at rest and in transit. All said and done, cloud providers and consumers play a collective role to realize maximum protection of cloud activities. The image below depicts the security responsibilities of both cloud users and providers. Cloud security architectures Enterprises access cloud resources and services at three levels. These are infrastructure as a service (IaaS), platform as a service (PaaS), and software as a service (Saas). The shared security responsibilities must cut across all three models for efficient security. The following figure is a representation of a typical cloud security architecture.In IaaS security, cloud providers secure infrastructure and abstraction layers. SaaS security is a collaboration between service providers and cloud users. Whereas the provider provides security for most of the PaaS model, the enterprise has to ensure security for applications accessed through the cloud platforms.Enterprise's response to security challengesCloud security has a lot of challenges that an enterprise must navigate to conduct business functions. Here are some of the challenges and the means organizations respond to ensure global business functions.1. Audit and compliance: Enterprises must maintain compliance regulations when using cloud services. This introduces challenges in evaluating cloud security compliance with its internal security needs and policies.It Ischallenging to deliver, measure, or communicate compliance due to the numerous compliance requirements spread across different jurisdictions. Besides, whenever audited, an enterprise must be able to prove full compliance at any given time. Since non-compliance attract hefty fines, not to mention the lack of proper security controls, organizations conduct assurance campaigns aimed at creating awareness for observing compliance regulations. They also use compliance management tools which are offered through software applications.Protecting The Cloud: Industry Perspectives on Cloud SecurityBy Byron Aris, Vice President, Cloud Security Advisor, SunTrust, (NYSE: STI)TIn My Opinion
< Page 7 | Page 9 >