December - 2019ENTERPRISE SECURITY| | 92. Governance and risk management: Key security challenges include identifying and implementing suitable enterprise structures, controls, and processes. These are required to maintain adequate governance in regards to information security, compliance, and risk management. Information security must include the entire information supply chain customers, providers, and third-party vendors. Enterprises deal with the challenges through well-developed processes for governing information security. The processes must scale with business operations, be replicable across the enterprise, improve continuously, sustainable, and be measurable.3. Data security and information management: Transitioning from on-site premises to cloud environments introduces new challenges in securing information. Traditional techniques for protecting information on-site are incapable of addressing challenges brought by cloud architectures, including multi-tenancy, elasticity, and abstracted controls requiring specific data security strategies. A data security life-cycle provides most of the solutions for securing data and maintaining its integrity, confidentiality, and availability. An example of a common data security lifecycle program consists of secure guidelines for creating, storing, using, sharing, archiving, and deleting data.4. Interoperability and portability: These are not new concepts in cloud computing. They allow information to be exchanged across platforms and to be processed from any device, thus increasing productivity and efficiency. However, information flow in shared cloud resources in multitenant platforms causes security challenges in preserving data integrity, confidentiality, and availability. Applications with insecure API's may be used to process data, thus increasing security risks. As a security measure, organizations rely on data encryption, and a thorough investigation of APIs used to handle data. An enterprise must also fully understand the Service Level Agreements to better comprehend their roles and those of the provider in securing information. Sophisticated cyber threats influencing security practices Cybercriminals are relentless in creating new attack tools and techniques. This has caused cybercrime to be more sophisticated, forcing enterprises to re-think their security practices.1. Increased account compromise: As the cloud positions itself as an integral technology today, cybercriminals are more determined to compromise organizational cloud accounts. Enterprises are forced to implement powerful cybersecurity policies for identifying malicious activities within their cloud environments.2. Crypto jacking: This is an attack where attackers are only interested in compromising the cloud resources processing power to mine for virtual currencies. It causes slow system response thus lowering productivity. Since the malware is often delivered through phishing, organizations must raise awareness among users regularly and conduct frequent training.To address the above threats and other sophisticated attacks, organizations are incorporating artificial intelligence in their security practices to track the threats better and respond to them in real time.Cloud security principles requiring evaluation1. Personnel security: Requires cloud provider staff to be screened and educated regarding their roles. Should be evaluated to include enterprise cloud security staff.2. Supply chain security: The provider must vet supply chain providers to ensure they satisfy security requirements. This should extend to the entire product development lifecycle as cybercriminals have taken to planting malware during the software development process. ESCloud providers and consumers play a collective role to realize maximum protection of cloud activitiesByron Aris
<
Page 8 |
Page 10 >