| | ENTERPRISE SECURITY8 DECEMBER - 2021IN MY OPINIONIN MY OPINIONBy Shew McGrew, Director, Enterprise Data Center, and Lester Godsey, Chief Information Security and Privacy Officer, Maricopa CountyWHY CLOUD SERVICES SHOULD DRIVE YOUR ENTERPRISE SECURITY ARCHITECTURE Even though cloud computing services have been around since the mid-2000s, it's surprising that some organizations still don't invest the same level of security planning into cloud services as they do with traditional on-premise services. This article will explore why this is critical for all enterprises moving forward, what are some of the challenges, and what we can do to rectify this. The Why: What's so crucial about enterprise security architecture in the cloud? This goes back to January 2006 when Gartner introduced the idea of adding security in the Enterprise Architecture framework to help identify and reduce risk across an organization. Since then, security professionals have developed practices, such as perimeter protection and defense-in-depth, that allow organizations to defend their assets and minimize risk while inside the network. But even on-prem, with a strong perimeter, one cannot achieve absolute security. So, where to focus one's efforts? The Enterprise Security Architecture framework recommends concentrating on value and vulnerability. Where do the most valuable and vulnerable corporate assets exist? According to Techjury.net, cloud services in 2010 were valued at $24.65 billion and are projected by the end of 2020 to reach $150 billion. This investment level shows that organizations are flocking to cloud services, not just for application development needs. The cloud is now a go-to for production business processes and end-user consumption. This, coupled with the escalated adoption of cloud services due to COVID-19, points to the cloud containing not only our most valuable assets Lester Godsey
<
Page 7 |
Page 9 >