enterprisesecuritymag

ENTERPRISE SECURITY| | 9DECEMBER - 2021but perhaps our most vulnerable ones. According to the 2020 Trustwave Global Security Report, attacks on cloud services doubled in 2019 from 2018 and made up 20% of investigated incidents. It's a safe assumption that as the use of cloud services increases, so will the attacks on them. We are dealing with a way of conducting business that we cannot afford to ignore when it comes to enterprise security architecture.The Issues:The ease in which cloud services are procured/consumed and the abstracted nature in which they are offered are the first hurdles. Instead of having a traditional server layer where all servers of a particular type are located together and configured to perform specific actions, we now have IaaS, PaaS and serverless solutions for applications. Enterprise cloud service management, especially infrastructure and platform services, is substantially different from that of local networks. In the case of an Apache web server, no longer are we responsible for the whole Linux, Apache, MySQL and PHPstack. We click a couple of boxes, fill out some information, and suddenly have a web server ready for production. Many Infrastructure and DevOps Engineers have become accustomed to the traditional network perimeter providing protection, resulting in never having to think twice about security for deployments inside the network. Now they are working in a world that blurs the lines between inside and outside the network.Another challenge related to the ease of providing these services is large, highly decentralized and/or widely dispersed organizations struggle to control the creep of services outside the network. Regardless of organization structure, virtually all organizations have and are currently struggling with departments procuring cloud services with little to no guidance from their technology teams. Often all it takes is someone with an internet connection and a credit card to set up cloud payment services. Without various cloud controls in place, all one will see through traditional firewalls is increased port 80 and 443 traffic. The ubiquitous nature of cloud services is that they are simple to procure and can be challenging to manage, leading to various levels of potential risk to one's organization, much of which may be unknown.What We Can Do: Continue to focus on the basics. The concept of managing risk applies the same to cloud services as it does with on-prem ones, but our approach might be different. If a prerequisite of risk management is knowing what's in one's environment, then we need to know what cloud services are in use. How can we manage/inventory cloud services? Technologies like CASB (cloud access service broker) can help organizations gain insight into what cloud services are being used. What about next-generation firewalls? Sure, some can tell at an application level, as opposed to port/protocol, what is coming in and going out, linking cloud services to enterprise usage. However, what about cloud services that are used by staff that never traverse the corporate firewall? Without a service/system perspective in designing and analyzing enterprise networks, organizations would continue to look at the parts that make up a service instead of the sum of those parts. Cloud services have effectively turned the traditional model of security zones on its head. From a security perspective, how should we be designing enterprises? Architecturally, we must understand all points of ingress/egress in our network, keeping in mind that the very definition of 'network' is an amalgamation of traditional on-premise technology and cloud services. From a design perspective, micro services might be employed for development purposes or software-defined networks might be the way that your organization intends to provide secure access to services. These all need to be taken into consideration before a proper security architecture can be identified and implemented. Cloud services bring a whole new way of delivering services to the enterprise, and while this poses its challenges in designing security, the approach we take today doesn't need to change. An awareness of how these services are consumed and the generated risks are still required to provide security architecture for our cloud-dominated future. ESCloud services bring a whole new way of delivering services to the enterprise, and while this poses its challenges in designing security, the approach we take today doesn't need to changeShew McGrew
< Page 8 | Page 10 >