THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Friday, November 30, 2018
The soaring popularity of the cloud has resulted in steady adoption rates, which can be primarily attributed to no more hardware costs, long software release cycles, or the hassles of managing multiple physical data centers. As the benefits of cloud maturity come to the fore, several organizations are looking toward boarding the bandwagon to outlast the competition. The benefits of the cloud technology range from guaranteed uptime, significant savings in hardware deployment, all the way through to agility and elasticity, and being able to offload responsibility for operations. A shared-responsibility model for resilience, security, and uptime is what best describes proper cloud utilization.
However, cloud computing comes with its own set of issues that every cloud-adopter is well-aware of. The well-known research company, Gartner has captured aptly this human tendency to develop a “peak of inflated expectations” for every new disruptive technology, only later to land into the “troughs of disillusionment.” Cloud security threats are steadily on the rise with 20 percent of the cloud users facing security attacks on a daily basis, according to a recent report.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Nonetheless, the importance of security with the cloud is recognized by users leading to the relevant migration of sensitive data from private data centers. What is often overlooked is the shared-responsibility model for data security.
Generally, the security offered by cloud service providers is supported by an alphabet soup of standards like FedRAMP, CSA or SOC-based certifications. The need for security in the cloud is aligned to the need for security of the cloud, which implies that software components, processes, identities; basically all the data that resides in the cloud need to be secured. Rather than being the responsibility of the service provider, these elements are above the service boundary and hence the onus falls on the cloud consumers.
Cloud service providers mostly provide a service ‘control plane’, which includes APIs to help customers deploy and manage cloud services. In certain cases, a set of security-related services may accompany the cloud applications or services deployed in the cloud. This seems to be a pretty straightforward solution, which actually is not the case as the major security issue lies with the individual user who is working with the cloud as an on-premise environment.
Virtualization of networking and infrastructure, within a cloud environment, is implicit in the architecture itself. A level of dynamism is provided that can be difficult to replicate with on-premise environments. However, there is a fat chance that the cloud administrator can expose data within a given cloud service to the public internet; either by accident, malicious intent or via the compromise of a cloud administrator’s credentials by some rival.
Even though cloud providers are not directly responsible for a customer’s security in the cloud; however, they can help users navigate security in this complex domain. From a broad perspective, customers should ensure the following from their cloud providers. Security services should be externalized as independent cloud services, relinquishing the need for cloud developers altogether. Embedded security technologies need to be configured and operated by a customer in the cloud. The tools to monitor access to enterprise resources whether cloud or on-premise should be sufficient to tackle the ‘slow and low’ nature of modern threats, rather than mere prevention. Utilizing today’s hybrid cloud environment is the last step as it amplifies the downsides of any mistakes and reinforces the need for end-to-end visibility wherever identities and assets exist.
The occurrence of cloud outages isn’t uncommon and the dark truth is that even the service providers do not have a definite answer to this. Cloud outages cannot be avoided completely but taking certain steps can go a long way in preventing frequent occurrences. The cloud design should support the resilience level of the availability zones. The cloud infrastructure should be tested periodically to counter future fault scenarios. Lastly, it is important to have a backup plan for recoverability from cyber attacks. Unlike traditional causes of outages like human error or equipment failure, cyber events tend to target the prevention of recovery attempts.
The cloud security control framework is an approach that is based on certain basic principles. Clarity on the division of security responsibilities between cloud consumer and provider augmented with a robust approach to dealing with the risk that resides in the cloud. Companies with security strategies that can promote a cataclysmic reaction for the organization’s cloud initiatives, which are aided by an approach to risk and compliance both of and in the cloud, are benefiting, and steamrolling ahead. On the other hand, traditional organizations lacking a deeper understanding of key security aspects of the new paradigm will not realize full benefits of the cloud, or that it would drive cloud usage underground, opening the organization up to new risks. To sum up, transparency is the much-needed key to drive the security framework for the cloud.
More in News