Welcome!

Containers Expo Blog Authors: Elizabeth White, Liz McMillan, Yeshim Deniz, Pat Romanski, Amit Gupta

Related Topics: Cloud Security, @CloudExpo

Cloud Security: Article

A Service Auditor’s Letter to the Cloud

As an auditor (and former auditee), I will never be complacent about cloud security

SAS 70 Solutions Session at Cloud Expo

Dear Cloud:

Hello! Can you hear me? I know you can. Yes, yes...no one likes an auditor and I am even worse. I am that CPA who spent the last decade working in information security, both as a security consultant and as someone who managed the product lines of a global managed services business. So whether or not you want to open up those big APIs of yours and listen to me, this is what I have to say...

I know who you are and where you live.

Your name is "the cloud." I will admit that you are the catchiest IT buzzword since Java. Although you claim to live in the gated community called Web 2.0, I know better. You actually live in an unmarked windowless datacenter, with complex networks, servers, applications, policies, contracts, and worst of all, people!

You are unique, just like everyone else.

Your predecessors, such as the ASP, SaaS, and MSSP providers, have been providing customers with a vast array of multi-tenant solutions using the same underlying technology we now call "the cloud" for over a decade. I know because I was responsible for a managed security platform and your shared architecture model was our only path to profitability. From where I am standing, you look a lot like your predecessors, the only major exception being the amount of publicity you get from technology marketers as well as the security community as evidenced by the RSA Security Conference a few weeks ago.

You can be audited.

I have never met a technology that could not be audited...and you aren't going to be the first. Although I believe that many of my traditional methods are sufficient to gauge your control environment, my auditor and security friends are feverishly issuing new methods for assessing you. With time, there will be an army of IT auditors who will find very little about you to be "cloudy."

Like it or not... SAS 70 is the most widely adopted approach for Cloud Assurance

You know I work for a SAS 70 audit company. I do not claim independence on this matter. But lacking independence does not inherently make me wrong. You will also agree that there is no generally accepted standard for auditing you.

Contrary to what the security consultants tell you, Statement on Auditing Standard (SAS) No. 70 is not a weak security standard. It is not a security standard at all! It contains no mention of encryption, network segmentation, or password settings. It is, in fact, an auditing standard. Rather than attempt to tell you what to do, the standard tells you how to describe your services and related controls and tells me how I should test that description for the purposes of issuing results and an opinion. Security topics are normally included in the scope of SAS 70 audits (the extent of which is up to you, cloud), but security is not the primary objective of the audit. My security consulting friends continue to give themselves heartburn over this misconception.

What about the others standards and certifications?

ISO 27001 certification is sometimes mentioned as an alternative. However, with less than 100 certified companies in the United States, this certification has yet to hit mainstream service providers. Make no mistake, aligning with ISO 27001 and ISO 27002 will be both comprehensive and resource intensive. Vendor-specific certifications and seals are great for their specified purposes, but you must remember that they are focused on gauging compliance with static criteria. Such standards are prone to miss the forest for the trees and will disregard worthwhile controls beyond those contemplated by the standard.

PCI cannot provide cloud assurance either as it has a very specific application for providers who process or store credit card data. It is also a prescriptive standard, well liked by the security community but prone to the same cost issues as the ISO 27001/2 standards, which is why providers work so hard to reduce their card data footprints. The good news is that you can incorporate those commodity controls (such as physical security, access control, etc.) for PCI and other such standards into the SAS 70 audit scope such that if you have a comprehensive set of controls, you can potentially save significant time and assessment fees.

Why is SAS 70 more adopted than the others? One, it can adapt to your environment without excessive compliance cost that your end customers have not shown a willingness to share. In addition, it has utility. Only the SAS 70 audit can be leveraged for the purposes of customer assurance, financial auditor, Sarbanes Oxley compliance, regulators, and more. Last and unlike other assessments, the SAS 70 audit is regulated by both law and professional standards, so don't believe for a second that this is an easy undertaking for someone who maintains a CPA license along with CISSP, QSA, and other certifications!

There is always room for improvement.

As an auditor (and former auditee), I will never be complacent about cloud security. I was very excited about the Cloud Security Alliance announcement of the cloud controls matrix at RSA and anxiously await its release. I am also an active participant with Chris Hoff in the newly formed CloudAudit group. Even the AICPA and ISACA are working to make strides by updating their standards and modernizing with offerings such as WebTrust and SysTrust and an update to SAS 70 (SSAE 16), which also includes an international counterpart (ISAE 3402).

You see Cloud, it is unlikely that I will write any new standards, but I will contribute to groups that are focused on harnessing your potential (and addressing your risks). Most important, my day-to-day efforts will be focused on helping my clients understand, improve, and communicate the state of their internal controls to whoever needs to know and all within the bounds of economic reasonableness.

In the meantime, see you at 20,000 feet!

Yours Truly,

Doug

P.S. Want to discuss cloud assurance? Come find us at the 5th International Cloud Computing Expo in New York City. We will be at the SAS 70 Solutions booth in the exhibit hall and I am also presenting "Cloud Computing? There's an Audit for That!" on the Hot Topics! track (http://cloudcomputingexpo.com/event/session/768). Come by the booth or the presentation to register for a drawing for $200+ gift cards from Apple, American Express and more!

More Stories By Douglas Barbin

Doug Barbin is a Director at SAS 70 Solutions, a company that provides assurance and technology compliances services with an emphasis on SAS 70 audits, PCI validation, and ISO 27001/2 compliance. After starting his career with a "Big 4" global accounting firm, Doug has spent the last ten years working in the trenches of a wide variety of information security topics, and thus, understands the perspective of both the security consultant and the managed services / SaaS provider. Prior to joining SAS 70 Solutions, Barbin was Director of Product Management for VeriSign's Managed Security Services business, where he was responsible for the MSS "SaaS" platform architecture and compliance (including overseeing the conduct of the SAS 70 audit, PCI validation, and other types of compliance assessments). Prior to that, Doug was in charge of VeriSign's western US security consulting practice, where among other projects, he led some of the prototype PCI assessments. He has BS degrees in Accounting and Criminal Justice from Penn State University and an MBA from Pepperdine University.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@ThingsExpo Stories
SYS-CON Events announced today that IBM has been named “Diamond Sponsor” of SYS-CON's 21st Cloud Expo, which will take place on October 31 through November 2nd 2017 at the Santa Clara Convention Center in Santa Clara, California.
Infoblox delivers Actionable Network Intelligence to enterprise, government, and service provider customers around the world. They are the industry leader in DNS, DHCP, and IP address management, the category known as DDI. We empower thousands of organizations to control and secure their networks from the core-enabling them to increase efficiency and visibility, improve customer service, and meet compliance requirements.
SYS-CON Events announced today that TidalScale will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. TidalScale is the leading provider of Software-Defined Servers that bring flexibility to modern data centers by right-sizing servers on the fly to fit any data set or workload. TidalScale’s award-winning inverse hypervisor technology combines multiple commodity servers (including their ass...
As hybrid cloud becomes the de-facto standard mode of operation for most enterprises, new challenges arise on how to efficiently and economically share data across environments. In his session at 21st Cloud Expo, Dr. Allon Cohen, VP of Product at Elastifile, will explore new techniques and best practices that help enterprise IT benefit from the advantages of hybrid cloud environments by enabling data availability for both legacy enterprise and cloud-native mission critical applications. By rev...
Join IBM November 1 at 21st Cloud Expo at the Santa Clara Convention Center in Santa Clara, CA, and learn how IBM Watson can bring cognitive services and AI to intelligent, unmanned systems. Cognitive analysis impacts today’s systems with unparalleled ability that were previously available only to manned, back-end operations. Thanks to cloud processing, IBM Watson can bring cognitive services and AI to intelligent, unmanned systems. Imagine a robot vacuum that becomes your personal assistant tha...
As popularity of the smart home is growing and continues to go mainstream, technological factors play a greater role. The IoT protocol houses the interoperability battery consumption, security, and configuration of a smart home device, and it can be difficult for companies to choose the right kind for their product. For both DIY and professionally installed smart homes, developers need to consider each of these elements for their product to be successful in the market and current smart homes.
In his Opening Keynote at 21st Cloud Expo, John Considine, General Manager of IBM Cloud Infrastructure, will lead you through the exciting evolution of the cloud. He'll look at this major disruption from the perspective of technology, business models, and what this means for enterprises of all sizes. John Considine is General Manager of Cloud Infrastructure Services at IBM. In that role he is responsible for leading IBM’s public cloud infrastructure including strategy, development, and offering ...
SYS-CON Events announced today that N3N will exhibit at SYS-CON's @ThingsExpo, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. N3N’s solutions increase the effectiveness of operations and control centers, increase the value of IoT investments, and facilitate real-time operational decision making. N3N enables operations teams with a four dimensional digital “big board” that consolidates real-time live video feeds alongside IoT sensor data a...
In a recent survey, Sumo Logic surveyed 1,500 customers who employ cloud services such as Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). According to the survey, a quarter of the respondents have already deployed Docker containers and nearly as many (23 percent) are employing the AWS Lambda serverless computing framework. It’s clear: serverless is here to stay. The adoption does come with some needed changes, within both application development and operations. Tha...
SYS-CON Events announced today that Avere Systems, a leading provider of enterprise storage for the hybrid cloud, will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Avere delivers a more modern architectural approach to storage that doesn't require the overprovisioning of storage capacity to achieve performance, overspending on expensive storage media for inactive data or the overbui...
With major technology companies and startups seriously embracing Cloud strategies, now is the perfect time to attend 21st Cloud Expo October 31 - November 2, 2017, at the Santa Clara Convention Center, CA, and June 12-14, 2018, at the Javits Center in New York City, NY, and learn what is going on, contribute to the discussions, and ensure that your enterprise is on the right path to Digital Transformation.
SYS-CON Events announced today that mruby Forum will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. mruby is the lightweight implementation of the Ruby language. We introduce mruby and the mruby IoT framework that enhances development productivity. For more information, visit http://forum.mruby.org/.
Digital transformation is changing the face of business. The IDC predicts that enterprises will commit to a massive new scale of digital transformation, to stake out leadership positions in the "digital transformation economy." Accordingly, attendees at the upcoming Cloud Expo | @ThingsExpo at the Santa Clara Convention Center in Santa Clara, CA, Oct 31-Nov 2, will find fresh new content in a new track called Enterprise Cloud & Digital Transformation.
SYS-CON Events announced today that NetApp has been named “Bronze Sponsor” of SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. NetApp is the data authority for hybrid cloud. NetApp provides a full range of hybrid cloud data services that simplify management of applications and data across cloud and on-premises environments to accelerate digital transformation. Together with their partners, NetApp emp...
Smart cities have the potential to change our lives at so many levels for citizens: less pollution, reduced parking obstacles, better health, education and more energy savings. Real-time data streaming and the Internet of Things (IoT) possess the power to turn this vision into a reality. However, most organizations today are building their data infrastructure to focus solely on addressing immediate business needs vs. a platform capable of quickly adapting emerging technologies to address future ...
Amazon is pursuing new markets and disrupting industries at an incredible pace. Almost every industry seems to be in its crosshairs. Companies and industries that once thought they were safe are now worried about being “Amazoned.”. The new watch word should be “Be afraid. Be very afraid.” In his session 21st Cloud Expo, Chris Kocher, a co-founder of Grey Heron, will address questions such as: What new areas is Amazon disrupting? How are they doing this? Where are they likely to go? What are th...
Most technology leaders, contemporary and from the hardware era, are reshaping their businesses to do software. They hope to capture value from emerging technologies such as IoT, SDN, and AI. Ultimately, irrespective of the vertical, it is about deriving value from independent software applications participating in an ecosystem as one comprehensive solution. In his session at @ThingsExpo, Kausik Sridhar, founder and CTO of Pulzze Systems, will discuss how given the magnitude of today's applicati...
Join IBM November 1 at 21st Cloud Expo at the Santa Clara Convention Center in Santa Clara, CA, and learn how IBM Watson can bring cognitive services and AI to intelligent, unmanned systems. Cognitive analysis impacts today’s systems with unparalleled ability that were previously available only to manned, back-end operations. Thanks to cloud processing, IBM Watson can bring cognitive services and AI to intelligent, unmanned systems. Imagine a robot vacuum that becomes your personal assistant th...
SYS-CON Events announced today that SkyScale will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. SkyScale is a world-class provider of cloud-based, ultra-fast multi-GPU hardware platforms for lease to customers desiring the fastest performance available as a service anywhere in the world. SkyScale builds, configures, and manages dedicated systems strategically located in maximum-security...
SYS-CON Events announced today that Avere Systems, a leading provider of hybrid cloud enablement solutions, will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Avere Systems was created by file systems experts determined to reinvent storage by changing the way enterprises thought about and bought storage resources. With decades of experience behind the company’s founders, Avere got its ...