|By Gilad Parann-Nissany||
|July 10, 2014 11:46 AM EDT||
Cloud computing security issues are constantly a top concern for IT leaders migrating to the cloud. There are many issues related to data security in the cloud and more than one approach to cloud security. Focusing on Infrastructure as a Service cloud security, there are five issues that repeatedly concern customers that are resolved by implementing the best practices discussed at a high level below. Cloud security best practices are technology related, but also focuses on P3: Process, People, Products.
1. Choose your cloud wisely
Infrastructure clouds come in many variations. Some are big (like Amazon Web Services, Microsoft Azure, Google, or HP) and some are smaller but more focused on specific needs such as addressing compliance (Firehost and Layered Technologies are two examples, but there are many more).
A cross-platform concern in every Infrastructure as a Service (IaaS) deployment is that data security is a shared responsibility. When shortlisting cloud providers, make sure specific certification such as ISO 27001 or SOC3 are in place. If you have specific regulatory concerns such as HIPAA safe harbor or PCI DSS compliance, ensure your cloud provider can support these specific requirements. Ask to speak with customers with a similar use case and similar size (or bigger). Learn from their lessons and make a decision accordingly.
2. Encrypt your data
As we’ve written before, encryption becomes your virtual walls in a cloud deployment. In your datacenter, your physical servers are protected by the 4 walls and the tight access security policy. In a shared cloud infrastructure, those measures are basically nonexistent.
This is where data encryption steps in. Data encryption allows you to segregate and isolate your environment from other companies (or adversaries) running on the same infrastructure. Data encryption in the cloud takes multiple forms: some more secure than others.
Freeware encryption tools might seem attractive at first, but they have two major issues:
- They don’t scale well
- In many cases, the encryption key is stored on the virtual disk along with the encrypted data, which renders the entire solution useless.
In a compliance use case, these drawbacks might pose serious issues.
Research and test more than one encryption solution, and learn carefully about the security posture of the encryption provider.
3. Focus on encryption keys
Although it sounds strange at first, cloud encryption can be easily achieved. The challenge lies=s not with the actual encryption, but with the encryption keys.
The Heartbleed bug, discovered a few weeks ago, exposed a weakness in Open SSL’s SSL/TLS protocol, allowing anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. As a result, many encrypted servers in the cloud unknowingly exposed their encryption key, which resided in memory of a server impacted by heartbleed.
To mitigate with such sophisticated attack vectors, the encryption keys should be secured throughout their life cycle: while in the key management system and while in use in the cloud. Emerging technologies such as split-key encryption and homomorphic key management can be used to avoid such attacks.
When researching encryption and key management technologies, look for cloud-enabled innovative technologies, and verify how encryption keys are managed and secure throughout the life cycle of the key usage.
4. Automate cloud security as much as possible
One of the clouds’ most important benefits is its ability to automatically scale an infrastructure environment up or down, in a single geography or across multiple geographies. When it comes to cloud security, the paradigm shifts. You’ll hear experts telling you about the need to “keep security under your control,” and that security automation means sacrificing trust.
While true for traditional security systems, new – cloud based – security solutions do enable automation using secure, RESTful API tools.
Automating data security actually reduces risk and configuration mistakes. Assuming the software vendor can prove automation is done securely, it is a best practice for IaaS cloud security.
5. Train your employees
Implementing the latest and greatest security toys is fun. Training employees may not seem as exciting. Yet, in many cases, a trained employee will be more efficient in stopping an attack than most technologies. (Art Gilliland gave a great pitch on “defense in depth” during RSA 2014 – see the video here).
A common modern attack pattern would start by identifying and infiltrating privileged users’ accounts (such as database administrator, or system administrators), and once access is gained, getting to end user data stored on those databases becomes a much simpler task for the attacker.
By educating users on risks and security best practices, the access of the attacker can be avoided. In addition, the cloud brings additional potential attack vectors, such as disk snapshots, or identity theft to the online portal, managing all servers. When training employees, always keep cloud in mind, together with your business tools and processes.
Cloud Security Best Practices Lead to Successful Deployments
There are many considerations surrounding cloud security. These best practices do not eliminate the risks or remove the need to always be kept abreast of the latest development. They do, however, ensure that your cloud will be more secure and enable you to comply with laws and industry regulations while taking advantage of the many business benefits of the cloud. Much of this, when explored from such a high level seems like common sense, and yet, the news is filled with stories of companies large and small who failed to properly manage their encryption keys or permitted their employees or vendors to enable access by attackers (a la recent breaches at Ebay and Target). Implementing these best practices will ensure that yours isn’t listed among the news-making breaches.
The Jevons Paradox suggests that when technological advances increase efficiency of a resource, it results in an overall increase in consumption. Writing on the increased use of coal as a result of technological improvements, 19th-century economist William Stanley Jevons found that these improvements led to the development of new ways to utilize coal. In his session at 19th Cloud Expo, Mark Thiele, Chief Strategy Officer for Apcera, will compare the Jevons Paradox to modern-day enterprise IT, e...
Sep. 27, 2016 04:30 AM EDT Reads: 1,891
There are several IoTs: the Industrial Internet, Consumer Wearables, Wearables and Healthcare, Supply Chains, and the movement toward Smart Grids, Cities, Regions, and Nations. There are competing communications standards every step of the way, a bewildering array of sensors and devices, and an entire world of competing data analytics platforms. To some this appears to be chaos. In this power panel at @ThingsExpo, moderated by Conference Chair Roger Strukhoff, Bradley Holt, Developer Advocate a...
Sep. 27, 2016 04:15 AM EDT Reads: 1,996
In his general session at 18th Cloud Expo, Lee Atchison, Principal Cloud Architect and Advocate at New Relic, discussed cloud as a ‘better data center’ and how it adds new capacity (faster) and improves application availability (redundancy). The cloud is a ‘Dynamic Tool for Dynamic Apps’ and resource allocation is an integral part of your application architecture, so use only the resources you need and allocate /de-allocate resources on the fly.
Sep. 27, 2016 03:45 AM EDT Reads: 2,551
SYS-CON Events announced today that Bsquare has been named “Silver Sponsor” of SYS-CON's @ThingsExpo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. For more than two decades, Bsquare has helped its customers extract business value from a broad array of physical assets by making them intelligent, connecting them, and using the data they generate to optimize business processes.
Sep. 27, 2016 03:00 AM EDT Reads: 2,751
There is growing need for data-driven applications and the need for digital platforms to build these apps. In his session at 19th Cloud Expo, Muddu Sudhakar, VP and GM of Security & IoT at Splunk, will cover different PaaS solutions and Big Data platforms that are available to build applications. In addition, AI and machine learning are creating new requirements that developers need in the building of next-gen apps. The next-generation digital platforms have some of the past platform needs a...
Sep. 27, 2016 03:00 AM EDT Reads: 1,795
SYS-CON Events announced today that ReadyTalk, a leading provider of online conferencing and webinar services, has been named Vendor Presentation Sponsor at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. ReadyTalk delivers audio and web conferencing services that inspire collaboration and enable the Future of Work for today’s increasingly digital and mobile workforce. By combining intuitive, innovative tec...
Sep. 27, 2016 03:00 AM EDT Reads: 2,932
Fact is, enterprises have significant legacy voice infrastructure that’s costly to replace with pure IP solutions. How can we bring this analog infrastructure into our shiny new cloud applications? There are proven methods to bind both legacy voice applications and traditional PSTN audio into cloud-based applications and services at a carrier scale. Some of the most successful implementations leverage WebRTC, WebSockets, SIP and other open source technologies. In his session at @ThingsExpo, Da...
Sep. 27, 2016 02:15 AM EDT Reads: 1,598
Cognitive Computing is becoming the foundation for a new generation of solutions that have the potential to transform business. Unlike traditional approaches to building solutions, a cognitive computing approach allows the data to help determine the way applications are designed. This contrasts with conventional software development that begins with defining logic based on the current way a business operates. In her session at 18th Cloud Expo, Judith S. Hurwitz, President and CEO of Hurwitz & ...
Sep. 27, 2016 02:15 AM EDT Reads: 3,037
Almost two-thirds of companies either have or soon will have IoT as the backbone of their business in 2016. However, IoT is far more complex than most firms expected. How can you not get trapped in the pitfalls? In his session at @ThingsExpo, Tony Shan, a renowned visionary and thought leader, will introduce a holistic method of IoTification, which is the process of IoTifying the existing technology and business models to adopt and leverage IoT. He will drill down to the components in this fra...
Sep. 27, 2016 02:00 AM EDT Reads: 1,726
The Internet of Things can drive efficiency for airlines and airports. In their session at @ThingsExpo, Shyam Varan Nath, Principal Architect with GE, and Sudip Majumder, senior director of development at Oracle, will discuss the technical details of the connected airline baggage and related social media solutions. These IoT applications will enhance travelers' journey experience and drive efficiency for the airlines and the airports. The session will include a working demo and a technical d...
Sep. 27, 2016 02:00 AM EDT Reads: 1,730
I'm a lonely sensor. I spend all day telling the world how I'm feeling, but none of the other sensors seem to care. I want to be connected. I want to build relationships with other sensors to be more useful for my human. I want my human to understand that when my friends next door are too hot for a while, I'll soon be flaming. And when all my friends go outside without me, I may be left behind. Don't just log my data; use the relationship graph. In his session at @ThingsExpo, Ryan Boyd, Engi...
Sep. 27, 2016 01:45 AM EDT Reads: 1,292
SYS-CON Events announced today that Pulzze Systems will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Pulzze Systems, Inc. provides infrastructure products for the Internet of Things to enable any connected device and system to carry out matched operations without programming. For more information, visit http://www.pulzzesystems.com.
Sep. 27, 2016 01:30 AM EDT Reads: 1,849
SYS-CON Events announced today that Numerex Corp, a leading provider of managed enterprise solutions enabling the Internet of Things (IoT), will exhibit at the 19th International Cloud Expo | @ThingsExpo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Numerex Corp. (NASDAQ:NMRX) is a leading provider of managed enterprise solutions enabling the Internet of Things (IoT). The Company's solutions produce new revenue streams or create operating...
Sep. 27, 2016 01:15 AM EDT Reads: 2,000
If you’re responsible for an application that depends on the data or functionality of various IoT endpoints – either sensors or devices – your brand reputation depends on the security, reliability, and compliance of its many integrated parts. If your application fails to deliver the expected business results, your customers and partners won't care if that failure stems from the code you developed or from a component that you integrated. What can you do to ensure that the endpoints work as expect...
Sep. 27, 2016 12:30 AM EDT Reads: 1,634
The Transparent Cloud-computing Consortium (abbreviation: T-Cloud Consortium) will conduct research activities into changes in the computing model as a result of collaboration between "device" and "cloud" and the creation of new value and markets through organic data processing High speed and high quality networks, and dramatic improvements in computer processing capabilities, have greatly changed the nature of applications and made the storing and processing of data on the network commonplace.
Sep. 27, 2016 12:00 AM EDT Reads: 1,051
WebRTC adoption has generated a wave of creative uses of communications and collaboration through websites, sales apps, customer care and business applications. As WebRTC has become more mainstream it has evolved to use cases beyond the original peer-to-peer case, which has led to a repeating requirement for interoperability with existing infrastructures. In his session at @ThingsExpo, Graham Holt, Executive Vice President of Daitan Group, will cover implementation examples that have enabled ea...
Sep. 27, 2016 12:00 AM EDT Reads: 1,542
Major trends and emerging technologies – from virtual reality and IoT, to Big Data and algorithms – are helping organizations innovate in the digital era. However, to create real business value, IT must think beyond the ‘what’ of digital transformation to the ‘how’ to harness emerging trends, innovation and disruption. Architecture is the key that underpins and ties all these efforts together. In the digital age, it’s important to invest in architecture, extend the enterprise footprint to the cl...
Sep. 26, 2016 10:45 PM EDT Reads: 489
Fifty billion connected devices and still no winning protocols standards. HTTP, WebSockets, MQTT, and CoAP seem to be leading in the IoT protocol race at the moment but many more protocols are getting introduced on a regular basis. Each protocol has its pros and cons depending on the nature of the communications. Does there really need to be only one protocol to rule them all? Of course not. In his session at @ThingsExpo, Chris Matthieu, co-founder and CTO of Octoblu, walk you through how Oct...
Sep. 26, 2016 08:45 PM EDT Reads: 2,171
In his keynote at 18th Cloud Expo, Andrew Keys, Co-Founder of ConsenSys Enterprise, provided an overview of the evolution of the Internet and the Database and the future of their combination – the Blockchain. Andrew Keys is Co-Founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life sett...
Sep. 26, 2016 08:45 PM EDT Reads: 3,422
Vidyo, Inc., has joined the Alliance for Open Media. The Alliance for Open Media is a non-profit organization working to define and develop media technologies that address the need for an open standard for video compression and delivery over the web. As a member of the Alliance, Vidyo will collaborate with industry leaders in pursuit of an open and royalty-free AOMedia Video codec, AV1. Vidyo’s contributions to the organization will bring to bear its long history of expertise in codec technolo...
Sep. 26, 2016 05:15 PM EDT Reads: 2,628