Showing posts with label cloud security. Show all posts
Showing posts with label cloud security. Show all posts

Tuesday, July 1, 2014

Will the Cloud Soak Your Fireworks?

This week in the States, the Nation celebrates it's Independence and many people will be attending or setting off their own fireworks show. In Hawaii, fireworks are shot off more during New Year's Eve than on July 4th and there is even Daytime Fireworks now.

Cloud computing is exploding like fireworks with all the Oooooooo's and Ahhhhhhh's of what it offers but the same groan, like the traffic jam home, might be coming to an office near you.

Recently, Ponemon Institute and cloud firm Netskope released a study Data Breach: The Cloud Multiplier Effect, indicating that 613 IT and security professionals felt that deploying resources in the cloud triples the probability of a major breach. Specifically, a data breach with 100,000+ customer records compromised, the cost would be just over $20 million, based on Ponemon Institute’s May 2014 'Cost of a Data Breach'. With a breach of that scale, using cloud services may triple the risk of a data breach. It's called the 'cloud multiplier effect' and it translates to a 3% higher risk of a data breach for every 1% increase in the use of cloud services. So if you had 100 cloud services, you would only need to add 25 more to increase the possibility of a data breach by 75%, according to the study.

69% of the respondents felt that their organizations are not proactive in assessing what data is too sensitive to be stored in the cloud and 62% said that the cloud services their companies are using are not fully tested to make sure they are secure. Most, almost three-quarters, believed they would not even be notified of a breach that involved lost or stolen intellectual property/business confidential or even customer data. Not a lot of confidence there. The security respondents felt around 45% of all software applications used by the company were cloud based yet half of those had no IT visibility.

This comes at a time when many organizations are looking to the cloud to solve a bunch of challenges. At the same time, this sounds a lot like the cloud concerns of year's past - security and risk - plus this is the perception of...not necessarily the reality of what's actually occurring. It very well could be the case - with all the parts, loss of control, out in the wild, etc - that the risk is greater.

And I think that's the point. The risk.

While cloud does offer organizations amazing opportunities, what these people are saying is that companies need to do a better job at the onset, in the beginning and during the evaluations, to understand the risk of the type(s) of data getting sent to the cloud along with the specific cloud service that holds it. It has only been a few years that the cloud has been taken seriously and from the beginning there have been grumblings about the security risks and loss of control. Some cloud providers have addressed many of those concerns and organizations are subscribing to services or building their own cloud infrastructure. It is where IT is going.

But still,as with any new technology bursting with light, color and noise, take good care where and when you light the fuse.

ps

Related

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, July 23, 2013

Big Data Getting Attention

According to IBM, we generate 2.5 quintillion (2.5 followed by 17 zeros) bytes of data every day.  In the last two years, we've created about 90% of the data we have today.  Almost everything that's 'connected' generates data.  Our mobile devices, social media interactions, online purchases, GPS navigators, digital media, climate sensors and even this blog to name a few, adds to the pile of big data that needs to be processed, analyzed, managed and stored.  And you think that saving all your movies, music and games is a challenge.

This data growth conundrum is 3 (or 4 - depending on who you talk to) dimensional with Volume (always increasing amount of data), Velocity (the speed back and forth) and Variety (all the different types - structured & unstructured).  Veracity (trust and accuracy) is also included in some circles.  With all this data churning, security and privacy only add to the concerns but traditional tactics might not be adequate.

Recently the Cloud Security Alliance (CSA) listed the top 10 security and privacy challenges big data poses to enterprises and what organizations can do about them.  After interviewing CSA members and security-practitioners to draft an initial list of high priority security and privacy problems, studying the published solutions and characterizing problems as challenges if the proposed solution(s) did not cover the problem scenarios, they arrived at the Top 10 Security & Privacy Challenges for Big Data.

They are:

  1. Secure computations in distributed programming frameworks
  2. Security best practices for non-relational data stores
  3. Secure data storage and transactions logs
  4. End-point input validation/filtering
  5. Real-Time Security Monitoring
  6. Scalable and composable privacy-preserving data mining and analytics
  7. Cryptographically enforced data centric security
  8. Granular access control
  9. Granular audits
  10. Data Provenance

The Expanded Top 10 Big Data challenges has evolved from the initial list of challenges to an expanded version that addresses new distinct issues.

  1. Modeling: formalizing a threat model that covers most of the cyber-attack or data-leakage scenarios
  2. Analysis: finding tractable solutions based on the threat model
  3. Implementation: implanting the solution in existing infrastructures

The idea of highlighting these challenges is to bring renewed focus on fortifying big data infrastructures.  The entire CSA Top 10 Big Data Security Challenges report can be downloaded here.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, June 4, 2013

TechEd2013 – Secure Windows Azure Access

I meet with F5 Solution Engineer Greg Coward to talk about and demo the BIG-IP IPsec integration with Windows Azure.  To support the number of organizations embracing the Windows Azure cloud platform, Microsoft has chosen to work with F5 on integrating complementary technologies. The integration enables BIG-IP solutions to better direct, monitor, and secure application resources according to an IT team’s traffic management preferences. BIG-IP LTM provides advanced IPsec tunneling capabilities between corporate data centers and multiple Windows Azure data centers.  This approach enhances access and security capabilities across separate resource environments, while enabling application services—such as optimization and health monitoring—to be seamlessly deployed as if all cloud and data center resources were connected by the same local networking fabric.

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, May 28, 2013

FedRAMP Federates Further

FedRAMP (Federal Risk and Authorization Management Program), the government’s cloud security assessment plan, announced late last week that Amazon Web Services (AWS) is the first agency-approved cloud service provider.  The accreditation covers all AWS data centers in the United States.  Amazon becomes the third vendor to meet the security requirements detailed by FedRAMP.  FedRAMP is the result of the US Government’s work to address security concerns related to the growing practice of cloud computing and establishes a standardized approach to security assessment, authorizations and continuous monitoring for cloud services and products.  By creating industry-wide security standards and focusing more on risk management, as opposed to strict compliance with reporting metrics, officials expect to improve data security as well as simplify the processes agencies use to purchase cloud services.  FedRAMP is looking toward full operational capability later this year.

As both the cloud and the government’s use of cloud services grow, officials found that there were many inconsistencies to requirements and approaches as each agency began to adopt the cloud.  Launched in 2012, FedRAMP’s goal is to bring consistency to the process but also give cloud vendors a standard way of providing services to the government.  And with the government’s cloud-first policy, which requires agencies to consider moving applications to the cloud as a first option for new IT projects, this should streamline the process of deploying to the cloud.  This is an ‘approve once, and use many’ approach, reducing the cost and time required to conduct redundant, individual agency security assessment.  AWS's certification is for 3 years.

FedRAMP provides an overall checklist for handling risks associated with Web services that would have a limited, or serious impact on government operations if disrupted.  Cloud providers must implement these security controls to be authorized to provide cloud services to federal agencies.  The government will forbid federal agencies from using a cloud service provider unless the vendor can prove that a FedRAMP-accredited third-party organization has verified and validated the security controls.  Once approved, the cloud vendor would not need to be ‘re-evaluated’ by every government entity that might be interested in their solution.  There may be instances where additional controls are added by agencies to address specific needs.

The BIG-IP Virtual Edition for AWS includes options for traffic management, global server load balancing, application firewall, web application acceleration, and other advanced application delivery functions.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Monday, January 21, 2013

HELLO, My Name is Cloud_009...

 ...scrolls across the small 16:9 LCD protruding from my chest cavity. 

In case you missed it, I'm from the future, where we all have become our own personal cloud.  Some clouds you can actually see, like auras, but look somewhat like the classic Peanuts character Pigpen.  We've all become walking antennas, routers, hotspots and hubs for all the other personal clouds.  If auto-discovery is enabled, once you are in range of a 'friend' that you 'like,' a few beeps go off and they appear as an icon right in our own retina.  You remember those smart phones that allowed users to tap the phones to send a picture or file?  Now, all we have to do is crank up some digital audio and do a move called 'The Bump.'  It's based on some ancient 1970's fad dance where participants would lightly 'bump' hips to the beat of the music.  Today we use it to exchange data.  A bump or two and you've shared your music library.  A hip-check, your movie collection.  Passing gas is kinda like your old computer's recycle bin that you need to empty every so often.

All this works in conjunction with the IPv6 chip inserted into the freshly cut umbilical cord of every newborn, so it heals right into the system.  As you grow, the bellybutton also becomes a power source - you can interchange belly-ring connections and power almost any device with the solar plexus.  But we really do not carry 'mobile' devices anymore since their functionality is now mostly built in to our carcasses.  Our ear and earlobe have evolved to have the capability of answering calls or listening to audio just by pushing in the outer ear plug or as you used to call it, the tragus.  The earlobe itself is a highly sensitive bio-metric scanner that'll check your thumbprint and if authenticated, will unlock your car, home or any other item that you program. 

We each have a cloud identifier to distinguish our identity.  I'm Cloud_009.  I used to be Cloud_337528 but since I'm usually happy, have a strong security posture and graduated from ISO University, I was recently upgraded.  You're probably wondering if I know Cloud_007.  We've met a couple times but I try to stay away from the espionage cloud since you really don't know what you may catch in there.  Lots of infecting, crashing and drive-by Bumps. 

I'm also able to segment parts of my cloud for work and play.  Some clouds do top half/bottom half but I like to go right down the middle.  When enabled, my right side handles my work/corporate data and the left does my personal stuff.  Because I'm flexible, the percentages can adjust on the spot when the demand goes up.  From 9-5, I might use up to 80% of my cloud-body for work related computations with the other 20% reserved for bathroom breaks, eating, breathing, recharging and any other personal activities.  The data stays separate, secure and encrypted. 

Well, I got a hologram coming in that I need to watch but it was nice talking with you.  We don't do much of that anymore since most messages are sent telepathically these days.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, September 18, 2012

Hybrid–The New Normal

From Cars to Clouds, The Hybrids are Here

cornMost of us are hybrids.  I’m Hawaiian and Portuguese with a bit of English and old time Shogun.  The mix is me.  I bet you probably have some mix from your parents which makes you a hybrid.  The U.S. has been called the melting pot due to all the different ethnicities that live here.  I’ve got hybrid seeds for planting – my grass is a hybrid that contains 90% of the fescue and 10% bluegrass so bare spots grow back and also got some hybrid corn growing.  With the drought this year, some farmers are using more drought resistant hybrid crops.  There are hybrid cats, hybrid bicycles and of course, hybrid cars which has a 3% market share according to hybridcars.com.  My favorite has always been SNL’s Shimmer Floor Wax – A Floor Wax and a Dessert Topping!  Hybrid is the new normal.

Hybrid has even made it’s way into our IT terminology with hybrid cloud and hybrid infrastructures.  There are Public Clouds, those cloud services that are available to the general public over the internet; Private (Internal or Corporate) Clouds, which provides cloud hosted services to an authorized group of people in a secure environment; Hybrid Clouds, which is a combo of at least one public cloud and one private cloud; and, what I think will become the norm, a Hybrid Infrastructure or Hybrid IT, where there is a full mix of in-house corporate resources, dedicated servers, virtual servers, cloud services and possibly leased raised floor – resources are located anywhere data can live, but not necessarily all-cloud. 

This past June, North Bridge Venture Partners announced the results of its second annual Future of Cloud Computing Survey which noted that companies are growing their trust in cloud solutions, with 50% of respondents confident that cloud solutions are viable for mission critical business applications.  At the same time, scalability remains the top reason for adopting the cloud, with 57% of companies identifying it as the most important driver for cloud adoption.  Business agility ranked second, with 54% of respondents focused on agility.  They also noted that cloud users are changing their view with regard to public vs. hybrid cloud platforms.  Today, 40% of respondents’ are deploying public cloud strategies, with 36 percent emphasizing a hybrid approach and within five years, hybrid clouds will be the emphasis of 52% of respondents’ cloud strategies.  Most respondents (53%) believe that cloud computing maintains a lower TCO and creates a less complex IT.

    Earlier this year, CIO.com ran a story called, Forget Public Cloud or Private Cloud, It's All About Hyper-Hybrid, where they discussed that as more organizations adopt cloud services, both public and private, for mission critical business operations, connecting,  integrating and orchestrating the data back to the core of the business is critical but a challenge.  It’s no longer about cloud but it’s about clouds.  Multiple cloud services that must link back to the core and to each other.  Even when organizations that are cloud heavy, IT shops need to keep up the on-premise side as well, since it's not likely to go anywhere soon.  They offer 5 attributes that, if relevant to a business problem, the cloud is a potential fit: Predictable pricing, Ubiquitous network access, Resource pooling & location independence, Self-service and Elasticity of supply.

    If you are heading in the Hybrid direction, then take a look at BCW’s article from April this year called, Hybrid Cloud Adoption Issues Are A Case In Point For The Need For Industry Regulation Of Cloud Computing.  They discuss that the single most pressing issue with hybrid cloud is that it is never really yours which obviously leads to security concerns.  Even when a ‘private cloud’ is hosted by a third party, 100% control is still impossible since an organizations is still relying on ‘others’ for certain logistics.  Plus, interoperability is not guaranteed.  So a true hybrid is actually hard to achieve with security and interoperability issues still a concern.  The fix?  Vladimir Getov suggests a regulatory framework that would allow cloud subscribers to undergo a risk assessment prior to data migration, helping to make service providers accountable and provide transparency and assurance.  He also mentions the IEEE's Cloud Computing Initiative with the goal of creating some cloud standards.  He states that a global consensus on regulation and standards will increase trust and lower the risk to organizations when precious data is in someone else’s hands.  The true benefits of the cloud will then be realized.

    ps

    References:

     

    Technorati Tags: F5, cloud computing, Pete Silva, security, business, technology,ieee,cloud, compliance, regulations,silva, virtualization,dynamic data center,cloud broker,hybrid cloud,architecture,compliance,security,policy,blog

    Connect with Peter: Connect with F5:
    o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

    Wednesday, August 22, 2012

    The Venerable Vulnerable Cloud

    Ever since cloud computing burst onto the technology scene a few short years ago, Security has always been a top concern.  It was cited as the biggest hurdle in many surveys over the years and in 2010, I covered a lot of those in my CloudFucius blog series.   A recent InformationWeek 2012 Cloud Security and Risk Survey says that 27% of respondents have no plans to use public cloud services while 48% of those respondents say their primary reason for not doing so is related to security - fears of leaks of customer and proprietary data.  Certainly, a lot has been done to bolster cloud security, reduce the perceived risks associated with cloud deployments and even with security concerns, organizations are moving to the cloud for business reasons. 

    A new survey from Everest Group and Cloud Connect,  finds cloud adoption is widespread.  The majority of the 346 executive respondents, 57%, say they are already using Software as a Service (SaaS) applications, with another 38% adopting  Platform as a Service (PaaS) solutions.  The most common applications already in the cloud or in the process of being migrated to the cloud include application development/test environments (54%), disaster recovery and storage (45%), email/collaboration (41%),  and business intelligence/analytics (35%).  Also, the survey found that cloud buyers say the two top benefits they anticipate the most is a more flexible infrastructure capacity and reduced time for provisioning and 61% say they are already meeting their goals for achieving more flexibility in their infrastructures.

    There’s an interesting article by Dino Londis on InformationWeek.com called How Consumerization is Lowering Security Standards where he talks about how Mob Rule or the a democratization of technology where employees can pick the best products and services from the market is potentially downgrading security in favor of convenience.  We all may forgo privacy and security in the name of convenience – just look at loyalty rewards cards.  You’d never give up so much personal info to a stranger yet when a store offers 5% discount and targeted coupons, we just might spill our info.  He also includes a list of some of the larger cloud breaches so far in 2012.

    Also this week, the Cloud Security Alliance (CSA) announced more details of its Open Certification Framework, and its partnership with BSI (British Standards Institution). The BSI partnership ensures the Open Certification Framework is in line with international standards.  The CSA Open Certification Framework is an industry push that offers cloud providers a trusted global certification scheme. This flexible three-stage scheme will be created in line with the CSA's security guidance and control objectives. The Open Certification Framework is composed of three levels, each one providing an incremental level of trust and transparency to the operations of cloud service providers and a higher level of assurance to the cloud consumer.  Additional details can be found at: http://cloudsecurityalliance.org/research/ocf/

    The levels are:

    • CSA STAR Self Assessment: The first level of certification allows cloud providers to submit reports to the CSA STAR Registry to indicate their compliance with CSA best practices.  This is available now.
    • CSA STAR Certification: At the second level, cloud providers require a third-party independent assessment.  The certification leverages the requirements of the ISO/IEC 27001:2005 management systems standard together with the CSA Cloud Controls Matrix (CCM).  These assessments will be conducted by approved certification bodies only.  This will be available sometime in the first half of 2013.
    • The STAR Certification will be enhanced in the future by a continuous monitoring-based certification.  This level is still in development.

    Clearly the cloud has come a long way since we were all trying to define it a couple years ago yet, also clearly, there is still much to be accomplished.  It is imperative that organizations take the time to understand their provider’s security controls and make sure that they protect your data as good or better as you do.  Also, stop by Booth 1101 at VMworld next week to learn how F5 can help with Cloud deployments.

    ps

    Related:

    Technorati Tags: F5, federal government, integration, cloud computing, Pete Silva, security, business, fedramp, technology, nist,cloud, compliance, regulations, csa,internet

    Connect with Peter: Connect with F5:
    o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]