Showing posts with label Cloud Security Fundamentals. Show all posts
Showing posts with label Cloud Security Fundamentals. Show all posts

Friday, 17 January 2014

Securing Cloud Services Part 3

Practical tips

Through our many risk assessments of cloud services there a few practical tips which you may find useful in selecting the right cloud services.

        I.        Do the risk assessment early. On a number of occasions a cloud service has advanced to pilot stage prior to a risk assessment. The assessment identifies some key risks which require remediation or mitigation. The result is either a severe impact on the rollout plan or the project is abandoned.

       II.        Data classification. Make sure the business understands the need to classify the data and/or business process to ensure the appropriate security controls are understood and implemented by the cloud provider

      III.        Service availability. Ensure the cloud provider’s service recovery plan aligns with business expectations. It might be nice that a cloud provider offers a fee credit for an outage but this may be irrelevant compared to a focus on service restoration within a time period.

     IV.        Incident management. The company’s information security policies and procedures define the responsibilities, actions and reporting requirements in the event of an incident. The shift to the Cloud sees a blurring of responsibilities between the company and the cloud provider.  The service level agreement needs to reflect a clear understanding of who is responsible for taking actions in relation to a security incident and the reporting protocols.

      V.        IaaS preferred providers.  Perform a risk assessment on a select group of IaaS providers. Initially this can be achieved by a self-assessment questionnaire, security review, or confirming their compliance to industry standards or a risk management framework. Once assessed, the company then has a baseline rating for providers to recommend to business units depending on the technical controls and mapping to data integrity, availability and confidentiality needs.

     VI.        Compliance requirements. The business unit considering a cloud deployment must clearly understand the company’s own security compliance requirements and risk appetite. This needs to be conveyed to the cloud provider so it can comply with the appropriate levels of risk assessments and audits.  There can be considerable reluctance on the part of the cloud provider after deployment for testing of the provider’s applications and infrastructure if this has not been agreed upfront.

    VII.        PaaS and SaaS services. Make sure data integrity, availability and confidentiality requirements are agreed. Where possible have these services deployed on one of the IaaS preferred suppliers platforms.

   VIII.        Impact of an Outage. The increased interdependence of cloud and on premises data should not be underestimated. The impact an incident or outage of a cloud service would have on the company’s overall operation needs to be quantified and reflected in the corporate risk register.

     IX.        Cloud assessment document. Develop a cloud computing security assessment document based on the ASD document “Cloud Computing Security Considerations” and apply appropriate risk ratings. This assessment document can be completed by potential cloud providers early in a project lifecycle to avoid any unnecessary waste of time or resources on a solution which is not going to match the company’s risk profile.

Greg Starkey
Business Development Manager, Government & Commercial
www.cqr.com

Thursday, 16 January 2014

Securing Cloud Services Part 2

Cloud Security Fundamentals

Numerous surveys have found CIOs citing “security” as their main concern in adopting cloud computing technology. The Cloud is seen as an environment that is outside of the CIOs control, and from the perspective of accountability and compliance this seems to represent a risk. Security and control go hand-in-hand, and few security-conscious CIOs would be willing to cede control over core business systems until the benefits far outweigh the risks.

To convince organisations that risks have been addressed cloud vendors need to provide to their clients details on their information security management program. A number of vendors have obtained ISO27001certification for their service offerings. Moving forward this is something that will no doubt become the benchmark for serious Cloud providers. Certification, of course, does not guarantee security but at least provides an independent verification that information is governed by an international standard.

Due diligence is the key for selecting a provider. Customers should demand transparency and ask tough questions regarding risk management and technical security controls. The vendor must be able to provide assurance that any information will be adequately protected and that technical controls and security processes are subjected to regular testing. The customer should dictate the level of assurance detail provided.

So what is a good starting point for an organisation considering cloud computing solutions?  A   very concise and plain speaking document is the Australian Government ASD guide “Cloud Computing Security Considerations”. It contains a practical checklist of security considerations to maintain availability and business functionality in the Cloud. http://www.asd.gov.au/infosec/cloudsecurity.htm

For more detailed guidance and implementing the appropriate information security controls, the Cloud Security Alliance website offers much valuable information to assist organisations make the right decisions. https://cloudsecurityalliance.org/

There are some unique security considerations when it comes to cloud services which are not encountered when compared to an organisation’s on-premises operations. 

The key ones are:
·         The problem of multi-tenancy
Multi-tenancy is a term used to describe the shared use of a cloud computing resource by multiple customers.  An example of multi-tenancy might be a large database server running multiple secured databases for numerous users, or a virtual machine server running multiple instances of an operating system.

The issue with multi-tenancy in the Cloud is that a customer’s instance may be running on the same physical hardware as an attacker.  The attacker may be able to compromise shared physical resources or escape the virtual machine to execute arbitrary code on the physical host. Several VM escape vulnerabilities have been identified by security researchers. As more customers take up virtualized Cloud computing services, these technologies will come under increased hacker scrutiny and more vulnerabilities are likely to appear.

·         The chain of third parties
Cloud providers tend to work with a number of third parties. A hosted application may be on another cloud provider’s hosted infrastructure however your service level agreement is with the hosted application provider.  In the event of an incident affecting the infrastructure provider that results in loss of access to the application it may be unclear as to each provider’s responsibilities and commitments for service recovery. An organisation needs to identify with their frontline cloud provider any potential third parties involved in managing their data and ensure they answer the same key questions on information security.

·         Data security and backup
One of the first questions asked of cloud providers is - where on the global map is my data stored? The more important questions are around responsibilities for data security:

               I.        Is the provider responsible for data backups?

              II.        If a contract is terminated is there a provision for the cloud provider to       supply an export of the application data?

             III.       Does the organisation have the capability to meaningful use exported data?

             IV.       Is the provider obliged to report incidents & data breaches to the client?

Often Cloud service level agreements do not have much detail regarding backup arrangements, nor do they specify what would happen in the event of data loss or a security breach. The onus of risk for data security and backup is more than likely pushed back on the customer.

Below is an extract from a cloud provider service level agreement that CQR recently reviewed:

"Customer remains solely and fully responsible for any data, material or other content posted, hosted, stored… using the cloud provider Network or Services. Cloud provider has no responsibility for any data, material or other content created on or accessible using the cloud provider Network or Services”

·         The Virtual System Administrator
A company’s system administrator has clear responsibilities and functions for controlling user and data access. He or she abides by the company’s code of conduct and their job performance can be reviewed and subject to consequences in relation to negligent actions.  When the employee moves on the HR process kicks in to revoke their access and ensure any privileged account passwords are changed.

In the Cloud depending on the time of day and/or your location your services could be administered by one of perhaps three global teams or a provider’s helpdesk with dozens of privileged users. A request to change a user’s access or application rights may be done by email which is acted upon by one of these virtual administrators.
 
The level of risk these virtual administrators posed to the company needs to be understood. It is not unreasonable to request the cloud service to provide evidence of how they manage privileged user accounts in your environment and what are the processes to grant and revoke such privileges given inevitable staff changes.

Part 3 following tomorrow...

Greg Starkey
Business Development Manager, Government & Commercial
www.cqr.com