Question everything: considerations to raise with your cloud service provider What information do you need to obtain from your cloud provider when it comes to the protection of business-critical data? By Stephen Coty. The cloud has well and truly arrived. It's scalable, flexible, cost-effective and offers the huge convenience of not having physical on-site hardware to maintain. However, while these benefits certainly are compelling, these are the only considerations to take into account when undergoing a cloud project. Companies need to do their homework and think about the scale and type of information that will reside within a cloud provider’s infrastructure and give weight to the security of that data. This is for a number of reasons: The same type of attacks typical to on-premise data centre/center environments are moving to the cloud: what used to be historically on-premise based attacks, such as malware, botnet and brute force attacks, are now targeting cloud environments. A big driver for this is that businesses are starting to deploy traditional enterprise applications like ERP and virtual desktop infrastructure (VDI) in the cloud. Hackers that see this happen run vulnerability scans and brute force attacks, that attempt to siphon valuable company data, in hopes of finding and taking advantage of lax security policies in the cloud. Furthermore, as more end user applications move to the cloud, malware and botnet attacks follow suit. The breadth and depth of attacks means that threat diversity in the cloud is on the rise: threat diversity is basically a measurement of how many different types of attacks exist and companies are facing. This year, threat diversity in the cloud increased to rival that of on-premise data centres. This means that companies need to be just as vigilant with the same security sophistication in the cloud that would normally apply to protect an enterprise’s on-premise data centre. The point solutions typically relied upon to combat these threats are not enough: to gauge the effectiveness of security solutions, such as anti-virus protection, in major public clouds around the world, new patterns of attacks and emerging threats were observed through a honeypot project. One particularly interesting and disturbing observation was that 14 percent of the malware collected was considered undetectable by 51 of the world’s top anti-virus vendors. Despite this stark reality, it is certainly not to say that businesses should stop using the cloud: there are just way too many benefits. The good news is that there is a lot that organizations can do to protect themselves in the cloud; and the first step is to get educated on what their businesses and applications require from a compliance and security perspective. The following guide to the questions you should be asking your service provider when it comes to security in the cloud is a good starting point. Make sure that the cloud service provider can answer these questions confidently and comprehensively so you feel assured that it takes the security of your business-critical data seriously: 1. What is their data encryption strategy and how is it implemented? 2. What is the hypervisor and provider infrastructure patching schedule? 3. How do you isolate and safeguard my data from other customers? 4. How is user access monitored, modified and documented? 5. What regulatory requirements does the provider subscribe to? 6. What is the provider’s back-up and disaster recovery strategy? 7. What visibility will the provider offer your organization into security processes and events affecting your data? While this is not an exhaustive list of the questions you want to be asking a cloud service provider about the security of sensitive information residing in the cloud, it is a good base point. The answers can help you match your expectations with cloud platforms that fit your criteria to help you implement the right coverage of products, security threat intelligence, analytics/correlation and people to watch over your business critical applications and data. They will help you quickly judge how seriously they take the security of the data that backs and fuels your business and how safe your data will be with the cloud service provider. The author Stephen Coty is chief security evangelist for Alert Logic. •Date: 10th July 2014 • World •Type: Article • Topic: Cloud computing
|
To submit news stories to Continuity Central, e-mail the editor. Want an RSS newsfeed for your website? Click here |
||||||||