Skip to main content

E-Book: Securing the Cloud

Page 1

Securing the Cloud: A Comprehensive Guide to Security Best Practices in a Shared Responsibility Model AN E-BOOK BY ADAPTURE

2

ADAPTURE /// Securing the Cloud


Contents

4

6

Securing the Cloud

8

A More Secure Infrastructure

12

A More Secure Facility

14

Your Responsibility in the Public Cloud

18

Your Cloud Security and How to Improve It

24

About Us

ADAPTURE /// Securing the Cloud


Securing the Cloud

No one wants to be the next big breach—to get hacked and have private data plastered across the internet. As many of us have seen, even one cloud-based hack can severely alter the trajectory of a company’s profitability and success. It can be difficult not to let the media taint your opinion of cloud-based technologies; breaches like Target, Equifax, and Yahoo have left many executives nervous.

FEAR IS NOT ALWAYS A BAD THING Are you one of those who harbor a mistrust of cloud? Do you think your data is just “up there for everyone to hack”? There’s a lot of conflicting advice out there. One side declares that on-premise infrastructure is the most sure-fire way to secure your assets; the other contends that cloud environments are the best way to go. Each has a litany of well-researched (and sometimes not-sowell-researched) reasons for their opinions; and, as with many debates in the tech industry, there are misconceptions on both sides.

6

ADAPTURE /// Securing the Cloud


Know that the big picture of your security concerns are valid—having a healthy fear of both external and internal threats is valuable in inspiring your company toward better security practices. But many of these misconceptions only hinder your company’s technical progression. Quit being afraid what you don’t know—and become informed.

COMPARING PRIVATE AND PUBLIC CLOUD Some companies operate under the assumption that private cloud is safer because it grants them more control over their on-premise environments, and it keeps their sensitive data “closer to home.” Because of this confidence, they continue to sustain their operations predominantly on-premise, not realizing that their security measures are not as resilient as they believe.


A More Secure Infrastructure

Contrary to some beliefs, public cloud offers more comprehensive security than many private cloud environments are capable of. This is due, in part, to public cloud’s intrinsically robust infrastructure.

Permissions and Access When it comes to your private cloud environment, hardware technicians often retain a higher level of access than necessary. Because on-site admins manage both hardware and software, they can also grant themselves the highest levels of access at all times. Yes, it’s lazy IT, but it’s “easier” to have open access than it is to scale for whatever projects come down the pipeline. The vulnerabilities this causes, however, are self-explanatory. In contrast, when it comes to high-level permissions and access, public cloud providers fully separate hardware and software operations. Their rigid management structures prevent public cloud personnel from having any access to data and applications. This enables full-control, in real-time, of the elevation of permissions for each individual or group, according to the duration of the project that is being executed.

8

ADAPTURE /// Securing the Cloud


A More Secure Infrastructure

Data is Inaccessible at Rest When you leverage public cloud, you can easily enable data encryption, making your data what ADAPTURE security experts call “inaccessible at rest” to unauthorized personnel. In this way, public cloud vendors ensure your data and all other virtual assets are encrypted from all sides—and you alone have the decryption key. So, even when public cloud technicians work on the underlying storage systems, they are unable to manipulate, leverage, or make use of your critical data. The same goes for the data center’s hardware technicians who maintain the physical compute infrastructure; they do not have root access to the virtual machines running within. Most importantly, these restrictions apply to cybercriminals as well. If someone hacks into the system, it’s impossible to just browse around your infrastructure and look at open data. Your virtual machines (known as “instances” in the cloud) are individually keyed on the backend, and each requires its own unique key pair in order to be decrypted.

10

ADAPTURE /// Securing the Cloud


Loosely-Coupled Environments Public cloud further thwarts malicious attacks by making hacking a major inconvenience. If someone breaks in—and then somehow manages to crack a key pair for one instance—that person will only have access to a very small portion of the larger application. Your environment is less likely to be compromised because public cloud’s loosely-coupled architecture makes “reassembling” the fragmented pieces even more difficult. The number of instances that a hacker would need to discover, decrypt, and reassemble (to simply gain visibility inside the application) is extremely daunting.


A More Secure Facility

Public cloud’s infrastructure is architected to be more secure from every angle. And its physical facilities and data centers are built with the same integrity in mind.

Security Through Obscurity Public cloud’s data centers are strategically distributed across the globe1 to provide comprehensive regional services and support for their clients. However, for increased security, these data centers are often constructed in obscure, highly-remote areas, and their exteriors are built with discretion in mind (there is often no identification as to what company or infrastructure resides within the warehouse2). Nondescript, remote facilities are meant to draw as little attention as possible. This surreptitious layering of structural security on top of existing cybersecurity protocols circumvent potential physical attacks.

A Security Team with One Job to Do These facilities also provide state-of-the-art multi-layered security systems that minutely control who has physical access to the building itself and to the more critical areas within. Security clearances are strictly enforced within the data center, employees are carefully vetted, and the server rooms are highly guarded.

12

ADAPTURE /// Securing the Cloud


Most importantly, public cloud providers keep highly-specialized security teams on staff to monitor the premises 24/7. They have one job only: to protect and secure the infrastructure.

YERBURY, RACQUEL (2016). “REGIONS BEYOND REGIONS: GLOBAL CLOUD INFRASTRUCTURE EXPANSIONS.” FUGUE. HTTPS://BLOG.FUGUE.CO/2016-04-12-REGIONSBEYOND-REGIONS-GLOBAL-CLOUD-INFRASTRUCTURE-EXPANSIONS.HTML 1

BURRINGTON, INGRID (2016). “WHY AMAZON’S DATA CENTERS ARE HIDDEN IN SPY COUNTRY.” THE ATLANTIC. HTTPS://WWW.THEATLANTIC.COM/TECHNOLOGY/ ARCHIVE/2016/01/AMAZON-WEB-SERVICES-DATA-CENTER/423147/ 2


Your Responsibility in the Public Cloud

Public cloud provides cutting edge encryption and security. You enjoy th maintain and protect your assets. But that doesn’t mean that you shoul

ADAPTURE experts warn that public cloud security is a shared respo essential to learn the lines of “security responsibility.”

SOFTWARE AS A SERVICE (SAAS) With SaaS, the end-user can only access the cloud at the application level. As such, the end user’s required to manage authorization, entitlements, and identity management, but little else. As a result, the SaaS cloud provider is responsible for securing all other aspects of the environment. This broadly includes: »» Perimeter security »» Logging/monitoring/auditing security »» Application security

PLATFORM AS (PAA

PaaS requires a ma responsibility from the e overall security burden While the PaaS cloud pr for the platform’s secur fully responsible for e implement within that includes the configur security features as we of accounts and authe The PaaS vendor is still e

»» Fundamental sec »» Patching

»» Core configuratio 14

ADAPTURE /// Securing the Cloud


he benefits of having highly-specialized teams that work specifically to ld set your security on “auto pilot.”

onsibility. You might be accountable for more than you think, so it is

S A SERVICE AS)

arginal increase of end-user, making the n a rough 50-50 split. rovider is responsible rity, the cloud user is everything that they t environment—this ration of database ell as the managing entication methods. expected to provide:

curity

on

INFRASTRUCTURE AS A SERVICE (IAAS) IaaS places significantly more security liability on the cloud user than SaaS or PaaS. While IaaS providers are still responsible for the foundational hardware security of the platform, the cloud user is now responsible for everything that is built on top of that infrastructure. IaaS providers will: »» Secure the physical data base locations »» Monitor perimeter for attacks The cloud user remains fully responsible for the implementation and monitoring of the individual cloud environment security— including patching and securing the OS.


Your Responsibility in the Public Cloud

Each platform is different, so don’t let ignorance be the cause of your next security breach. Firmly establish the line between where your vendor compliance ends and your responsibility begins. ADAPTURE experts recommend that you establish documentation that clearly defines what each party is accountable for.

»» From the Cloud Provider: Obtain clear documentation that delineates the provider’s security offerings, the internal security tools that can be implemented by the user, and an explanation of included SLAs. »» For the Cloud User: Establish an internal “responsibilities matrix” that includes a detailed account of all implementation security controls and compliance standards required for each cloud project. Now that you’ve established responsibilities, it’s time to implement the security measures themselves.

16

ADAPTURE /// Securing the Cloud


Your Cloud Security and How to Improve

Security doesn’t apply to your virtual environments alone. In fact, according to Jacob Hunt, Senior Security Solutions Architect at ADAPTURE, your security responsibilities begin with your company’s culture:

“A company with a mature security mindset will have each department require a security focus in its assigned tasks. Everyone is responsible. The days of having an infosec department being responsible for preventing a breach is no longer viable.” Even after moving to the cloud, there is still work to be done internally. Consider the following aspects of corporate workplace security.

PEOPLE No matter the software installed, the technology implemented, or the protocols established, network security will only be as strong as its weakest link. That weakest link has proven to be the company’s human factor. It doesn’t matter how much you vet each employee or grow to trust in his or her character, your collective workforce remains a security wild card—even under the best circumstances. An

18

ADAPTURE /// Securing the Cloud


e It

uneducated employee is just as susceptible to a spear phishing attack as a not-so-tech-savvy senior citizen. In fact, a recent study showed that 91% of cyberattacks begin with a simple phishing attempt3. There is no quick fix or one-time cure-all. Comprehensive security requires long-term, consistent cloud training initiatives and a willing dedication from all involved. The carelessness of one endangers the many, so your employees and upper management alike need to be acutely aware of the liability that comes with any level of data access (software can only do so much if you insist on using passwords like “password” or “1234”). Repetition is key. In an ideal work environment—thanks to consistent reminders, training, and accountability measures—cloud security best practices should become as commonplace to your employees as washing their hands.

DARKREADING (2016): “91% OF CYBERATTACKS START WITH A PHISHING EMAIL.” HTTPS://WWW.DARKREADING.COM/ENDPOINT/91--OF-CYBERATTACKS-START-WITH-APHISHING-EMAIL/D/D-ID/1327704 3


Your Cloud Security and How to Improv

PROCESS The next step in building a more robust cloud security architecture is establishing clear-cut security and response protocols for your employees to follow. In short, security processes enable you to leverage the human and technological resources you have and make them into a mutually-effective line of defense. Without a systematic method of approaching and responding to known vulnerabilities, your company risks greater ramifications after an attack has occurred. For example, the backlash from the infamous Target breach could have been significantly reduced if the SOC had acted on the FireEye alerts they received. Unfortunately, that wasn’t the case, and the entire company suffered because of it. In a breach situation, speed and accuracy become most critical, and unless your employees have universal protocols to follow, mistakes will be made, and vital steps can be missed entirely. To effectively mobilize this cloud defense, your security processes must be fully standardized and transferable within your workforce.

20

ADAPTURE /// Securing the Cloud


ve It

Any employee, regardless of his or her status or involvement with IT, needs to be able to look at the security protocols and end up at the same solution every time for scenarios like: »» How do you determine if an email is a phishing scam? »» How do you know when your accounts have been compromised? »» What steps do you take to respond to a data breach/ malware attack/DDoS attack? Naturally, these cloud security processes must be meticulously architected for them to be effective. Your employee could be doing everything by the book, but if the process itself is flawed, then so are your defenses. You need to ensure that your processes cover each conceivable scenario and outcome, and often that requires external expertise. When ADAPTURE established its own security processes, our experts based our cloud security program on the industry-vetted authority of the NIST Cybersecurity Framework. NIST continues to directly inform how we approach security risk mitigation today.

REUTERS (2014): “TARGET SAYS IT DECLINED TO ACT ON EARLY ALERT OF CYBER BREACH” HTTPS://WWW.REUTERS.COM/ARTICLE/US-TARGET-BREACH/TARGET-SAYS-IT-DECLINEDTO-ACT-ON-EARLY-ALERT-OF-CYBER-BREACH-IDUSBREA2C14F20140313 4

NIST (2017): “CYBERSECURITY FRAMEWORK” HTTPS://WWW.NIST.GOV/ CYBERFRAMEWORK. 5


Your Cloud Security and How to Improve

TECHNOLOGY Any single security element is useless without the others—each depends on the other to form a cohesive defense. You’ve trained and vetted your workforce. You have researched and implemented exhaustive security processes. If you lack the proper technology, however, then your cloud security measures could fail. Security technology is not a one-size-fits-all, and many of the security products that you have grown accustomed to in your on-premise systems will not work well in the cloud. What was once a physical cable is now a comprehensive software-defined redirection in cloud. Those IDS controllers that used to be freestanding units in your data center are now virtualized instances. Before, you wouldn’t use endpoint security on your on-premise servers because they decreased performance; now, due to the increasing sophistication of attacks, it is a must—with cloud’s scalability eradicating the former performance issues. You’re changing your environment entirely. You need to be prepared to augment your security technology as well. There is no place for a blanket security mentality anymore—cloud users must layer their security technologies against infiltrations.

22

ADAPTURE /// Securing the Cloud


e It

Oftentimes, the platform security tools offered with your cloud services do not have sufficient features to cover all security compliance necessities (e.g. HIPAA, PCA, etc.). As a result, a cloud user might need to implement F5 Web Application Security, Check Point vSec, or FireEye on top of cloud vendor’s security offerings if the original platform’s WAF does not offer adequate features to meet specific compliance standards. ADAPTURE Senior Security Solutions Architect, Jacob Hunt, warns that, “Cloud is great for rapid deployment, but you can also rapidly violate security procedures and processes without planning and testing from your side of the environment. You cannot assume that a recent patch released by the cloud provider will automatically prevent future breaches.” You and your cloud provider must work together to create a robust, layered security architecture that increases the safety of the environment and of your assets as a whole.


Skip the Learning Curve We’re not saying that private cloud has no place. But public cloud has many advantages that can represent a more comprehensive architecture for securing your assets. And unlike most individual private cloud environments, public cloud boasts a long history of innovation and extensive testing. From the get-go, your environment can be as cutting edge and secure as the industry offers. It’s just a matter of proper implementation. ADAPTURE experts have years of experience implementing and managing cloud infrastructures.

24

ADAPTURE /// Securing the Cloud


We keep pace with cloud security innovation and fluctuation. Even though we’ve been in the technology industry for some time, cloud itself is still young. Its environments change constantly, and its capabilities expand all the time. Thanks to our industry experience, we stay ahead of that expansion and change so that you don’t have to learn by trial and error. Skip the curve (and the liability) of learning on your own and start making more informed cloud decisions.

Are you concerned about the security of your cloud environments and the steps you’re taking to protect them? Speak to one of our ADAPTURE cloud security experts to secure your assets no matter where they are.


Turn static files into dynamic content formats.

Create a flipbook
E-Book: Securing the Cloud by ADAPTURE - Issuu