2 hours 41 minutes
and welcome to the episode on clout, security and cybersecurity. Architectural fundamentals.
In this session,
I'll cover the basics of cloud.
What is the shed responsibility model
and cover some tools and consideration for clout. Security.
This session is by no means an in depth study and clout security,
but more to highlight that different considerations you have in the cloud environment versus traditional on premise environment.
Now to begin, I just want to emphasize that cloud security is not just a technology play. You also need to consider your processes, controls and policy around the usage off the cloud environment.
We also need to pay attention to things like configuration off the security and how you do logging. Almost all major breach off cloud environment was due to human error or or configuration in the cloud environment,
and most investigations are hampered due to poor logging.
It's cloud computing. It's not a new concept,
but it's only in recent times that the use have picked up very rapidly.
This model, which I'm showing which is then this cloud Computing Security Reference Architecture was first published in 2013
and the focus was on. How would you categorize different aspects off the clock security model.
This is by no means the only way to view clout security.
When we talk about clout, we usually refer to one off three ways. That the cloud issues software as a service
platform. It's a service or infrastructure as a service
in this session, my topics are fairly general and could be applied to all tree usage off the club.
Do search around the cost catalog to look for more in depth sessions on the various topics that catch your interests.
Now let's talk a little bit about the shed responsibility model
that's the club is managed by a clock provider. There are some things that they are responsible for
and some things you are responsible for.
No, if you look at this diagram
the bottom layer, which contains the physical infrastructure, network infrastructure
and virtual ization platform. These are the responsibility off the crop provider.
This is what we term security off the cloud.
It is the cloud environment which you would hold your application or data
on top off this you. It holds your application and data, and you would be responsible for your network configuration,
identity and excess management. All your systems and platform configuration, including the data security standards, which is set, which is your encryption standards, your key management, et cetera.
This is term security in the club.
Obviously, this is a very simplistic view
off the situation.
Armed is using this to illustrate that it takes both parties to secure the public cloud environment
in a private cloud. It will be a different team, which is your internal clock team, which would be responsible for the lower stack.
There are a few common issues with today's clout. Security situation.
as there is no real standard off clout environment,
most off the security stack is still very vendor specific in many aspects.
You also have a lack of control off the technology.
Some vendors have partnerships with different club providers that gives them different level of service than what you might expect as a direct customer. On your premise environment,
Miss Configuration Off systems, for example, your authorization, your authentication, your excess rights and so on are still the number one issue in a cloud environment today,
and commercial contracts are not easy to fit into a security model.
For example, if you have a need to do investigation off a breach. Do make sure that you have access to what you need to do in your contracts,
because by default, many club providers do not give access to death locks off the stack that they're responsible for.
It is good to brief the legal or procurement person on what you would need in terms, off investigation or in terms of excess of certain locks. When negotiation contracts
in terms of threats to the clout, I look at it in two ways. Thea application tracks and the data trends and the application treads. Some of the more common ones are
having insecure or untested AP eyes
supply chain weakness. For example, The Spectra and meltdown situation with Intel processes
all the set of libraries available in a past environment.
D does both ways, either as a target. Aw, your club environment use as a sauce off Adidas attack.
Similarly, for AP tease, many cloud applications have been hijacked To serve
S a P T platform. Do take care off the security off your applications.
In terms of data, data leak is usually the biggest concern for most organizations
in the shed platform environment. We have to be very careful off data contamination across different accounts or across different users,
and unauthorized access to the data is also a major concern.
Some awful things to do to ensure that you have a good clout security process
is to, firstly work out your instant response process with the clock vendor.
What are the shed responsibilities and what? Ah, the objects you need to perform investigation all incident response.
Next, do check and recheck all configurations off your cloud environment
and share. You have a make a checker process and a good workflow. That person is authorized to make the change
as the cloud environment. It's accessible, true many different areas. Please make use of multi factor authentication, especially for all your privilege uses
in terms off disaster recovery. Do check with the club provider. While it's the process, you have to fit in your own company's disaster recovery to fit what the club providers can provide
and lastly, do consider the use off a cat's be a cloth access security broker.
This helps simplify
your policy management across various club providers and also says providers
most cast me today are implemented. That's a smart proxy
where you can filter and control the traffic to and from your cloud environment.
It is an increasingly popular tool to manage clout security.
I would also like to promote this chart created by Adrian and Morris and post it on his Lincoln account.
Please follow the link and get a copy off this to see the details. It showcase all the different security controls and what is available natively from each off the major clock vendors from AWS Toe Azure, Google, Arkle, IBM and Ali Clough.
This chart is extremely useful when deciding what tools to use for different controls within your cloud environment.
Other things to consider
this lot frequency em timeliness.
This is especially important. For example, if you're using AWS cloudtrail to do audit locks, you bear in mind that it is not really time, and that could be a delay of up to five for 15 minutes and some instance. Consider how you would do privilege was a management,
which you use a PM solution.
Oh, which you do your own control recording for certain route users like your uses.
Be very careful how you manage your secrets and keys like you're a P I excess keys or your encryption keys
do consider the use of a hitch, sm to manage him off these instances on the cloud
to wrap up.
In today's brief lecture, we discuss the basics of clout,
shared responsibility, model What is security in the cloud and what its security off the cloud and lastly, some twos and consideration for you in terms of managing your clout. Security.
Here are some good publications you can read. One is the nous cloud computing standards, and the other is from the Clot Security Alliance on the Our guidance for critical areas of Focus in cloud Computing. Both our recently been updated and service a very good reference sauce
your clock security.
In the next session, I'll cover a few more. Advance into price security areas like mobile security and data center security if you have to time. I look forward to seeing you in the next session.
Fundamentals of Cybersecurity Architecture
This cyber security architecture class aims to give an appreciation of the various aspects of consideration that goes into a proper security architecture.