By Venkat Krishnapur, Vice-President of Engineering and Managing Director, McAfee India
Cloud computing has become near-ubiquitous, with Indias cloud market poised to reach over US$7 billion by 2022. The use of cloud services has empowered organizations to accelerate their businesses with more agile technology at moderate costs. Cloud is making IT more strategic than ever and companies are structuring themselves around the rapid transformation, growth and agility the cloud delivers. However, this rapid migration is also presenting complexities and risks that few businesses are equipped to deal with, and the security of data has taken center stage. While cloud providers are enabling more security than ever before, there are aspects of Security that they do not cover, and it becomes the responsibility of the users to ensure those are mitigated.
The data dilemma
While its true that sensitive data can be stored safely in the cloud, this is not an inevitable conclusion. According to the McAfee 2019 Cloud Adoption and Risk Report, 21 percent of all files in the cloud contain sensitive data and sharing of sensitive data in the cloud has increased by more than 50 percent. While most of this data is stored in well-established enterprise cloud services such as Box, Salesforce, and Office365, its necessary to realize that none of these services guarantee 100 percent safety.
Irrespective of how robust your threat mitigation strategy is, the threat rates are too high to have a reactive approach. Access control policies must be ascertained and enforced before data ever enters or exits the cloud.
Think of it this wayjust as the number of employees who require the ability to edit a document is much smaller than those who need to view it, it is likely that not everyone who needs to access certain data needs the ability to share it. Examine all permissions and access the context associated with data in the cloud environment. Control who has access. Access management requires three capabilities: the ability to identify and authenticate users, the ability to assign users access rights, and the ability to create and enforce access control policies for resources.
Large institutions that have a range of data, including sensitive consumer data to protect, and many cloud solutions to choose from, must balance potential benefits against risks of breaches and access integrity. What many organizations fail to realize when moving to the cloud is, to what extent they are responsible for securing their own cloud environment. Cloud providers (vendors) secure the infrastructure but securing data, and applications are all the responsibility of the cloud customer.
The Responsibility Equation
When it comes to security, CISOs are speculating if external providers can protect their sensitive data, while also ensuring compliance. There exists a misconception that the Cloud Service Provider is responsible for securing the cloud environment. This is where shared responsibility comes into play. In simple terms, this means that the organization and the vendor split responsibilities for cloud deployment. While the vendor may handle everything from physical networks, servers, and storage to operating systems, and even applications, but the organization will need to be responsible for the rest. In reality, no matter what level of service the vendor offers, the organization is ultimately responsible for the security and compliance of cloud deployment.
As it is with all aspects of cloud, responding to security incidents is also a shared responsibility. CISOs must learn to collaborate effectively with the Cloud Service Provider, to examine and respond to potential security occurrences. To collaborate effectively, they need to understand what information the vendor can share, and the limits within which they can assist.
Companies that are fulfilling their shared responsibility by securing their data are assuming substantially more benefits than those who arent taking data protection into their own hands. There are ways and means of mitigating security risks and the cloud is a feasible alternative for enterprises; the advantages from cloud-managed services far outweigh concerns.
Organizations need to regularly assess the security posture of their cloud environments, and that of their vendors, suppliers, partners all third parties. The Verizon breach is a fine example where the vendors mistake turns to be the organizations headache. The shared security model exists for a reason. No matter who is responsible for the security of the cloud data, the organization is eventually responsible for what happens to their data.
CASB a key enabler
Cloud access security brokers (CASBs) are on-premise or cloud-based security nodes, that sit between cloud service consumers and cloud service providers, to enforce security and compliance for cloud applications. These help organizations extend the security controls of their on-premises infrastructure to the cloud.
CISOs need to evaluate the full risk landscape in their on-premise and externally hosted cloud environments that can compromise security. Think of them this waythey act as central data authentication and encryption hubs for both cloud and on-premise applications, accessed by all endpoints, including personal devices like smartphones and tablets. CASBs are an essential element of a cloud security strategy, that helps organizations govern the use of cloud and protect sensitive data. These implement security procedures like authentication, authorization, encryption, device profiling, alerting and anomaly detection/prevention.
By using CASBs, organizations can:
Conclusion
Technology has come a long way since the dawn of computing that included conventional ways of data management. Today, cloud computing is revolutionizing the IT industry, shaking up the business landscape, and pretty much everything else it touches. Although migration to the cloud is helping CIOs in their digital transformation journeys, hastily jumping into it without the necessary maturity can throw all their efforts out of the window.
While the business advantage of cloud usage is significant, this rapid migration is also introducing complexities and risks that most organizations dont have provisions to deal with. If properly addressed, these issues will not hinder your IT roadmap and data doesnt have to remain anchored on-premise. The future of cloud rests upon introducing industry standards, that will help address regulatory, management and technological matters.
The stronger your cyber defenses are, the better you are at reducing the risk and the impact when something happens.
Disclaimer: CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views expressed in this article are personal.
Go here to see the original:
Data in the Cloud is Much More at Risk Than Enterprises May Think - CISO MAG
- Roundup Of Cloud Computing Forecasts, 2017 - Forbes [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- RCom arm in tie-up for cloud computing - Moneycontrol.com [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- How Do You Define Cloud Computing? - Data Center Knowledge [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- 5 Cloud Computing Stocks to Buy - TheStreet.com [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Cloud Computing Continues to Influence HPC - insideHPC [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Red Hat's New Products Centered Around Cloud Computing, Containers - Virtualization Review [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Adobe bets big on cloud computing for marketing, creative professionals - Livemint [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Verizon sells cloud services to IBM in 'unique cooperation between ... - Cloud Tech [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- How Cloud Computing Is Turning the Tide on Heart Attacks - Fortune [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Hospital CIOs see benefits of healthcare cloud computing - TechTarget [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Trends In Cloud Computing - Business Solutions Magazine [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- A deeper dive into cloud security as a service: Advantages and issues - Cloud Tech [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- OpenText buys cloud computing firm for US$103 million - TheRecord.com [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- Belfast IT firm celebrates cloud computing success in 57 countries ... - Belfast Telegraph [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- Meet The Cloud Wars Top 10: The World's Most-Powerful Cloud-Computing Vendors - Forbes [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- How to approach cloud computing and cyber security in 2017 - Information Age [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- CFOs have discovered the big stick of cloud computing - InfoWorld [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- Belmont Stakes Odds 2017: Latest Vegas Betting Lines Before Post Positions Draw - Bleacher Report [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Cloudistics Announces New Cloud Computing Program That Enables High Margin Reoccurring Revenue Models for ... - Marketwired (press release) [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- CloudCheckr, cloud computing company expects rapid growth in Rochester - WXXI News [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- IBM Losing Facebook's WhatsApp as Cloud Customer, says CNBC - Barron's [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- What My Father Taught Me About Cloud Computing - Virtualization Review [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Workday Phenomenon Goes Global As Cloud Computing Goes Mainstream - Forbes [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- New Cloud Computing and IT Outsourcing Requirements in the Financial Sector - JD Supra (press release) [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- 3 Things You Should Know About Cloud Computing Right Now - Fortune [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Learning in the Sky: Collaborative Robots Embrace Cloud Computing - Machine Design [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Best Practices To Manage Your Hybrid Cloud - Forbes [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Here's how venture capitalists are thinking about cloud computing companies and technologies - GeekWire [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Amazon is helping veterans find jobs in cloud computing - Marketplace - Marketplace.org [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- New Cloud Computing and IT Outsourcing Requirements in the Financial Sector - Lexology (registration) [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Growing Patent Claim Risks in Cloud Computing - Lexology (registration) [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- The benefits of cloud computing, Rust 1.18, and intelligent tracking prevention in WebKit SD Times news digest ... - SDTimes.com [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Edge Computing Is New Cloud Computing Tech Investors Should Track - GuruFocus.com [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Real Estate Weekly: Digital Realty Becomes A Cloud Computing Giant - Seeking Alpha [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Virtualization admin? Pivot -- pivot now -- to a cloud computing career - TechTarget [Last Updated On: June 10th, 2017] [Originally Added On: June 10th, 2017]
- Why isn't Cloud Computing in the 2017 Belmont Stakes? - FanSided [Last Updated On: June 11th, 2017] [Originally Added On: June 11th, 2017]
- Cloud Computing Companies Move Into Medical Diagnosis (GOOG, IBM) - Investopedia [Last Updated On: June 11th, 2017] [Originally Added On: June 11th, 2017]
- China's cloud industry moving to new era with emergence of unicorns - TechNode (blog) [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- Terry Crews Is On Crackdown 3 Trailer, No Cloud Computing For Single Player - EconoTimes [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- The Risks and Perquisites of Cloud Computing - DATAQUEST [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- Alibaba Cloud announces launch of data centres in India and Indonesia - Cloud Tech [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- Indonesia banks have yet to implement cloud computing - Jakarta Post [Last Updated On: June 13th, 2017] [Originally Added On: June 13th, 2017]
- 'Sweden is heaven for cloud computing': Amazon Nordic chief - The ... - The Local Sweden [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- Amazon.com to open second government cloud-computing region ... - The Seattle Times [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- Shadow raises $57 million for its cloud computing service for ... - TechCrunch [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- Amazon Still Leads Cloud Rankings, But Competition Is Coming On Strong - Fortune [Last Updated On: June 16th, 2017] [Originally Added On: June 16th, 2017]
- Alibaba to enter European cloud computing market in mid-2017 | Air ... - Air Cargo World (registration) [Last Updated On: June 17th, 2017] [Originally Added On: June 17th, 2017]
- Alibaba to enter European cloud computing market in mid-2017 - Air Cargo World (registration) [Last Updated On: June 17th, 2017] [Originally Added On: June 17th, 2017]
- Pressing Tech Issue: Enterprise Software Vs. Cloud Computing? - Credit Union Times [Last Updated On: June 17th, 2017] [Originally Added On: June 17th, 2017]
- 7 Tips for Securely Moving Data to the Cloud - Government Technology (blog) [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- Chinese tech giant Alibaba joins key open-source cloud computing foundation - GeekWire [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- Microsoft Could Surpass Amazon in Cloud Computing This Year (AMZN, MSFT) - Investopedia [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- GDS Holdings Limited (GDS) Announces Strategic Partnership with Tencent Cloud - StreetInsider.com [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- Cloud first - Philippine Star [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- Three Considerations for Reducing Risk in Cloud Computing - CIOReview [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- Cloud Computing and Digital Divide 2.0 - CircleID - CircleID [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- Microsoft will ride artificial intelligence, cloud computing to higher ... - CNBC [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- Cloud-Computing Business Lifts Oracle's Profit -- Update - Fox Business [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- Report affirms continued cloud spend for US businesses in 2017 - Cloud Tech [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Catching up with an interconnected federal cloud - GCN.com [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Cloud-Computing Business Lifts Oracle's Profit -- 2nd Update - Fox Business [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Cisco adapts to the rise of cloud computing - The Economist [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Amazon accuses Walmart of bullying in cloud computing clash - BBC News [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Companies plan to spend more on cloud computing services this year, higher prices among drivers: Clutch - Canadian Underwriter [Last Updated On: June 23rd, 2017] [Originally Added On: June 23rd, 2017]
- Survey: businesses ramp up spending on cloud computing DC ... - DC Velocity [Last Updated On: June 24th, 2017] [Originally Added On: June 24th, 2017]
- Morgan Stanley: Cloud computing is at 'an inflection point' but how big will it get? - GeekWire [Last Updated On: June 26th, 2017] [Originally Added On: June 26th, 2017]
- How the cloud has changed education and training - TNW [Last Updated On: June 26th, 2017] [Originally Added On: June 26th, 2017]
- Cloud computing key to 4th industrial revolution - News VietNamNet - VietNamNet Bridge [Last Updated On: June 26th, 2017] [Originally Added On: June 26th, 2017]
- Lady Eli, Cloud Computing Among Workers for Brown - BloodHorse.com (press release) (registration) (blog) [Last Updated On: June 26th, 2017] [Originally Added On: June 26th, 2017]
- Microsoft signs cloud-computing partnership with Box - The Seattle Times [Last Updated On: June 27th, 2017] [Originally Added On: June 27th, 2017]
- Microsoft Signs Cloud Computing Partnership with Box - CIO Today [Last Updated On: June 30th, 2017] [Originally Added On: June 30th, 2017]
- US action on Microsoft email case could devastate cloud computing - Irish Times [Last Updated On: June 30th, 2017] [Originally Added On: June 30th, 2017]
- Cloud computing challenges today: Planning, process and people - TechTarget [Last Updated On: July 2nd, 2017] [Originally Added On: July 2nd, 2017]
- Five podcasts to catch up on the latest trends in cloud computing - TechTarget [Last Updated On: July 2nd, 2017] [Originally Added On: July 2nd, 2017]
- Microsoft reportedly set to lay off thousands as part of massive sales reorganization - GeekWire [Last Updated On: July 3rd, 2017] [Originally Added On: July 3rd, 2017]
- VMware to surge more than 20 percent because the Amazon cloud ... - CNBC [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]
- Google Unveils Custom Hardware Chip for Cloud - Investopedia [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]
- Cloud Computing Confirmed for Travers | TDN | Thoroughbred Daily ... - Thoroughbred Daily News [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]
- Why 2017 Is The Year To Understand Cloud Computing - Nasdaq [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]
- Biz Cloud Computing - Four States Homepage [Last Updated On: August 25th, 2017] [Originally Added On: August 25th, 2017]