Welcome!

Silverlight Authors: Automic Blog, Michael Kopp, AppDynamics Blog, Kaazing Blog, Steven Mandel

Blog Feed Post

Top 5 Best Practices for Cloud Security

cloud security best practices Cloud Security Cloud Encryption  security daily Top 5 Best Practices for Cloud SecurityCloud computing security issues are constantly a top concern for IT leaders migrating to the cloud. There are many issues related to data security in the cloud and more than one approach to cloud security. Focusing on Infrastructure as a Service cloud security, there are five issues that repeatedly concern customers that are resolved by implementing the best practices discussed at a high level below. Cloud security best practices are technology related, but also focuses on P3: Process, People, Products.

1.     Choose your cloud wisely


Infrastructure clouds come in many variations. Some are big (like Amazon Web Services, Microsoft Azure, Google, or HP) and some are smaller but more focused on specific needs such as addressing compliance (Firehost and Layered Technologies are two examples, but there are many more).

A cross-platform concern in every Infrastructure as a Service (IaaS) deployment is that data security is a shared responsibility. When shortlisting cloud providers, make sure specific certification such as ISO 27001 or SOC3 are in place. If you have specific regulatory concerns such as HIPAA safe harbor or PCI DSS compliance, ensure your cloud provider can support these specific requirements. Ask to speak with customers with a similar use case and similar size (or bigger). Learn from their lessons and make a decision accordingly.

2.     Encrypt your data

As we’ve written before, encryption becomes your virtual walls in a cloud deployment. In your datacenter, your physical servers are protected by the 4 walls and the tight access security policy. In a shared cloud infrastructure, those measures are basically nonexistent.

This is where data encryption steps in. Data encryption allows you to segregate and isolate your environment from other companies (or adversaries) running on the same infrastructure. Data encryption in the cloud takes multiple forms: some more secure than others.

Freeware encryption tools might seem attractive at first, but they have two major issues:

  1. They don’t scale well
  2. In many cases, the encryption key is stored on the virtual disk along with the encrypted data, which renders the entire solution useless.

In a compliance use case, these drawbacks might pose serious issues.

Research and test more than one encryption solution, and learn carefully about the security posture of the encryption provider.

3.     Focus on encryption keys

Although it sounds strange at first, cloud encryption can be easily achieved. The challenge lies=s not with the actual encryption, but with the encryption keys.

The Heartbleed bug, discovered a few weeks ago, exposed a weakness in Open SSL’s SSL/TLS protocol, allowing anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. As a result, many encrypted servers in the cloud unknowingly exposed their encryption key, which resided in memory of a server impacted by heartbleed.

To mitigate with such sophisticated attack vectors, the encryption keys should be secured throughout their life cycle: while in the key management system and while in use in the cloud. Emerging technologies such as split-key encryption and homomorphic key management can be used to avoid such attacks.

When researching encryption and key management technologies, look for cloud-enabled innovative technologies, and verify how encryption keys are managed and secure throughout the life cycle of the key usage.

4.     Automate cloud security as much as possible

One of the clouds’ most important benefits is its ability to automatically scale an infrastructure environment up or down, in a single geography or across multiple geographies. When it comes to cloud security, the paradigm shifts. You’ll hear experts telling you about the need to “keep security under your control,” and that security automation means sacrificing trust.

While true for traditional security systems, new – cloud based – security solutions do enable automation using secure, RESTful API tools.

Automating data security actually reduces risk and configuration mistakes. Assuming the software vendor can prove automation is done securely, it is a best practice for IaaS cloud security.

5.     Train your employees

Implementing the latest and greatest security toys is fun. Training employees may not seem as exciting. Yet, in many cases, a trained employee will be more efficient in stopping an attack than most technologies. (Art Gilliland gave a great pitch on “defense in depth” during RSA 2014 – see the video here).

A common modern attack pattern would start by identifying and infiltrating privileged users’ accounts (such as database administrator, or system administrators), and once access is gained, getting to end user data stored on those databases becomes a much simpler task for the attacker.

By educating users on risks and security best practices, the access of the attacker can be avoided. In addition, the cloud brings additional potential attack vectors, such as disk snapshots, or identity theft to the online portal, managing all servers. When training employees, always keep cloud in mind, together with your business tools and processes.

Cloud Security Best Practices Lead to Successful Deployments
There are many considerations surrounding cloud security. These best practices do not eliminate the risks or remove the need to always be kept abreast of the latest development. They do, however, ensure that your cloud will be more secure and enable you to comply with laws and industry regulations while taking advantage of the many business benefits of the cloud. Much of this, when explored from such a high level seems like common sense, and yet, the news is filled with stories of companies large and small who failed to properly manage their encryption keys or permitted their employees or vendors to enable access by attackers (a la recent breaches at Ebay and Target). Implementing these best practices will ensure that yours isn’t listed among the news-making breaches.

cloud security best practices Cloud Security Cloud Encryption  333333 Top 5 Best Practices for Cloud Security

The post Top 5 Best Practices for Cloud Security appeared first on Porticor Cloud Security.

Read the original blog entry...

More Stories By Gilad Parann-Nissany

Gilad Parann-Nissany, Founder and CEO at Porticor is a pioneer of Cloud Computing. He has built SaaS Clouds for medium and small enterprises at SAP (CTO Small Business); contributing to several SAP products and reaching more than 8 million users. Recently he has created a consumer Cloud at G.ho.st - a cloud operating system that delighted hundreds of thousands of users while providing browser-based and mobile access to data, people and a variety of cloud-based applications. He is now CEO of Porticor, a leader in Virtual Privacy and Cloud Security.

@ThingsExpo Stories
SYS-CON Events announced today that MIRAI Inc. will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. MIRAI Inc. are IT consultants from the public sector whose mission is to solve social issues by technology and innovation and to create a meaningful future for people.
Widespread fragmentation is stalling the growth of the IIoT and making it difficult for partners to work together. The number of software platforms, apps, hardware and connectivity standards is creating paralysis among businesses that are afraid of being locked into a solution. EdgeX Foundry is unifying the community around a common IoT edge framework and an ecosystem of interoperable components.
SYS-CON Events announced today that Dasher Technologies will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Dasher Technologies, Inc. ® is a premier IT solution provider that delivers expert technical resources along with trusted account executives to architect and deliver complete IT solutions and services to help our clients execute their goals, plans and objectives. Since 1999, we'v...
SYS-CON Events announced today that TidalScale, a leading provider of systems and services, will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. TidalScale has been involved in shaping the computing landscape. They've designed, developed and deployed some of the most important and successful systems and services in the history of the computing industry - internet, Ethernet, operating s...
SYS-CON Events announced today that Massive Networks, that helps your business operate seamlessly with fast, reliable, and secure internet and network solutions, has been named "Exhibitor" of SYS-CON's 21st International Cloud Expo ®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. As a premier telecommunications provider, Massive Networks is headquartered out of Louisville, Colorado. With years of experience under their belt, their team of...
SYS-CON Events announced today that IBM has been named “Diamond Sponsor” of SYS-CON's 21st Cloud Expo, which will take place on October 31 through November 2nd 2017 at the Santa Clara Convention Center in Santa Clara, California.
Infoblox delivers Actionable Network Intelligence to enterprise, government, and service provider customers around the world. They are the industry leader in DNS, DHCP, and IP address management, the category known as DDI. We empower thousands of organizations to control and secure their networks from the core-enabling them to increase efficiency and visibility, improve customer service, and meet compliance requirements.
SYS-CON Events announced today that TidalScale will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. TidalScale is the leading provider of Software-Defined Servers that bring flexibility to modern data centers by right-sizing servers on the fly to fit any data set or workload. TidalScale’s award-winning inverse hypervisor technology combines multiple commodity servers (including their ass...
As hybrid cloud becomes the de-facto standard mode of operation for most enterprises, new challenges arise on how to efficiently and economically share data across environments. In his session at 21st Cloud Expo, Dr. Allon Cohen, VP of Product at Elastifile, will explore new techniques and best practices that help enterprise IT benefit from the advantages of hybrid cloud environments by enabling data availability for both legacy enterprise and cloud-native mission critical applications. By rev...
Join IBM November 1 at 21st Cloud Expo at the Santa Clara Convention Center in Santa Clara, CA, and learn how IBM Watson can bring cognitive services and AI to intelligent, unmanned systems. Cognitive analysis impacts today’s systems with unparalleled ability that were previously available only to manned, back-end operations. Thanks to cloud processing, IBM Watson can bring cognitive services and AI to intelligent, unmanned systems. Imagine a robot vacuum that becomes your personal assistant tha...
As popularity of the smart home is growing and continues to go mainstream, technological factors play a greater role. The IoT protocol houses the interoperability battery consumption, security, and configuration of a smart home device, and it can be difficult for companies to choose the right kind for their product. For both DIY and professionally installed smart homes, developers need to consider each of these elements for their product to be successful in the market and current smart homes.
In his Opening Keynote at 21st Cloud Expo, John Considine, General Manager of IBM Cloud Infrastructure, will lead you through the exciting evolution of the cloud. He'll look at this major disruption from the perspective of technology, business models, and what this means for enterprises of all sizes. John Considine is General Manager of Cloud Infrastructure Services at IBM. In that role he is responsible for leading IBM’s public cloud infrastructure including strategy, development, and offering ...
SYS-CON Events announced today that N3N will exhibit at SYS-CON's @ThingsExpo, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. N3N’s solutions increase the effectiveness of operations and control centers, increase the value of IoT investments, and facilitate real-time operational decision making. N3N enables operations teams with a four dimensional digital “big board” that consolidates real-time live video feeds alongside IoT sensor data a...
In a recent survey, Sumo Logic surveyed 1,500 customers who employ cloud services such as Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). According to the survey, a quarter of the respondents have already deployed Docker containers and nearly as many (23 percent) are employing the AWS Lambda serverless computing framework. It’s clear: serverless is here to stay. The adoption does come with some needed changes, within both application development and operations. Tha...
SYS-CON Events announced today that Avere Systems, a leading provider of enterprise storage for the hybrid cloud, will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Avere delivers a more modern architectural approach to storage that doesn't require the overprovisioning of storage capacity to achieve performance, overspending on expensive storage media for inactive data or the overbui...
With major technology companies and startups seriously embracing Cloud strategies, now is the perfect time to attend 21st Cloud Expo October 31 - November 2, 2017, at the Santa Clara Convention Center, CA, and June 12-14, 2018, at the Javits Center in New York City, NY, and learn what is going on, contribute to the discussions, and ensure that your enterprise is on the right path to Digital Transformation.
SYS-CON Events announced today that mruby Forum will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. mruby is the lightweight implementation of the Ruby language. We introduce mruby and the mruby IoT framework that enhances development productivity. For more information, visit http://forum.mruby.org/.
Digital transformation is changing the face of business. The IDC predicts that enterprises will commit to a massive new scale of digital transformation, to stake out leadership positions in the "digital transformation economy." Accordingly, attendees at the upcoming Cloud Expo | @ThingsExpo at the Santa Clara Convention Center in Santa Clara, CA, Oct 31-Nov 2, will find fresh new content in a new track called Enterprise Cloud & Digital Transformation.
Amazon is pursuing new markets and disrupting industries at an incredible pace. Almost every industry seems to be in its crosshairs. Companies and industries that once thought they were safe are now worried about being “Amazoned.”. The new watch word should be “Be afraid. Be very afraid.” In his session 21st Cloud Expo, Chris Kocher, a co-founder of Grey Heron, will address questions such as: What new areas is Amazon disrupting? How are they doing this? Where are they likely to go? What are th...
Most technology leaders, contemporary and from the hardware era, are reshaping their businesses to do software. They hope to capture value from emerging technologies such as IoT, SDN, and AI. Ultimately, irrespective of the vertical, it is about deriving value from independent software applications participating in an ecosystem as one comprehensive solution. In his session at @ThingsExpo, Kausik Sridhar, founder and CTO of Pulzze Systems, will discuss how given the magnitude of today's applicati...