Defending the Whole, IaaS, PaaS, and SaaS

44
This session was 1st given at the CSA Summit in San Francisco 29–Feb–2016

Transcript of Defending the Whole, IaaS, PaaS, and SaaS

Page 1: Defending the Whole, IaaS, PaaS, and SaaS

This session was 1st given at theCSA Summit in San Francisco 29–Feb–2016

Page 2: Defending the Whole, IaaS, PaaS, and SaaS
Page 3: Defending the Whole, IaaS, PaaS, and SaaS

Defending The Whole IaaS, PaaS, and SaaS

Page 4: Defending the Whole, IaaS, PaaS, and SaaS

Mark Nunnikhoven Vice President, Cloud Research @marknca

Page 5: Defending the Whole, IaaS, PaaS, and SaaS

Builder UserSympathy Roadmap

Understanding Tactics

Page 6: Defending the Whole, IaaS, PaaS, and SaaS

Problems

Page 7: Defending the Whole, IaaS, PaaS, and SaaS

# of services

Page 8: Defending the Whole, IaaS, PaaS, and SaaS

# of services

# of controls

Page 9: Defending the Whole, IaaS, PaaS, and SaaS

# of services # of controls

Page 10: Defending the Whole, IaaS, PaaS, and SaaS

No. of Cloud Services In Use

AllNone

Page 11: Defending the Whole, IaaS, PaaS, and SaaS

Lots

AllNone

No. of Cloud Services In Use

Page 12: Defending the Whole, IaaS, PaaS, and SaaS

Reported numbers vary widely depending You can be confident saying, ‘more then a couple’

AllNone

No. of Cloud Services In Use

Lots

Page 13: Defending the Whole, IaaS, PaaS, and SaaS

# of services # of controls

Page 14: Defending the Whole, IaaS, PaaS, and SaaS

Shared Responsibility Model

Physical

Infrastructure

Network

Virtualization

Operating System

ApplicationData

Service Configuration

Cloud Provider Cloud Consumer

Page 15: Defending the Whole, IaaS, PaaS, and SaaS

Shared Responsibility Model

Physical

Infrastructure

Network

Virtualization

Operating System

ApplicationData

Service Configuration

IaaS

Page 16: Defending the Whole, IaaS, PaaS, and SaaS

Shared Responsibility Model

Physical

Infrastructure

Network

Virtualization

Operating System

ApplicationData

Service Configuration

IaaS

Physical

Infrastructure

Network

Virtualization

Operating System

ApplicationData

Service Configuration

PaaS

Page 17: Defending the Whole, IaaS, PaaS, and SaaS

Shared Responsibility Model

Physical

Infrastructure

Network

Virtualization

Operating System

ApplicationData

Service Configuration

IaaS

Physical

Infrastructure

Network

Virtualization

Operating System

ApplicationData

Service Configuration

Physical

Infrastructure

Network

Virtualization

Operating System

ApplicationData

Service Configuration

PaaS SaaS

Page 18: Defending the Whole, IaaS, PaaS, and SaaS

Shared Responsibility Model

Physical

Infrastructure

Network

Virtualization

Operating System

ApplicationData

Service Configuration

IaaS

Physical

Infrastructure

Network

Virtualization

Operating System

ApplicationData

Service Configuration

Physical

Infrastructure

Network

Virtualization

Operating System

ApplicationData

Service Configuration

PaaS SaaS

Page 19: Defending the Whole, IaaS, PaaS, and SaaS

Consumer Controls

IDS/IPS

Anti-malware

Integrity monitoring

Access control

Content filtering

IaaS

CASB

Secure designAnti-malware

Access control

CASB

Education program

PaaS SaaS

Page 20: Defending the Whole, IaaS, PaaS, and SaaS

Pace of Uptake

FastSlow

Security Tools

Cloud Services

Page 21: Defending the Whole, IaaS, PaaS, and SaaS

Pace of Uptake

FastSlow

Security Tools

Cloud Services

This is hard to keep up with

Page 22: Defending the Whole, IaaS, PaaS, and SaaS

How do you manage security for all of these services?

Page 23: Defending the Whole, IaaS, PaaS, and SaaS

Where We’re Heading

Page 24: Defending the Whole, IaaS, PaaS, and SaaS

Cloud Control Matrix

Page 25: Defending the Whole, IaaS, PaaS, and SaaS

Cloud Security Open API

Page 26: Defending the Whole, IaaS, PaaS, and SaaS

Better Tools

Page 27: Defending the Whole, IaaS, PaaS, and SaaS

Where We Are

Page 28: Defending the Whole, IaaS, PaaS, and SaaS

VMs ERP Docs Files Files [ other ]

IaaS PaaS SaaS

Page 29: Defending the Whole, IaaS, PaaS, and SaaS

VMs ERP Docs Files Files [ other ]

IaaS PaaS SaaS

Unique controls for each SPI

Page 30: Defending the Whole, IaaS, PaaS, and SaaS

VMs ERP Docs Files Files [ other ]

IaaS PaaS SaaS

Unique controls for each SPI

Page 31: Defending the Whole, IaaS, PaaS, and SaaS

Tactics

Page 32: Defending the Whole, IaaS, PaaS, and SaaS

P P P

Successful Security

Page 33: Defending the Whole, IaaS, PaaS, and SaaS

People Process Products

Successful Security

Page 34: Defending the Whole, IaaS, PaaS, and SaaS

VMs ERP Docs Files Files [ other ]

IaaS PaaS SaaS

Page 35: Defending the Whole, IaaS, PaaS, and SaaS

VMs ERP Docs Files Files [ other ]

IaaS PaaS SaaS

Reduce ExposureEducation and awareness Strong policy (CCM) Responsive internal IT services

Page 36: Defending the Whole, IaaS, PaaS, and SaaS

VMs ERP Docs Files Files [ other ]

IaaS PaaS SaaS

Centralized MonitoringLowest common denominator Spit, glue, and hope Manual follow-ups

Page 37: Defending the Whole, IaaS, PaaS, and SaaS

VMs ERP Docs Files Files [ other ]

IaaS PaaS SaaS

Smart Service ChoicesEasy to get data in and out Supports standard APIs Strong reputation

Page 38: Defending the Whole, IaaS, PaaS, and SaaS

VMs ERP Docs Files Files [ other ]

IaaS PaaS SaaS

Realizing you’re unlikely to influence

Smart Service ChoicesEasy to get data in and out Supports standard APIs Strong reputation

Page 39: Defending the Whole, IaaS, PaaS, and SaaS

Wins

Page 40: Defending the Whole, IaaS, PaaS, and SaaS

VMs ERP Docs Files Files [ other ]

IaaS PaaS SaaS

Page 41: Defending the Whole, IaaS, PaaS, and SaaS

Where is my data?Is it adequately secured?

Page 42: Defending the Whole, IaaS, PaaS, and SaaS

Reduce exposure

Centralized monitoring

Smart service choices

Page 43: Defending the Whole, IaaS, PaaS, and SaaS

VMs ERP Docs Files Files [ other ]

IaaS PaaS SaaS

Page 44: Defending the Whole, IaaS, PaaS, and SaaS

Thank YouFollow Mark @marknca