Security + Cloud: What studios and vendors need to consider when adopting cloud solutions. - Ted...

55
ISE Proprietary SECURITY + CLOUD Ted Harrington, Executive Partner | [email protected]

Transcript of Security + Cloud: What studios and vendors need to consider when adopting cloud solutions. - Ted...

Page 1: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Proprietary

SECURITY + CLOUDTed Harrington, Executive Partner |

[email protected]

Page 2: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Proprietary

why is this important?

Page 3: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Proprietary

Page 4: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Confidential - not for distribution

THREAT MODELING

Page 5: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Proprietary

Page 6: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Proprietary

“If you don’t know where you’re going, any road will take you there”

Page 7: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Proprietary

Page 8: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

EXTERNAL ADVERSARIES

ISE Proprietary

Page 9: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Proprietary

Page 10: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Proprietary

CASUAL HACKER

Page 11: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Proprietary

HACKTIVIST

Page 12: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Proprietary

CORPORATE ESPIONAGE

Page 13: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Proprietary

ORGANIZED CRIME

Page 14: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Proprietary

NATION STATE

Page 15: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Proprietary

INTERNAL ADVERSARIES

Page 16: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Internal Adversaries

ISE Confidential - not for distribution

Page 17: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Internal Adversaries

ISE Confidential - not for distribution

ACCIDENTAL

Page 18: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Internal Adversaries

ISE Confidential - not for distribution

OPPORTUNISTIC

Page 19: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Internal Adversaries

ISE Confidential - not for distribution

DETERMINED

Page 20: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Confidential - not for distribution

SECURITY + CLOUD

Page 21: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Security + Cloud

ISE Confidential - not for distribution

Page 22: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Security + Cloud

ISE Confidential - not for distribution

Platform must be hardened

Page 23: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Security + Cloud

ISE Confidential - not for distribution

Configuration is CRITICAL!

Page 24: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Security + Cloud

ISE Confidential - not for distribution

“But I don’t own the equipment!”

Page 25: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Security + Cloud

ISE Confidential - not for distribution

“But I don’t own the equipment!”

Bad if: cloud platform < on-premGood if: cloud platform > on-prem

Page 26: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Cautionary Tale

ISE Confidential - not for distribution

Page 27: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Confidential - not for distribution

!

Page 28: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Confidential - not for distribution

SECURE DESIGN PRINCIPLES

Page 29: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Least Privilege

ISE Confidential - not for distribution

Page 30: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Privilege Separation

ISE Confidential - not for distribution

Page 31: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Defense in Depth

ISE Confidential - not for distribution

Page 32: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Trust Reluctance

ISE Confidential - not for distribution

Page 33: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Open Design

ISE Confidential - not for distribution

Page 34: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Economy of Mechanism

ISE Confidential - not for distribution

Page 35: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Complete Mediation

ISE Confidential - not for distribution

Page 36: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Psychological Acceptability

ISE Confidential - not for distribution

Page 37: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Fail Secure

ISE Confidential - not for distribution

Page 38: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Secure the Weakest Link

ISE Confidential - not for distribution

Page 39: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Reduce Asset Handling

ISE Confidential - not for distribution

Page 40: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Build Security In

ISE Confidential - not for distribution

Page 41: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Ongoing Reassessment

ISE Confidential - not for distribution

Page 42: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Confidential - not for distribution

ANTI-PRINCIPLES

Page 43: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Compliance

ISE Confidential - not for distribution

Page 44: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Complexity

ISE Confidential - not for distribution

Page 45: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Obscurity

ISE Confidential - not for distribution

Page 46: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Security Through Legality

ISE Confidential - not for distribution

Page 47: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Deferral of Risk

ISE Confidential - not for distribution

Page 48: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Confidential - not for distribution

SECURITY ASSESSMENT:The Wrong Way

Page 49: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Security Assessment Fail

ISE Confidential - not for distribution

Page 50: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Confidential - not for distribution

SECURITY ASSESSEMENT:The Right Way

Page 51: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Security Assessment Win

ISE Confidential - not for distribution

Page 52: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Confidential - not for distribution

KEY TAKEAWAYS

Page 53: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

Key Takeaways• Configuration is critical!• Cloud could be more secure, could be less secure• Assessment methodology matters

ISE Confidential - not for distribution

Page 54: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

How Can ISE Help?• Security assessment

– Application– Infrastructure– Supply Chain– Vendor

• Design guidance• Training• Embed

ISE Confidential - not for distribution

Page 55: Security + Cloud: What studios and vendors need to consider when adopting cloud solutions.  - Ted Harrington ISE: ETC Cloud QTR

ISE Confidential - not for distribution

[email protected]