63
Not so fast! “I’m Cloud Confused” series In Cloud We Trust

Cloud trust

  • View
    457

  • Download
    0

Embed Size (px)

DESCRIPTION

 

Citation preview

Page 1: Cloud trust

Not so fast!

“I’m Cloud Confused” series

In CloudWe Trust

Page 2: Cloud trust

http://www.slideshare.net/Guppers/im-cloud-confused

If you’re new to Cloud Computing, or just confused…

Please try

Page 3: Cloud trust

the biggest Cloud Computing concerns are…

Security Privacy

Page 4: Cloud trust

Is Cloud Computingsecurity weaker

than

EnterpriseSecurity?

Fundamental Question

Page 5: Cloud trust

a Typical Reaction

when asks about security

SHA256

PKCS

X.509

AES

DES

Salt

IV

Page 6: Cloud trust

Heard

it

on

the street

Security is….

Complex Boring

Hacker stuff

Necessary EvilComplicates my life

Kills usability

Page 7: Cloud trust

Let’s make it simple

Child Play

Page 8: Cloud trust

You worked hard this year, you bought a pile of gold bars

Let’s pick a simple story

Page 9: Cloud trust

Your BankYour House

Where should you store them?

House? Bank?

Page 10: Cloud trust

What does this thief think?

Page 11: Cloud trust

Plenty of valuable assets,

but it may have elaborate security protection in place

Bank

Page 12: Cloud trust

Some valuable assets,

security protection may notas elaborate

House

Page 13: Cloud trust

What would you do to boostyour protection?

Page 14: Cloud trust

Yes, build layers of defense

Page 15: Cloud trust

Put Put the fence up

Page 16: Cloud trust

Install additional door locks

Page 17: Cloud trust

Let’s also install alarm system

and surveillance cameras

Page 18: Cloud trust

Feel Better?

Page 19: Cloud trust

Oh, don’t forget about

a disaster plan

Page 20: Cloud trust

Knock, knock

Who’s there?

Page 21: Cloud trust

You control who

has access to your house

Page 22: Cloud trust

And, pretty sure

your inner circle won’t steal from you

Page 23: Cloud trust

Let’s translate…

Corporate Data

IT Assets(Software, Hardware)

Employees

Page 24: Cloud trust

You feel totally in control

Page 25: Cloud trust

Why in the world

you would give up control?

Page 26: Cloud trust

..and many eyes aim at big prizes

Page 27: Cloud trust

a few things to consider….

when delegating security to other…

Page 28: Cloud trust

It’s all about Trust

Trust

It’s all about

Page 29: Cloud trust

Do you trust them that they’ll still be in the

business tomorrow? Help!

Ex-Cloud Provider willwork for Food

Page 30: Cloud trust

Didn’t we see this before?

Page 32: Cloud trust

Data Lost

It is unlikely.

Reputable Cloud Providers copy data 3-4 times

Page 33: Cloud trust

However, it is normal to store highly value-able data in

two or more different cloud providers

Cloud Provider 1 Cloud Provider 2

Servicereplicated replicated

Data

Page 34: Cloud trust

Data Privacy

Confidentiality

Page 35: Cloud trust

Data in Transit

Cloud Provider

It can be secured using encryption technology, e.g. SSLIt is used especially for sensitive data

Internetdata

Page 36: Cloud trust

Data at Rest

More and more cloud providers are developing native data encryption Even if it is stolen, it will be useless for attackers

Biggest prize for attackers!

Cloud Provider

Page 37: Cloud trust

You can pick where your data resides

Page 38: Cloud trust

Physi

cal A

ccess

Data CenterCloud Provider

Page 39: Cloud trust

Security processes are typically in place for physical access Background Check

Two factor authentication

Video surveillance

Intrusion detection system

Audit

Page 40: Cloud trust

Multi tenantInfrastructure

Corporate 1 Corporate 2 Corporate 3 Corporate 4

…infrastructure is shared by many corporations (tenant)

Page 41: Cloud trust

Will vulnerability in one company

affect others in the cloud?

Page 42: Cloud trust

VirtualizationData Isolation

Cloud Providers use

isolation techniques

Computing Isolation

a vulnerability in one tenant has little impact on other tenants

Page 43: Cloud trust

Identity

Page 44: Cloud trust

Employees

Customers Suppliers

Cloud Computing

Unwanted guest

Page 45: Cloud trust

XYZCorp.com

Potential External Entry Points

Web SiteHTTP(S)

Web ServicesHTTP(S)

Database Blob(Files, Docs)

Queue Custom

Worker VM

Page 46: Cloud trust

Typical access to a web site hosted in the Cloud

Page 47: Cloud trust

Example of

a stronger authentication process

for sensitive web site

A8KP

Page 48: Cloud trust

Accessing other Cloud Services(Example)

https://aservice.mycloudprov.net

Address

Key1

R3ZhU3xAmLIEAnRRyiMHx…

Key2

xFAlNx4VeRDGQgSQI…

Page 49: Cloud trust

Control which network or machines have access

98.237.178.63 83.231.32.17

Page 50: Cloud trust

Let’s look at from cloud infrastructure provider’s

perspectives

Page 51: Cloud trust

Typical SLAs to compete

99.95% uptime

around

Page 52: Cloud trust

It is in their best interest to maintain reputation, best security practice

their business depends on it

Page 53: Cloud trust

Headlines they try hard to avoid

…. has been downsince yesterday

Data is stolen from ….

Security breach at data center….

Page 54: Cloud trust

Should you migrate all to Cloud?

Page 55: Cloud trust

NOCloud Computing is still at infancy

Page 56: Cloud trust

Trust is Always Earned,

Never Given---R. Williams

Page 57: Cloud trust

Enterprise

Migrate non-critical business operations,

departmental level data first

and Observe!

Page 58: Cloud trust

It’s not as difficult as you think

simplicity, agility and elasticity (another topic for further discussion)

Page 59: Cloud trust

Excited about new possibilities in

cloud space?

Page 60: Cloud trust

Follow discussions andpresentations on

http://www.facebook.com/pages/Im-Cloud-Confused/219897591208?ref=ts

“I’m Cloud Confused”

facebook

Page 61: Cloud trust

Us You

10 simple questions,

2 minutes to completehttp://surveymonkey.com/s.aspx?sm=NrndNTZkoG6j8BWJYejC1g_3d_3d

Will Publish Results on

facebook

Page 62: Cloud trust

Want to try Cloud for your business now ?

Only a few minutes to setup

http://www.slideshare.net/Guppers/guppers-3-minute-walkthrough

Page 63: Cloud trust

For more presentations like this, visit, follow, subscribe to:

Blog: http://www.andyharjanto.com Twitter: http://twitter.com/harjanto

Contact: [email protected]