50
Helping You Piece IT Together http:// www.bhconsulting.ie info@bhconsulting .ie Incident Response & Cloud Security

Incident response cloud

Embed Size (px)

DESCRIPTION

What are the key considerations when looking at incident response and cloud computing? This presentation takes a look at the key areas that people should consider when developing their IR plans

Citation preview

Page 1: Incident response cloud

Helping You Piece IT Together

http://www.bhconsulting.ie [email protected]

Incident Response&

Cloud Security

Page 2: Incident response cloud

Who Am I?

[email protected]

www.twitter.com/brianhonanwww.bhconsulting.ie/securitywatch

Page 3: Incident response cloud

Who Am I?

Page 4: Incident response cloud

Who Am I?

Page 5: Incident response cloud

Business View of The Cloud

Page 6: Incident response cloud

Vendor View of the Cloud

Page 7: Incident response cloud

Security View of the Cloud

7

Page 8: Incident response cloud

Cloud Security Challenges

8

Page 9: Incident response cloud

Cloud IR

Page 10: Incident response cloud

Cloud IR

Page 11: Incident response cloud

Old Threats Still There

Page 12: Incident response cloud

Control Panel Concerns

Page 13: Incident response cloud

Multi-Tenant Concerns

Page 14: Incident response cloud

Who Has Access?

Page 15: Incident response cloud

Insider Threat

Page 16: Incident response cloud

How Good Are Their Controls?

Page 17: Incident response cloud

Financial Denial Of Service

Page 18: Incident response cloud

Weakest Link ?

Page 19: Incident response cloud

Merger & Acquisitions

Page 20: Incident response cloud

Merger & Acquisitions

Page 21: Incident response cloud

Provider Closures

Page 22: Incident response cloud

Secure Data Deletion?

Page 23: Incident response cloud

Where is Your Data?

Page 24: Incident response cloud

Compliance Issues

Page 25: Incident response cloud

Data Protection & Privacy

Page 26: Incident response cloud

In Line Of Fire

Page 27: Incident response cloud

Traditional IR

Page 28: Incident response cloud

Traditional Incident Response

Detect

Contain

Eradicate

Remediate

Recover

Review

Communicate

Page 29: Incident response cloud

Cloud Incident Response

Page 30: Incident response cloud

How Do You Contain Cloud?

Page 31: Incident response cloud

Change of Mindset

Page 32: Incident response cloud

Same IR Principles

Detect

Contain

Eradicate

Remediate

Recover

Review

Communicate

Page 33: Incident response cloud

Change of Mindset

Page 34: Incident response cloud

Engage Early with Business

Page 35: Incident response cloud

Ensure IR Requirements in T&Cs

Page 36: Incident response cloud

Establish Team

Information Security Operations Human

Resources Legal Public Relations

Facilities Management

Page 37: Incident response cloud

Establish Relationships

Page 38: Incident response cloud

Agree Roles & Responsibilities

Page 39: Incident response cloud

Agree Policies & Procedures

Page 40: Incident response cloud

Agree Jurisdictional Issues

Page 41: Incident response cloud

Agree Disclosure Rules

Page 42: Incident response cloud

Notification in Place

Page 43: Incident response cloud

Set up Alerting Mechanisms

Page 44: Incident response cloud

Access to Logs

Page 45: Incident response cloud

Other Alerting Mechanisms

Page 46: Incident response cloud

Identify Tools

Page 47: Incident response cloud

Practise Makes Perfect

Page 48: Incident response cloud

Agree Testing

Page 49: Incident response cloud

Review & Measure

Page 50: Incident response cloud

Questions ?

[email protected]

www.twitter.com/brianhonanwww.bhconsulting.ie/securitywatch

Tel : +353 – 1 - 4404065