26
Sharing the Cloud Glen Roberts, CISSP

Sharing the Cloud

Embed Size (px)

DESCRIPTION

Sharing the Cloud by Glen Roberts, CISSP Presented at CUISPA 2012 Conference in Austin, TX on 2/21/2012. CUISPA (Credit Union Information Security Professionals Association) is a national association of credit union information technology professionals focused on improving security and risk management through cooperation.

Citation preview

Page 1: Sharing the Cloud

Sharing  the  Cloud  Glen  Roberts,  CISSP  

Page 2: Sharing the Cloud

About  the  Presenter  

*  Glen  Roberts,  CISSP  *  IT  Infrastructure  Manager  at  UFCU  *  President  at  Cloud  Security  Alliance,  Austin  Chapter  

Page 3: Sharing the Cloud

*  Cloud  Computing  Overview  *  Cloud  Benefits  and  Risks  *  Community  Cloud  Deployment  Model  *  Case  Study:  2nd  Node  *  Foundational  Issues  *  Abbreviated  Risk  Framework  *  Addressing  Common  Security  Concerns  

Agenda  

Page 4: Sharing the Cloud

Cloud  Computing  Definition  

A  model  for  enabling  ubiquitous,  convenient,  on-­‐demand  network  access  to  a  shared  pool  of  configurable  computing  resources  (NIST:  September,  2011)    

Page 5: Sharing the Cloud

Cloud  Computing  Model  

!

Page 6: Sharing the Cloud

What  are  some  of  the  benefits  cloud  computing  can  offer  credit  unions?  

Interactive  Slide    

Page 7: Sharing the Cloud

1.  Faster  implementation,  ready  to  use,  automation  2.  Access  anywhere,  on  any  device  3.  Reduced  cost,  pay  for  use  4.  Scalability,  right-­‐sized,  flex  up  and  down  5.  Collective  benefits,  GRC  alignment,  new  functionality  6.  Improved  productivity,  shift  focus  to  further  innovate  7.  Integrated  security  and  patching  8.  Leverage  vendor  expertise,  economy  of  scale  9.  High  performance,  reliability,  uptime  10.  Environment-­‐friendly,  computing  efficiency  

Top  10  Cloud  Benefits  

Page 8: Sharing the Cloud

What  risks  might  cloud  computing  expose  a  credit  union  to?  

Interactive  Slide    

Page 9: Sharing the Cloud

1.  Data  loss,  alteration,  disclosure  2.  Unable  to  prove  security  of  provider  or  solution  3.  Provider  insider  threat,  insecure  APIs,  hypervisor  flaws  4.  Multi-­‐tenancy  trust  issues  5.  Account  hijacking  6.  Regulatory  problems,  lack  of  forensics  support  7.  Blurred  responsibilities    8.  Internet/external  network  dependency  9.  Poor  support,  scalability  issues  10.  Complexity,  hidden  costs  

Top  10  Cloud  Risks  

Page 10: Sharing the Cloud

*  Shared  by  several  organizations  *  Supports  a  community  with  common  interests  *  Business  purpose  *  Standardization  *  GRC  requirements:  GLBA,  NCUA  

*  Many  of  the  benefits  of  public  cloud  with  less  risk  *  Better  cost  savings  than  private  cloud  or  traditional  infrastructure  

Enter  Community  Clouds  

Page 11: Sharing the Cloud

*  Transparency  *  Dependable  SLAs  *  Clear  roles  &  responsibilities  *  Shared  improvements  *  Data  sharing  

What  Community  Offers  

Page 12: Sharing the Cloud

*  Cooperatively  select  vendors    *  Improved  bargaining  power  as  a  collective  *  Shared  cost  of  vendor  solutions  *  Leverage  shared  integration  with  vendors  

Cloud  Service  Brokerage  

Page 13: Sharing the Cloud

*  Reduce  maintenance  &  operations  costs  *  Share  the  expense  of  implementations  *  Free  up  staff  to  innovate  for  members  

Do  More  with  Less  

Page 14: Sharing the Cloud

Case  Study:  2nd  Node  

*  Formed  by  UFCU  and  AFCU  in  2009  *  CUSO  *  Second  data  center  *  Business  Continuity/Disaster  Recovery  

Page 15: Sharing the Cloud

2nd  Node:  Facility  

*  Facility  *  SAS  70  Type  II  Facility  *  Working  on  SSAE  16  Type  II  *  Generator,  UPS,  HVAC  *  Environmental  security  

Page 16: Sharing the Cloud

2nd  Node:  Infrastructure  

*  Utility  pricing  per  cabinet:    *  Telecom  *  Internet  connectivity  –  100  mbps  

*  SAN  *  Separate  LUNS,  partitions  *  EqualLogic,  Compellent  

*  IDS/IPS  *  Individual  consoles/customer  *  2nd  Node  as  the  oracle  

 

Page 17: Sharing the Cloud

2nd  Node:  Cloud  Services  

*  Private  clouds  *  SAN  replication  *  System  backups  *  Silver  Peak  network  concentrators  *  Hosted  failover  (Symitar)  

Page 18: Sharing the Cloud

*  NYSE  Capital  Markets  Community  Platform  *  IBM  Federal  Community  Cloud  *  G-­‐Cloud  *  News  Corporation  NC3  

Some  Community  Clouds  

Page 19: Sharing the Cloud

Foundational  Issues  

*  Many  have  tried  and  failed  *  Control  issues  vs.  cooperation  *  Visibility  of  operations  *  Differing  visions  *  Undefined  SLAs  

Page 20: Sharing the Cloud

*  Security  *  Not  necessarily  more  or  less  secure  *  Enormous  potential  to  be  more  secure  *  Collaborate  to  implement  controls  *  Standards  gaps  *  Traditional  standards  still  apply  *  NIST  and  CSA  are  helping  accelerate  catch-­‐up  

Addressing  Common  Security  Concerns  

Page 21: Sharing the Cloud

*  What  data  needs  to  be  protected?  *  Common  options:  *  Encryption  of  data  at  rest  and  in  motion  *  Tokenization  *  Sanitization,  anonymization  *  Object  security  (SQL)  *  Hashing  

Data  Protection  

Page 22: Sharing the Cloud

*  Identify  potential  assets  to  be  moved  to  a  community  cloud  *  Infrastructure  *  Data  *  Applications  *  Functions/Processes  

Abbreviated  Risk  Framework:  Identify  Assets  

Page 23: Sharing the Cloud

*  Assess  DAD  risks  of  moving  assets  to  community  cloud  *  What  is  the  impact  if  the  provider  accesses  the  asset  or  if  data  goes  public?  *  What  is  the  impact  if  processes  are  manipulated  or  fail  to  function?  

Abbreviated  Risk  Framework:  Community  Cloud  Risks  

Page 24: Sharing the Cloud

*  Location  *  Identification  of  other  tenants  *  Degree  of  control  *  Who  manages  assets  and  how  *  Security  and  compliance  controls  

Abbreviated  Risk  Framework:  Community  Cloud  Requirements  

Page 25: Sharing the Cloud

*  Providers  *  Partners  *  Solutions  

Abbreviated  Risk  Framework:  Community  Cloud  Evaluation  

Page 26: Sharing the Cloud

Thanks!  

 Glen  Roberts  [email protected]  (512)  966-­‐3425