Top Banner
www.cloudsec.com | #CLOUDSEC Enabling Cloud Security – It’s more than just ticking a box
17

CLOUDSEC LONDON 2016 - Puneet Kukreja - Enabling Cloud Security -

Jan 22, 2018

Download

Technology

Puneet Kukreja
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: CLOUDSEC LONDON 2016 - Puneet Kukreja - Enabling Cloud Security -

www.cloudsec.com | #CLOUDSEC

Enabling Cloud Security

– It’s more than just ticking a box

Page 2: CLOUDSEC LONDON 2016 - Puneet Kukreja - Enabling Cloud Security -

#CLOUDSEC

Th

e c

lou

d lan

dsca

pe

Source: https://steveblank.files.wordpress.com/2011/02/bessemercloudscape.jpg

Page 3: CLOUDSEC LONDON 2016 - Puneet Kukreja - Enabling Cloud Security -

Side Activities at Venue

“Opportunities and Challenges”

Page 4: CLOUDSEC LONDON 2016 - Puneet Kukreja - Enabling Cloud Security -

#CLOUDSEC

Clo

ud

op

po

rtun

itie

sFlexibility

On-demand Services

Rapid Deployment

AutomationScalability

Availability

Lower TCO

Page 5: CLOUDSEC LONDON 2016 - Puneet Kukreja - Enabling Cloud Security -

#CLOUDSEC

Clo

ud

ch

alle

nge

sTalent & Expertise

Security

Managing Multiple Services

ComplianceCost

Management

Governance and Control

Integration

Page 6: CLOUDSEC LONDON 2016 - Puneet Kukreja - Enabling Cloud Security -

“Why cloud hurts”

Page 7: CLOUDSEC LONDON 2016 - Puneet Kukreja - Enabling Cloud Security -

#CLOUDSEC

Th

e c

lassic

co

ntr

actsRequirements

Evaluations

Selection

DeploymentAdoption

Optimisation

Renewal

Page 8: CLOUDSEC LONDON 2016 - Puneet Kukreja - Enabling Cloud Security -

#CLOUDSEC

Standalone services

SLA based services

model

Business workflow

integration

Legacy infrastructure

integration

Data protection and

management

Source: https://www.simple-talk.com/iwritefor/articlefiles/cloud/2011/11/cloud-service-model.png

Page 9: CLOUDSEC LONDON 2016 - Puneet Kukreja - Enabling Cloud Security -

#CLOUDSEC

CSA shared responsibility model

Page 10: CLOUDSEC LONDON 2016 - Puneet Kukreja - Enabling Cloud Security -

#CLOUDSEC

Organisational implications• Clarity around scope and the primary motivation of moving to the cloud

• Changes to governance models and decision making

• Knowledge of cloud architecture, virtualization, multiple technology platforms

• Challenge of standardised processes supporting seamless integration across multiple systems

• Changing skillset from technology management to vendor management

• Upskilling on effective cloud-based systems management

Page 11: CLOUDSEC LONDON 2016 - Puneet Kukreja - Enabling Cloud Security -

#CLOUDSEC

http://cloudacademy.com/blog/wp-content/uploads/2014/07/CMS-in-VPC.jpg

Page 12: CLOUDSEC LONDON 2016 - Puneet Kukreja - Enabling Cloud Security -

#CLOUDSEC

Controls and Questions

295 Supporting Questions

133 Control Areas

16 Control

Domains

• Model for enabling active governance

• Enables cloud architecture discussions for business outputs

• Moves cloud decisions from audit assessment to a risk based outcomes

Page 13: CLOUDSEC LONDON 2016 - Puneet Kukreja - Enabling Cloud Security -

“A tale of three instances”

Page 14: CLOUDSEC LONDON 2016 - Puneet Kukreja - Enabling Cloud Security -

#CLOUDSEC

Three cloud projects

• IaaS contracts• PaaS contracts• SaaS Contracts

• Finance • HR Services• Collaboration• CRM• Business Intelligence

Global Bank Healthcare Provider Government Department

Complete Set

295 Questions133 Areas16 Domains

295 Questions

133 Areas16 Domains

• IaaS contracts• PaaS contracts• SaaS Contracts

• Finance • HR Services• Collaboration• Document Mgmt.• CRM

• GovCloud• SaaS Contracts

• Document Mgmt.• Collaboration• CRM

Page 15: CLOUDSEC LONDON 2016 - Puneet Kukreja - Enabling Cloud Security -
Page 16: CLOUDSEC LONDON 2016 - Puneet Kukreja - Enabling Cloud Security -

#CLOUDSEC

Th

e T

we

lve

Data Breaches

Access Management

Account Hijacking

System Vulnerabilities

Insufficient Due Diligence

Insecure Interface

Malicious Insider

Advanced Persistent

Threat

Tech Vulnerabilities

Data Loss

Services Abuse

Denial of Service

Page 17: CLOUDSEC LONDON 2016 - Puneet Kukreja - Enabling Cloud Security -

Puneet Kukreja

Partner, Cyber Advisory

Deloitte, Australia

@iPuneetKukreja