Top Banner
events.techtarget.com Rich Mogull, Analyst & CEO, Securosis, LLC @rmogull Data Security for Cloud Computing
37

Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Apr 26, 2018

Download

Documents

vukhue
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

events.techtarget.com

Rich Mogull, Analyst & CEO, Securosis, LLC

@rmogull

Data Security for

Cloud Computing

Page 2: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

To Steal a Data Center

Old School Cloud School

Page 3: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening
Page 4: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

How

Clouds

Store Data

Page 5: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Cloud Data Architectures

Abstraction/Management

Compute Instances

IaaS

PaaS

SaaS

Page 6: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Cloud vs. Trad

● Pooled physical storage

● Management by API

● Slower read/write, faster

snapshot/migration

● Multitenancy

Page 7: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Data

Dispersion

Photo by richiejarvisuk - http://flic.kr/p/7azb6u

Page 8: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

The

Pragmatic

Process

Page 9: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening
Page 10: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Assess

Page 11: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening
Page 12: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Manage

Cloud

Migrations

Page 13: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening
Page 14: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Secure

Transfers

Page 15: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Encryption

● Link/Network

● Client/Application

● Proxy

Photo by mbrand - http://flic.kr/p/61DP51

Page 16: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Encrypt

Page 17: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Encryption Matrix

Components Locations

Page 18: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Encryption Layers

Page 19: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Instance-Managed

Instance

Key Management

Encryption Engine Storage Volume

Page 20: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

External Key Management

Key Mgmt Server

Storage Instance

Crypto

Client

HSM, SECaaS, VM, or Server

Public/Private Cloud (IaaS)

Page 21: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Proxy

(Proxy)

Page 22: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

How to Choose

● Instance is easiest. Built into most operating systems.

● External more secure/flexible; easy to tie to existing

infrastructure. Go with agent-based.

● Proxy for databases and more-complex storage

situations.

Page 23: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Encrypting Object Storage

• File/Folder

• Client/Application

• Proxy

Page 24: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Object Storage Controllers

Container Container Container

Cloud Storage Gateway

Datacenter

Cloud

Server/Workst

ation

Server/Workst

ation

API

API

Page 25: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

How to Choose

● Try to find storage services that support encryption in the

client.

● Use file/folder for public cloud object storage (e.g.

DropBox, box.net, S3), or when extra protection needed

in private cloud.

● Consider proxy for server-to-object sync.

Page 26: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Encrypting PaaS/SaaS

SaaS

PaaS

Page 27: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Tokenization

Page 28: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

How to Choose

● PaaS is freaking hard to get right. Code into your

application if you can. Use a proxy if you can’t. Watch the

key management.

● Prefer a SaaS provider you trust.

● Proxy (encryption or tokenization) for SaaS if you have to,

but keep it simple.

Page 29: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Application Encryption Architecture

Page 30: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Monitor

Page 31: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Content Discovery

● DLP

● DAM

● Cloud awareness and

limitations

Photo by ...-Wink-... - http://flic.kr/p/6hTHYH

Page 32: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Data Loss Prevention

● Agent or hypervisor-based for

private cloud.

● Good for content discovery, less

good for in-cloud monitoring.

● SaaS for discovery should be

available soon.

Page 33: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Database Activity Monitoring

● Must be agent based.

● Physical server okay for

private, not good for

public.

● Virtual appliance for

public.

● Watch that performance.

Page 34: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Digital Rights Management?

● Maybe for consumer.

● Enterprise DRM complex beyond

workgroups, never mind cloud.

● It will happen... maybe in 5-10

years.

Page 35: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

What We Skipped

● Hardening the management plane.

● Internal segregations for private cloud.

● Authentication and Authorization.

● All the little details- encrypting an IaaS volume is

easy; encrypting a distributed cloud application is

hard.

● The future.

Page 36: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

What to Do

● Control data migrations with DLP, DAM, and FAM.

● Use the lifecycle to define your controls.

● Spend most of your cloud data security time on getting

encryption right.

Page 37: Data Security for Cloud Computing - cdn.ttgtmedia.com Mogull_Data Decurity... · Data Security for Cloud Computing . To Steal a Data Center Old School Cloud School . How ... Hardening

Thank You!

●Rich Mogull

●Analyst/CEO

●nexus.securosis.com

[email protected]

●@rmogull